Hi Everyone, We are planning to deploy Osquery on linux clients in our environment. We use splunk too. Can someone let me know what advantages we have in Kolide over splunk to use it for managing configurations?
05/07/2020, 7:10 PM
Splunk is a log aggregation and visualization tool. Osquery + Fleet is a OS visibility tool. They're solutions to different problems
06/07/2021, 3:05 AM
There is some overlap in things Splunk and osquery do, when you consider splunk add-ons such as the TA-unix. Like process monitoring, service status etc. they can also compliment each other. You can selectively schedule osquery packs to write results to files that can be indexed by splunk. Osquery is more of a end point security tool, but with the right, add-ons and scripted inputs splunk can achieve the same.