Skip to content

Instantly share code, notes, and snippets.

@maus-
Created February 24, 2015 00:05
Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save maus-/aaba8b03f7ea0ac6c11b to your computer and use it in GitHub Desktop.
Save maus-/aaba8b03f7ea0ac6c11b to your computer and use it in GitHub Desktop.
osquery.conf
{
"options": {
"osquery_log_dir": "/var/log/osquery",
"db_path": "/tmp/osquery.db",
"pidfile": "/var/run/osquery.pid",
"lockfile": "/var/lock/subsys/osquery",
"config_retriever": "filesystem",
"debug": "false",
"disable_logging": "false",
"event_pubsub": "true",
"event_pubsub_expiry": 86000,
"host_identifier": "hostname",
"log_receiver": "filesystem",
"log_result_events": "true",
"schedule_splay_percent": 10,
"use_in_memory_database": "false",
"verbose_debug": "false",
"worker_threads": 4
},
"scheduledQueries": [
{
"name": "processtest",
"query": "SELECT * FROM processes;",
"interval": 30
},
{
"name": "aprtest",
"query": "SELECT * FROM arp_cache;",
"interval": 110
},
{
"name": "listening_ports",
"query": "SELECT uid, name FROM listening_ports l, processes p WHERE l.pid=p.pid;",
"interval": 200
},
{
"name": "logged_in_users",
"query": "select * from logged_in_users;",
"interval": 60
},
{
"name": "kernel_modules",
"query": "select name, size, used_by, status from kernel_modules;",
"interval": 14400
},
{
"name": "rpm_pacakges",
"query": "select * from rpm_packages;",
"interval": 86400
}
]
}
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment