I'm currently evaluating osquery and would love to hear your experience or thoughts on it. For our use case:
• We'll probably just use it for servers and maybe docker containers
• The servers will be only Linux machines
• We have about 80 servers, which will increase but not tenfold (short term at least!)
• We probably want FIM, looking for odd behavior (eg. a new process started and is running as root or similar)
• We run our whole infrastructure on AWS, our infrastructure is self-healing and auto scales (well, parts of it at least)
So my questions:
• Do you think osquery is a good fit for what I describe above?
• How do you handle logs and alerts? I'm looking into streamalert for alerts and using firehose/s3 for the logs. Any good/bad experiences of doing that?
• Do you think kolide/fleet makes sense for us? We most likely want to version control queries/packs for example, but what are the upsides of using kolide/fleet?
• What is your experience with osquery for docker containers?
• Anything you think I should know? Like common pitfalls, good readings/presentations etc