Hari ini saya akan membahas cara Install Osquery pada Rocky Linux.
Salah satu dari evolusi teknologi adalah pembuatan osQuery , yang digunakan untuk Query information pada system yang ada pada datacenter. Query ini memungkinkan mengekspose operating system menggunakan High Performance database yang mana dapat di Query dengan SQL-base.
Installasi
- install Repo
curl -L https://pkg.osquery.io/rpm/GPG | sudo tee /etc/pki/rpm-gpg/RPM-GPG-KEY-osquery
dnf config-manager --add-repo https://pkg.osquery.io/rpm/osquery-s3-rpm.repo
- cek repo
dnf repolist | grep osquery
- install Osquery
dnf --enablerepo osquery-s3-rpm-repo install osquery -y
- start service
osqueryctl start osqueryd
osqueryctl stop osqueryd
osqueryctl restart osqueryd
- Coba jalankan dalam standalone mode
osqueryi
Using a virtual database. Need help, type '.help'
osquery>
- help
osquery> .help
![](https://i0.wp.com/hendro-wibiksono.web.id/wp-content/uploads/2021/08/image-30.png?resize=929%2C371&ssl=1)
– Listing Osquery system Information tables
osqueryi
osquery> .tables
![](https://i0.wp.com/hendro-wibiksono.web.id/wp-content/uploads/2021/08/image-31.png?resize=945%2C360&ssl=1)
– Querying Osquery system tables
select * from os_version;
![](https://i0.wp.com/hendro-wibiksono.web.id/wp-content/uploads/2021/08/image-32.png?resize=934%2C221&ssl=1)
select * from users where uid >=1000;
![](https://i0.wp.com/hendro-wibiksono.web.id/wp-content/uploads/2021/08/image-33.png?resize=935%2C322&ssl=1)
select user,tty,host,time from logged_in_users where tty not like '~';
![](https://i0.wp.com/hendro-wibiksono.web.id/wp-content/uploads/2021/08/image-34.png?resize=952%2C366&ssl=1)
(Visited 259 times, 1 visits today)