Basic Usage
--privileged- Required for eBPF--pid=host- See host processes--network=host- Access host network (required for SSL capture)-v /sys:/sys:ro- Read kernel interfaces-v /usr:/usr:ro- Access OpenSSL libraries-v /lib:/lib:ro- Access system libraries
With Persistent Logs
With Web UI
With Custom Config
Environment Variables
Run in Background
Export to OTLP
Troubleshooting
Container exits immediately
Check logs:- Kernel too old (< 4.18)
- BTF not available
- Missing
/sys/kernel/btf/vmlinux
No events captured
Verify host mode:Permission denied
Ensure--privileged flag is set.
Next Steps
- Docker Compose - Multi-container setup
- Cookbooks - Example configurations