Hi has anyone played with osquery and interpreting...
# general
s
Hi has anyone played with osquery and interpreting the results you get in iptables table when you use
firewall-cmd
, seems very odd. How would one monitor additions/deletions of iptables rules? There is the iptables table, I guess you could query the
processes
table, but what about things using the syscall
setsockopt
and
IPT_SO_SET_REPLACE
?