📦

osquery (Canonical build)

By Canonical SecOps

View on Snapcraft.io
Version5.21.0
Revision2
License(Apache-2.0 OR GPL-2.0-only)
Confinementclassic
Basecore22

SQL powered operating system instrumentation and analytics


osquery exposes an operating system as a high-performance relational
database, enabling SQL-based queries over processes, files, network
connections, and other host state. Built on core22/LLVM-14 with BPF
support, packaged so it can run on any snapd-enabled host with a
compatible kernel, independent of the host distro's own userspace
library versions.

Confinement note: osquery's BPF backend needs perfevent/tracefs access
and effectively CAP
SYSADMIN/CAPBPF-level privilege to trace syscalls
system-wide -- there is no strict-confinement interface that covers this,
so this snap requests classic confinement, the same effective privilege
the .deb already has.

Update History

5.21.0 (2)
24 Sept 2026, 00:00 UTC

Published24 Sept 2026, 00:00 UTC

Last updated23 Sept 2026, 23:59 UTC

First seen24 Sept 2026, 00:00 UTC