I'm currently evaluating osquery and would love to...
# general
j
I'm currently evaluating osquery and would love to hear your experience or thoughts on it. For our use case: • We'll probably just use it for servers and maybe docker containers • The servers will be only Linux machines • We have about 80 servers, which will increase but not tenfold (short term at least!) • We probably want FIM, looking for odd behavior (eg. a new process started and is running as root or similar) • We run our whole infrastructure on AWS, our infrastructure is self-healing and auto scales (well, parts of it at least) So my questions: • Do you think osquery is a good fit for what I describe above? • How do you handle logs and alerts? I'm looking into streamalert for alerts and using firehose/s3 for the logs. Any good/bad experiences of doing that? • Do you think kolide/fleet makes sense for us? We most likely want to version control queries/packs for example, but what are the upsides of using kolide/fleet? • What is your experience with osquery for docker containers? • Anything you think I should know? Like common pitfalls, good readings/presentations etc