Under Review

user_events_linux

Linux user events

SCHEMA

address string IPv4 address target
audit_type int The file description for the process socket
message string Message from the event
path string Full path to the value
pid long Process (or thread) ID
terminal string The network protocol ID
time long Timestamp of the windows powershell event (unix epoch)
uid long The local user that owns the plugin

-- user_events_linux INFO
SELECT 
   -- Device ID DETAILS
   meta_hostname, meta_ip_address, 

   -- Query Details
   query_name, address, audit_type, message, path,
   pid, terminal, time, uid,

   -- Decoration 
   meta_boot_time, meta_eid, meta_endpoint_type, 
   meta_ip_mask, meta_mac_address, meta_os_name, meta_os_platform, meta_os_type,
   meta_os_version, meta_public_ip, meta_query_pack_version, meta_username,

   --- Generic
   calendar_time, counter, epoch, host_identifier, numerics
   osquery_action, unix_time,

   -- Data Lake
   customer_id, endpoint_id, upload_size

FROM xdr_data
WHERE query_name = 'user_events_linux'

We need LINUX in the lake.