Osquery
Use the JSA osquery Custom Properties Content Extension to closely monitor Linux devices using osquery.
This content extension does not install when the Parent Filename custom property is present from Cisco AMP V.1.0.0. Delete Parent Filename before you install this content extension.
JSA Osquery Custom Properties Content Extension V1.0.0
The following table shows the custom properties in JSA osquery Custom Properties Content Extension V1.0.0.
Table 1: Custom Properties in JSA Osquery Custom Properties Content Extension V1.0.0
Name | Optimized | Regex Capture Group | Expressions |
---|---|---|---|
Container ID | Yes | 1 |
|
Container Image | No | 1 |
|
Container Image ID | No | 1 |
|
Container Name | No | 1 |
|
Destination Mount Point | No |
| |
File Directory | Yes | 1 |
|
File Extension | Yes | 1 |
|
File Permissions | Yes |
| |
Filename | Yes | 1 |
|
GroupID | Yes |
| |
Image Tag | No | 1 |
|
Parent Process Name | Yes | 1 |
|
Parent Process Path | Yes | 1 |
|
Privileged Container | Yes | 1 |
|
Process CommandLine | Yes | 1 |
|
Process Id | No | 1 |
|
Process Name | Yes | 1 |
|
Rule Details | Yes |
| |
SHA256 Hash | Yes | 1 |
|
Source Mount Point | Yes |
| |
Target User Name | Yes |
| |
User ID | Yes |
|