sudo
04/01/2020, 11:49 AMalessandrogario
04/01/2020, 12:26 PMsudo
04/01/2020, 12:27 PMalessandrogario
04/01/2020, 12:29 PMsudo
04/01/2020, 12:30 PMseph
04/01/2020, 5:42 PMosqueryi
command line.
A common way to deploy it is to connect osqueryd
to a remote management tool. (as listed above)sudo
04/01/2020, 5:46 PMseph
04/01/2020, 5:48 PMgui where we can perform aggregation as wellLike a log aggregation system? you can push logs to any existing one. Generally folks can help if you’re looking to get the data into places.
sudo
04/01/2020, 5:49 PMseph
04/01/2020, 5:50 PMsudo
04/01/2020, 5:53 PMseph
04/01/2020, 5:54 PMTrue but in general these would suffice just leveraging opensourceI’m not sure what you mean. But as before, it depends on what you like, and how you like using data
Do people use osquery to monitor their containers? I usually got used to prometheus and NodeExporterosquery and nodeexporter have access to different kinds of information. prometheus is oriented around being a TSDB for metrics. osquery is a tool to generate whatever. You could use it to feed prometheus. but feeding ELK, a SIEM, whatever is going to be more powerful.
sudo
04/01/2020, 6:02 PM