<@UMQ45C7GD> the documentation is relatively strai...
# general
g
@Sparta the documentation is relatively straight forward. I recommend you get osquery running, uncomment some query packs from the standard sample configuration, and check that results are making it to osqueryd.results.log. Then once you got that, you can make your own query pack and link it from the config file. https://osquery.readthedocs.io/en/stable/deployment/configuration/