Event Missing Process Information
| Description | A 'New External IP address' event was triggered where an external connection to a Public IP was made from a host. However, no process or connection details were displayed for the event. |
| Scope | Lacework Alerts from hosts using libpcap instead of eBPF. |
| Solution | Understanding the Event
The 'Where' section of the event displays the In/Out Bytes which help to identify if this was a short-lived connection. Short lived connections can sometimes miss information in the alerts if libpacap is being used rather than eBPF.
The agent supports eBPF as of agent version 4.3 and greater. Your host machine must also be running kernel version 4.16 or greater. If the host is running a kernel version higher than 4.16 and eBPF is confirmed to be enabled for the agent version 4.3 and above, Please submit a support ticket for further investigation. |
