@gregburd - if you configure osquery to use kinesis firehose, the data can land in S3 and you can query it via AWS' Athena (serverless big data that's powered by presto under the hood). If you're interested in a framework that helps facilitate that, as andrew points out, there's streamalert:
https://www.streamalert.io/