sudo
04/01/2020, 11:49 AMalessandrogario
sudo
04/01/2020, 12:27 PMalessandrogario
sudo
04/01/2020, 12:30 PMseph
osqueryi
command line.
A common way to deploy it is to connect osqueryd
to a remote management tool. (as listed above)sudo
04/01/2020, 5:46 PMseph
gui where we can perform aggregation as wellLike a log aggregation system? you can push logs to any existing one. Generally folks can help if you’re looking to get the data into places.
sudo
04/01/2020, 5:49 PMseph
sudo
04/01/2020, 5:53 PMseph
True but in general these would suffice just leveraging opensourceI’m not sure what you mean. But as before, it depends on what you like, and how you like using data
Do people use osquery to monitor their containers? I usually got used to prometheus and NodeExporterosquery and nodeexporter have access to different kinds of information. prometheus is oriented around being a TSDB for metrics. osquery is a tool to generate whatever. You could use it to feed prometheus. but feeding ELK, a SIEM, whatever is going to be more powerful.
sudo
04/01/2020, 6:02 PM