Fleet uses osquery tables to query operating system, hardware, and software data. Each table provides specific data for analysis and filtering.
syslog_events
Column | Type | Description |
---|---|---|
datetime | text | Time known to syslog |
eid | text | Event ID Not returned in SELECT * FROM syslog_events . |
facility | text | Syslog facility |
host | text | Hostname configured for syslog |
message | text | The syslog message |
severity | integer | Syslog severity |
tag | text | The syslog tag |
time | bigint | Current unix epoch time |