Upgraded to 3.11 with feature flag. Looking good for Ubuntu packages. It's cool to see this feature live now. I'm still at the beginning of the Fleet rollout, but I know that most Linux users in my company are using Arch Linux (including me). The osquery package that is available in the default Arch Linux repo contains a patch to also report packages installed on Arch as proposed in https://github.com/osquery/osquery/issues/6477 - what would be the best way to get Arch software reporting in fleet as well? PR to adjust the query or would you prefer to get this in a official osquery release 1st?
04/28/2021, 9:38 PM
Hi Martin! First off, thanks for your swift upgrade. Just for clarity, Arch Linux software is not supported with the current software inventory, correct? If you think you can write a quick PR to get Arch software reporting, we would love to check it out.
04/29/2021, 5:54 AM
That's right. The Arch Linux package table is only available in osquery when installed on Arch Linux. Fleet does not query this table.
04/29/2021, 5:26 PM
Hey @Martin Pöhlmann, I'm not on the Fleet team but do you know the contributor who made that patch for Arch Linux? If so, you should encourage them to submit a full patch. I will definitely be a supporter of that getting merged into Osquery core!
04/29/2021, 5:55 PM
I don't know him in person, but it's the same one who created the issue in osquery (https://github.com/osquery/osquery/issues/6477). He also maintains the official archlinux osquery package. I think he's also here on slack, @Anatol Pomazau