Fleet uses osquery tables to query operating system, hardware, and software data. Each table provides specific data for analysis and filtering.
extended_attributes
Returns the extended attributes for files (similar to Windows ADS).
Column | Type | Description |
---|---|---|
base64 | integer | 1 if the value is base64 encoded else 0 |
directory | text | Directory of file(s) Required in WHERE clause |
key | text | Name of the value generated from the extended attribute |
path | text | Absolute file path Required in WHERE clause |
value | text | The parsed information from the attribute |