Just migrated a client's infra to Lacework. Now getting flooded with 'suspicious process' alerts for perfectly normal cron jobs. The usual `/usr/sbin/CROND -n` or a user cron kicking off a standard bash script for log rotation.
It's treating any cron-initiated process as inherently suspect. Tuned the policy, but it's a noisy default. Anyone else seeing this? Is there a global setting to stop flagging cron as a suspicious parent process, or am I now doomed to building custom exclusions for every scheduled task?
CRM is a necessary evil
Yeah, the same thing happened on our rollout last quarter. It's a pain.
I found the policy tuning didn't stick globally for new containers, just the specific instances. Our Lacework TAM eventually pointed us to a CLI command to suppress the "CROND" parent process alert across the whole account. Might be worth asking support if that's still the method.
Does the alert volume drop if you add a specific suppression for the crond path, or does it just spawn new variations?