Title
#kolide
j

Jason W

07/15/2020, 7:47 PM
Curious - is anyone piping osquery logs to bigquery? How do you deal with schemas if so? This seems to be the big advantage of logging to ELK, but I’m curious if someone is using Google Bigquery
sundsta

sundsta

07/15/2020, 7:53 PM
Haven’t done it personally, but some Cloudflare folks gave a talk about their “serverless” SIEM in GCP using osquery for data collection and BigQuery was a part of it.

https://www.youtube.com/watch?v=6vrIXwiCtGI

j

Jason W

07/15/2020, 7:54 PM
ah interesting. I will take a look. I think the hard part of logging to BQ would be dealing with a different schema for every pack you configured, but maybe you could automate something around this…
sundsta

sundsta

07/15/2020, 8:01 PM
They had a ton of Cloud Functions to handle that
j

Jason W

07/16/2020, 2:31 AM
thanks @sundsta that was my guess, that you’d need to trigger a cloud function to bring up a new table with the right schema when a new pack was created. Maybe neat, but doesn’t sound like a lot of fun.