Let me know what you think about go audit after checking it out. Thanks!
01/31/2018, 4:07 PM
So just a preliminary look at it: I think you'll be able to get most of the go audit stuff from osquery. I also imagine that replacing the audit framework in linux with a third party solution would also be more difficult to deploy.
Just my poorly informed 2 cents based on some brief research. YMMV