hey folks — i was looking at the osquery-go repo a...
# kolide
v
hey folks — i was looking at the osquery-go repo and found https://github.com/kolide/osquery-go/issues/85, any updates on this? I was looking to implement an osquery->containerd extension and containerd has support for emitting events and would be awesome to integrate that into osquery
a
It is possible to manage a ringbuffer inside the extension itself, and return all the data when the SELECT occurs
This is actually what most extensions that implement event based tables are doing
v
👍
a
We actually have a containerd event table in the works to be merged in core
It's almost ready but I believe we were missing a couple of final edits
@Stefano Bonicatti knows more
v
would be sweet to get it merged !