Uploaded image for project: 'Network Observability'
  1. Network Observability
  2. NETOBSERV-2219

Include processes (pid/tgid) in flows

    • Icon: Spike Spike
    • Resolution: Unresolved
    • Icon: Undefined Undefined
    • None
    • None
    • eBPF
    • None
    • None
    • False
    • Hide

      None

      Show
      None
    • False
    • None
    • None
    • None

      See if we can include the running process that sends/receives traffic in net flows.

      A use case that we've seen where it would help, is when application pods are using host network / interfaces, which makes traffic invisible from those pods (the traffic source is the node in that case). We've seen that with ODF, among others. Knowing the process could help reasoning about what's behind those host network flows.

      Note: bpf_get_current_pid_tgid was added to TC in 6.10 kernel https://docs.ebpf.io/linux/helper-function/bpf_get_current_pid_tgid/ and backported in rhel 9.6

      Also an upstream ask: https://github.com/orgs/netobserv/discussions/1769 

              Unassigned Unassigned
              jtakvori Joel Takvorian
              None
              None
              None
              None
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

                Created:
                Updated: