Thomas Marsh
02/25/2021, 4:09 PMosqueryd
(and osqueryi
is just a symbolic link to that).Mike Myers
02/26/2021, 6:34 PMosqueryi
interactively. The challenge with either of these approaches is detecting and handling errors.
I think most teams that want to use osquery as a library really just want its abstraction of OS APIs, but don't really need its SQL abstractions. Unfortunately there's no clean partitioning of those two things in the code. If there was, maybe all of the OS APIs could be a library used by both the osquery agent and other teams.Thomas Marsh
02/26/2021, 7:49 PMSeshu
02/27/2021, 6:28 AM