@zwass yes I saw rocksdb is mentioned in the docs. But I’m more looking at it from a resource comparison exercise. Looking at how osquery performs. From monitoring the process to pmap. So following the trail from query to execution and comparing that to doing a puppet facter vs. salt grain. I understand the docs say lightweight but how do i see that forensically and explain that to a technical program manager the advantage. If there is something that illustrates this? Can you please post a link?