In addition to the SQLite commands, there are additional osquery ones described at https://osquery.readthedocs.io/en/stable/introduction/sql/
No. We do not have a regex replace. Just regex match and regex split.
You could probably fake it, though it might be cumbersome. You could PR a replace command. Might need to think about the syntax.
seph
10/16/2023, 1:06 PM
Depending on your use case, there might be more clever options.
stats and the regex extensions are awesome and could bring new capabilities to osquery 🙂
s
seph
10/16/2023, 2:23 PM
There are a lot of projects out there. Integrating them, at both the software or license level can be a surprising amount of work.
It’s often easier to bring in the couple of functions you want
seph
10/16/2023, 2:23 PM
I wonder how hard it would be to have osquery support sqlite extensions. Might be very hard
m
Mehmet
10/16/2023, 4:54 PM
I think I now understand what you mean. I thought the SQL in osquery is just the SQLite we know, but it's not, apparently.
s
seph
10/16/2023, 6:15 PM
It’s SQLite. But osquery adds some extensions. Same as that does.