osquery-1/specs/hardware_events.table
2015-07-15 23:23:42 -07:00

18 lines
873 B
Plaintext

table_name("hardware_events")
description("Hardware (PCI/USB/HID) events from UDEV or IOKit.")
schema([
Column("action", TEXT, "Remove, insert, change properties, etc"),
Column("path", TEXT, "Local device path assigned (optional)"),
Column("type", TEXT, "Type of hardware and hardware event"),
Column("driver", TEXT, "Driver claiming the device"),
Column("model", TEXT, "Hardware device model"),
Column("model_id", INTEGER, "Hardware model identifier"),
Column("vendor", TEXT, "Hardware device vendor"),
Column("vendor_id", INTEGER, "Hardware vendor identifier"),
Column("serial", TEXT, "Device serial (optional)"),
Column("revision", INTEGER, "Device revision (optional)"),
Column("time", BIGINT, "Time of hardware event"),
])
attributes(event_subscriber=True)
implementation("events/hardware_events@hardware_events::genTable")