osquery kibana dashboard

Description

This is an Kibana dashboard example visualizing performance metrics of osquery. The example has been created as part of this blog article. In order to get the right data for the dashboard you need to follow the guide in that article.

The recommended way to get osquery data into Elasticsearch is using the Filebeat module

What is osquery?

osquery is a SQL powered operating system instrumentation, monitoring, and analytics framework.

osquery exposes the operating system as a high-performance relational database. This allows you to write SQL-based queries to browse operating system data. With osquery, SQL tables represent abstract concepts such as running processes, loaded kernel modules, open network connections, browser plug-ins, hardware events, or file hashing. SQL tables are implemented through simple plug-ins and extension APIs. Various tables already exist, and more are being written: https://osquery.io/schema.

Source

Originally found at https://medium.com/fleetdm/build-an-osquery-performance-dashboard-1b1762ee3880

Tested versions 7.13
ECS compliant No

You must log in to submit a review.

Related downloads

Sigma Elastic SIEM rules for web server logs

A collection of rules based on the Sigma detection rules for web server looks, e.g. apache, nginx or IIS.

Logstash Meraki Pipeline

Logstash Pipeline to load Meraki logs via Syslog into Elasticsearch

Vega advanced heat map

Vega example to show GitHub commits per author per hour of day.

Elastic Stack Monitoring Dashboard

Kibana dashboards that is showing the monitoring data collected by Elastics in built monitoring capabilities.

RUM extension dashboard

This dashboard provide deeper insight into the real user monitoring data collected by Elastic RUM.

osquery performance dashboard

Kibana Dashboard example to visualize osquery performance

These downloads could be also interesting for you

Azure billing data network

A vega visualization that shows the connection between resource group, resource type and the resource itself based on Elastic agent azure billing data integration.

Sankey visualization example

This is an example of how to build an sankey visualization using the vega visualization in Kibana.

Elastic Cloud Monitoring dashboard

Kibana dashboard that uses the Elastic Cloud monitoring data to provide better insights into what’s happening in your cloud environment.

Vega Compound Gauge

This is a compund gauge visualization made with Vega. Its very helpful for visualization of percentage values.

osquery performance dashboard

Kibana Dashboard example to visualize osquery performance