https://github.com/osquery/osquery logo
s

sp

10/13/2021, 5:09 PM
Is my understanding correct ?
z

zwass

10/13/2021, 5:16 PM
Seems mostly correct. Typically the logs would be shipped to a destination where you can do analysis over time (ELK/Splunk/Panther etc.)
s

sp

10/13/2021, 5:17 PM
Got it
3 Views