https://github.com/osquery/osquery logo
#general
Title
# general
s

shed7

05/29/2018, 4:09 PM
Looking for reasons to use osquery for FIM/auditing when auditd is installed and running on all the servers I maintain? Any thoughts?
c

clong

05/29/2018, 6:53 PM
osquery in fim/audit mode is effectively a 1:1 replacement for auditd — you can’t run both at the same time because they both rely upon the linux audit system
i’ve found the output log format from osquery to be much more human readable than what auditd spits out and writing SQL is much easier than writing audit rules, but YMMV
s

shed7

05/30/2018, 7:48 AM
Many thanks
3 Views