Note: Do not run osquery in parallel with the LevelBlue Agent because it will interfere with the agent and cause USM Anywhere not to parse the data it receives.
- If you do not yet have osquery, download it and follow the instructions appropriate for your operating system.
-
Create a text file called
osquery.conf
and copy-paste the contents of this file into it.Important: After you copy-paste the text, make sure to edit it so that all strings with equals signs (=) in them remain on the same line. Otherwise, this procedure will fail. -
Save
osquery.conf
and copy it to/etc/osquery/
.Note: We recommend leaving the queries created by default, but you can create your own osquery configuration. -
Start the osquery daemon:
- If you have not already done so, configure syslog to send data to the USM Anywhere Sensor. See Linux Log Collection with Syslog for instructions. This should include restarting the syslog service.
-
Verify that you can see osquery events in USM Anywhere.