Title
#general
j

joshua

12/19/2019, 7:27 AM
Hello Everyone I m joshua I need One help regarding the osquery I know Using
osquery
I m able to monitor the
docker
is there any way to send the alert from os query to slack for example If I m running the previlaged container the
osquery
should send the slack notification
CptOfEvilMinions

CptOfEvilMinions

12/19/2019, 2:58 PM
Hey @joshua, to my knowledge Osquery does not have this ability. However, you can write the osquery logs to disk and have a python script read the logs for
privileged: true
.
2:59 PM
Another alternative is shipping the Osquery logs to a SIEM like Splunk and have splunk alert on
privileged: true