No commit activity in last 3 years
No release in over 3 years
osquery input plugin
2005
2006
2007
2008
2009
2010
2011
2012
2013
2014
2015
2016
2017
2018
2019
2020
2021
2022
2023
2024
 Dependencies

Development

Runtime

~> 1.2.0
 Project Readme

fluent-plugin-osquery

osquery input plugin

Installation

Add this line to your application's Gemfile:

gem 'fluent-plugin-osquery'

And then execute:

$ bundle

Or install it yourself as:

$ gem install fluent-plugin-osquery

When you use with td-agent, install it as below:

$ sudo /opt/td-agent/embedded/bin/fluent-gem install fluent-plugin-osquery

Create home directory: (It could be unnecessary)

$ sudo mkdir -p /home/td-agent/.osquery
$ sudo chown td-agent /home/td-agent/.osquery

Configuration

Example

<source>
  @type osquery
  tag osquery
  interval 60
  query select * from processes
</source>

<match osquery>
  @type stdout
</match>

Copyright

Copyright (c) 2015 Hidenori Suzuki. See LICENSE for details.