Fleet uses osquery tables to query operating system, hardware, and software data. Each table provides specific data for analysis and filtering.
hardware_events
Hardware (PCI/USB/HID) events from UDEV or IOKit.
Column | Type | Description |
---|---|---|
action | text | Remove, insert, change properties, etc |
driver | text | Driver claiming the device |
eid | text | Event ID Not returned in SELECT * FROM hardware_events . |
model | text | Hardware device model |
model_id | text | Hex encoded Hardware model identifier |
path | text | Local device path assigned (optional) |
revision | text | Device revision (optional) |
serial | text | Device serial (optional) |
time | bigint | Time of hardware event |
type | text | Type of hardware and hardware event |
vendor | text | Hardware device vendor |
vendor_id | text | Hex encoded Hardware vendor identifier |