Hari ini saya akan membahas cara Install Osquery pada Rocky Linux.
Salah satu dari evolusi teknologi adalah pembuatan osQuery , yang digunakan untuk Query information pada system yang ada pada datacenter. Query ini memungkinkan mengekspose operating system menggunakan High Performance database yang mana dapat di Query dengan SQL-base.
Installasi
- install Repo
curl -L https://pkg.osquery.io/rpm/GPG | sudo tee /etc/pki/rpm-gpg/RPM-GPG-KEY-osquery
dnf config-manager --add-repo https://pkg.osquery.io/rpm/osquery-s3-rpm.repo
- cek repo
dnf repolist | grep osquery
- install Osquery
dnf --enablerepo osquery-s3-rpm-repo install osquery -y
- start service
osqueryctl start osqueryd
osqueryctl stop osqueryd
osqueryctl restart osqueryd
- Coba jalankan dalam standalone mode
osqueryi
Using a virtual database. Need help, type '.help'
osquery>
- help
osquery> .help
data:image/s3,"s3://crabby-images/42fc2/42fc233a1de4cc91ab299d0d4bd5247ae332dc19" alt=""
– Listing Osquery system Information tables
osqueryi
osquery> .tables
data:image/s3,"s3://crabby-images/7b43d/7b43d4cdc415e61586d684aed97d3876315c7d67" alt=""
– Querying Osquery system tables
select * from os_version;
data:image/s3,"s3://crabby-images/7f06b/7f06bbc9ac8e61e608bafa02fcfa951431c82b03" alt=""
select * from users where uid >=1000;
data:image/s3,"s3://crabby-images/12bb2/12bb2c7a39d27141b97932944944608810a20e61" alt=""
select user,tty,host,time from logged_in_users where tty not like '~';
data:image/s3,"s3://crabby-images/09288/09288da2391b3d678d40ca67cdc61bef5acfd409" alt=""
(Visited 277 times, 1 visits today)