osquery kibana dashboard

Description

This is an Kibana dashboard example visualizing performance metrics of osquery. The example has been created as part of this blog article. In order to get the right data for the dashboard you need to follow the guide in that article.

The recommended way to get osquery data into Elasticsearch is using the Filebeat module

What is osquery?

osquery is a SQL powered operating system instrumentation, monitoring, and analytics framework.

osquery exposes the operating system as a high-performance relational database. This allows you to write SQL-based queries to browse operating system data. With osquery, SQL tables represent abstract concepts such as running processes, loaded kernel modules, open network connections, browser plug-ins, hardware events, or file hashing. SQL tables are implemented through simple plug-ins and extension APIs. Various tables already exist, and more are being written: https://osquery.io/schema.

Source

Originally found at https://medium.com/fleetdm/build-an-osquery-performance-dashboard-1b1762ee3880

Tested versions 7.13
ECS compliant No

You must log in to submit a review.

Related downloads

Elasticsearch Performance Troubleshooting Kit

Download the Elasticsearch Performance Troubleshooting Kit to efficiently diagnose and resolve slow query issues in your Elasticsearch environment.

APM Services overview canvas

Average rating:

An adaptive turn key canvas example based on Elastic APM data.

Ask Me Anything Booth – Canvas Example

This is an example canvas page that shows how to visualize using canvas in general.

Resource Optimization Dashboard

Elastic Resource Optimization Dashboard to seamlessly integrate APM insights with cloud cost data for actionable resource management and cost-saving strategies

Vega Scatterplot Kibana visualization

A scatterplot visualization made with Vega Lite for Kibana

Kibana Enhanced Table plugin

Data Table visualization with enhanced features like computed columns, pivot table or filter bar

These downloads could be also interesting for you

Sigma Elastic SIEM rules for web server logs

A collection of rules based on the Sigma detection rules for web server looks, e.g. apache, nginx or IIS.

Playable Pacman

This is a playable version of pacman made with Vega.

Terraform Elasticsearch environments

Terraform example scripts to deploy Elastic Cloud Clusters + all necessary components in AWS and GCP

Kibana Maps with Open Weather Map

This is the default basemap of Kibana incl. the Open Weather Map tile for temperature, wind and pressure

Sigma AWS Cloudtrail Detection rules

A collection of rules based on the Sigma rules for AWS based on the Filebeat AWS module and Elastic agent integration.

AWS Cloudtrail Monitoring dashboard

Deep insights into AWS Cloudtrail events for SIEM and Monitoring