osquery (Canonical build) (c-osquery) Package name

Install latest/edge of osquery (Canonical build)

Ubuntu 16.04 or later?

Make sure snap support is enabled in your Desktop store.


Install using the command line

sudo snap install c-osquery --edge --classic

Don't have snapd? Get set up for snaps.

osquery (Canonical build) is only available on the unstable edge channel. It could break and change often.

Channel Version Published

Details for osquery (Canonical build)

Package name

  • c-osquery

License

  • (Apache-2.0 OR GPL-2.0-only)

Last updated

  • Today - latest/edge

Report a Snap Store violation

Share this snap

Generate an embeddable card to be shared on external websites.

SQL powered operating system instrumentation and analytics

osquery exposes an operating system as a high-performance relational database, enabling SQL-based queries over processes, files, network connections, and other host state. Built on core22/LLVM-14 with BPF support, packaged so it can run on any snapd-enabled host with a compatible kernel, independent of the host distro's own userspace library versions.

Confinement note: osquery's BPF backend needs perf_event/tracefs access and effectively CAP_SYS_ADMIN/CAP_BPF-level privilege to trace syscalls system-wide -- there is no strict-confinement interface that covers this, so this snap requests classic confinement, the same effective privilege the .deb already has.

Revision Channel Version Published Build Commit Download SBOM

The build and commit information is derived from build infrastructure records.


Install osquery (Canonical build) on your Linux distribution

Choose your Linux distribution to get detailed installation instructions. If yours is not shown, get more details on the installing snapd documentation.