Fleet uses osquery tables to query operating system, hardware, and software data. Each table provides specific data for analysis and filtering.
device_file
Similar to the file table, but use TSK and allow block address access.
Column | Type | Description |
---|---|---|
atime | bigint | Last access time |
block_size | integer | Block size of filesystem |
ctime | bigint | Creation time |
device | text | Absolute file path to device node Required in WHERE clause |
filename | text | Name portion of file path |
gid | bigint | Owning group ID |
hard_links | integer | Number of hard links |
inode | bigint | Filesystem inode number |
mode | text | Permission bits |
mtime | bigint | Last modification time |
partition | text | A partition number Required in WHERE clause |
path | text | A logical path within the device node |
size | bigint | Size of file in bytes |
type | text | File status |
uid | bigint | Owning user ID |