是否可以打破 osquery 的结果日志?目前,每个查询都集中在 osqueryd.results.log 中,但我想根据预定事件分解日志记录。我怎样才能做到这一点?
例子:
{
"options": {
"config_plugin": "filesystem",
"logger_plugin": "filesystem",
"host_identifier": "hostname",
"utc": "true"
},
"schedule": {
"crontab": {
"query": "SELECT * FROM crontab;",
"interval": 100000,
+"logger_path": "/var/log/osquery/crontab.log"
},
"file_events": {
"query": "SELECT * FROM file_events;",
"removed": false,
"interval": 10,
+"logger_path": "/var/log/osquery/file_events.log"
}
},
"file_paths": {
"homes": [
"/home/%/.ssh/%%"
],
"etc": [
"/etc/%%"
]
},
"exclude_paths": {
"resolv.conf.*": [
"/etc/resolv.conf.%"
]
},
"decorators": {
"load": [
"SELECT uuid AS host_uuid FROM system_info;",
"SELECT user AS username FROM logged_in_users ORDER BY time DESC LIMIT 1;"
]
}
}