mirror of
https://github.com/valitydev/osquery-1.git
synced 2024-11-07 01:55:20 +00:00
98cdd3643f
This commit adds an event-based virtual table implementation for querying the linux syslog. It introduces an event publisher that attaches to a named pipe to ingest CSV formatted syslog forwarded from rsyslogd. An event subscriber/virtual table makes these log lines available for queries. Currently, no additional processing is done on the input data besides parsing. Using this table requires a properly configured rsyslogd. Documentation for this configuration is forthcoming in the wiki. |
||
---|---|---|
.. | ||
config.h | ||
core.h | ||
database.h | ||
dispatcher.h | ||
distributed.h | ||
enroll.h | ||
events.h | ||
extensions.h | ||
filesystem.h | ||
flags.h | ||
hash.h | ||
logger.h | ||
packs.h | ||
registry.h | ||
sdk.h | ||
sql.h | ||
status.h | ||
tables.h |