osquery (Canonical build) (c-osquery)
Install latest/edge of osquery (Canonical build)
Ubuntu 16.04 or later?
Make sure snap support is enabled in your Desktop store.
Install using the command line
sudo snap install c-osquery --edge --classic
Don't have snapd? Get set up for snaps.
Details for osquery (Canonical build)
Package name
- c-osquery
License
- (Apache-2.0 OR GPL-2.0-only)
Last updated
- Today - latest/edge
Report a Snap Store violation
Report osquery (Canonical build) for a Snap Store violation
Snap Store Violation Report submitted successfully
Thank you for your report. Information you provided will help us investigate further.
Error submitting report
There was an error while sending your report. Please try again later.
Share this snap
Generate an embeddable card to be shared on external websites.
SQL powered operating system instrumentation and analytics
osquery exposes an operating system as a high-performance relational database, enabling SQL-based queries over processes, files, network connections, and other host state. Built on core22/LLVM-14 with BPF support, packaged so it can run on any snapd-enabled host with a compatible kernel, independent of the host distro's own userspace library versions.
Confinement note: osquery's BPF backend needs perf_event/tracefs access and effectively CAP_SYS_ADMIN/CAP_BPF-level privilege to trace syscalls system-wide -- there is no strict-confinement interface that covers this, so this snap requests classic confinement, the same effective privilege the .deb already has.
| Revision | Channel | Version | Build | Commit | Download SBOM |
|---|
The build and commit information is derived from build infrastructure records.
Install osquery (Canonical build) on your Linux distribution
Choose your Linux distribution to get detailed installation instructions. If yours is not shown, get more details on the installing snapd documentation.