there are 3 scenarios here, for which 1 is missing information on the wiki/readthedocs:
1. Using syslog (2 facilities, 1 configurable) to log the results of status/error messages and the results from queries. This is poorly documented.
2. Setting up osquery on Linux to be a syslog consumer then scheduling queries against the
syslog
table.
3. Setting up osquery on OS X to receive ASL events, similarly to the syslog consumer setup in Linux, but using an
asl
table.