Log4j vulnerability scanning
The sensor can detect Log4j Remote Code Execution (RCE) Vulnerability QIDs. It can detect the presence of vulnerable log4j packages on your container images and running containers. The sensor will automatically perform a file system search to detect log4j vulnerabilities on your container images, and this can have a performance impact. To disable log4j vulnerability scanning, specify --disable-log4j-scanning as a command line parameter for “installsensor.sh” script or provide it as a command or args parameter when deploying a sensor.