@zwass yes I agree. Osquery performance depends on workload etc. but why can’t you do an apples to apples comparison? You can run the commands to get the same results using the different tools and monitor performance(cpu,time spent etc. ) on mirror envs before caching . Just wondering if anyone has done that exercise.