https://github.com/osquery/osquery logo
Title
m

marpaia

07/16/2018, 10:34 PM
not in the way you’re asking for it, no. you’d have to run an instance of osqueryd in each vm to perform that kind of data collection.
n

nebi

07/17/2018, 4:12 PM
@marpaia please see my follow up reply for this, thank you
m

marpaia

07/17/2018, 4:40 PM
depending on how you configure the namespaces, cgroups, etc. you may be able to identify pid groups or some other unique identifier for processes that are “containers”
but just note that “containers” don’t really exist at some level, they’re just really configured linux processes
n

nebi

07/18/2018, 3:34 AM
ok, thank you for the info sorry for taking your . time