mikermcneil
03/17/2022, 1:56 AMseph
03/17/2022, 9:22 PMMike Myers
03/18/2022, 1:58 AMseph
03/18/2022, 1:59 AMMike Myers
03/18/2022, 2:10 AMosqueryi
but to get events, better to be used as osqueryd
which is when the "building on top of osquery" gets difficultmikermcneil
03/18/2022, 2:13 AMMike Myers
03/18/2022, 2:36 AMseph
03/19/2022, 1:10 PMAnything come to mind as far as a low-hanging fruit for making it easier for anyone to build and use their own extensions successfully?With a reasonable SDK (go, python, maybe even ruby. Not c++) IMO the real difficulty is in understanding the model for how everything works. Like, I can make a go extension in an hour. But I’m pretty deeply versed in the osquery ecosystem, so I’m not exactly an average user.