we're currently switching FROM go-audit to osquery for our audit needs for a couple reasons. one, the go-audit project doesn't get tags, etc and builds aren't well packaged. true it's one binary and an init script, but it's something that I'd have to have someone maintain on our end. Two, go-audit's messages, though it does have nicer output than auditd, aren't as nice as osquery's, so the security guy's who are writing the monitoring, etc, are all "just use the tool we already have, dangit". and there you go.