Skip to content
marpaia edited this page Oct 29, 2014 · 53 revisions

osquery documentation

osquery is an operating system instrumentation framework and toolset for *nix based hosts. osquery makes low-level operating system analytics and monitoring both performant and intuitive.

osquery exposes an operating system as a high-performance relational database. This allows you to write SQL-based queries to explore operating system data.

For more information about the features and capabilities of osquery, read the overview page.

Getting Started

If you're interested in installing osquery, check out the install guide for OS X and Linux.

If you're interested in deploying osquery to provide your organization with deeper insight into your Linux and OS X hosts, check out the using osqueryd guide as well as the deployment guide.

If you're interested in performing ad-hoc queries, check out using osqueryi.

If you're interested in extending one of the existing osquery products or improving core libraries, read the extensive documentation which can be found on the wiki's right sidebar. You should start with "building the code" and "contributing code".

If you're interest in using osquery's functionality in your own tool, check out the public API documentation.

Getting help

If you any part of osquery isn't working as expected, please create a GitHub Issue.

Keep in touch with osquery developers and users in #osquery on freenode.

Clone this wiki locally