Interesting. The security facet of the rules turns it into some kind of HIDS (host intrusion detection system) - I would be curious to see the level of verbosity this get when scaling across hundreds of containers.
From what I get you also need to plug it to your own alerting system by hand.