diff --git a/containers/container.go b/containers/container.go index a66ae39..d0bdb8e 100644 --- a/containers/container.go +++ b/containers/container.go @@ -829,6 +829,13 @@ func (c *Container) createConnectionFromSocketInfo(pid uint32, fd uint64, timest if socketInfo == nil || !socketInfo.Valid { return nil, false } + // connectionKey applies the same filter below; checking it first skips + // the parsing and the kernel map lookup for the commonest case. A TLS + // server's accepted sockets have a client's ephemeral port as their + // destination, are never tracked, and come through here on every event. + if common.PortFilter.ShouldBeSkipped(socketInfo.DstPort) { + return nil, true + } // Parse destination IP dstIP, err := netaddr.ParseIP(socketInfo.DstIP) diff --git a/main.go b/main.go index 9ef2708..0d6b9fb 100644 --- a/main.go +++ b/main.go @@ -164,6 +164,10 @@ func main() { flag.Set("logtostderr", "false") flag.Set("alsologtostderr", "false") flag.Set("stderrthreshold", "FATAL") + // SetOutput gives every severity the same writer, and klog writes a + // message to its own severity's writer and every lower one's: without + // one_output each warning was logged twice and each error three times. + flag.Set("one_output", "true") klog.SetOutput(&RateLimitedLogOutput{limiter: rate.NewLimiter(rate.Limit(*flags.LogPerSecond), *flags.LogBurst)}) klog.Infoln("agent version:", version)