New

The executive guide to generative AI

Read more
Loading

OSQuery Integration

Version 1.22.0 (View all)
Compatible Kibana version(s) 8.7.1 or higher
9.0.0 or higher
Supported Serverless project types
What's this?
Security
Observability
Subscription level
What's this?
Basic
Level of support
What's this?
Elastic

The OSQuery integration collects and decodes the result logs written by osqueryd in the JSON format. To set up osqueryd follow the osquery installation instructions for your operating system and configure the filesystem logging driver (the default). Make sure UTC timestamps are enabled.

The OSQuery integration was tested with logs from osquery version 2.10.2. Since the results are written in the JSON format, it is likely that this module works with any version of osquery.

This module is available on Linux, macOS, and Windows.

This is the OSQuery result dataset.