
osctrl
Fast and efficient osquery management.
What is osctrl?
Section titled “What is osctrl?”osctrl is a fast and efficient osquery management solution, implementing its remote API as TLS endpoint.
With osctrl you are able to:
- Monitor all your systems running osquery,
- Distribute osquery configuration fast across all your enrolled nodes,
- Collect all the status and result logs, whether you want to store them or forward them to a different system (Splunk, ELK, Kafka, Graylog…),
- Run quasi-real-time on-demand queries in your selected enrolled nodes,
- Carve files or directories from your enrolled nodes.

osctrl has been designed to work as a scalable and reliable solution. It has been used successfully in networks from hundreds to hundreds of thousands nodes.
Give it a try!
Where to next
Section titled “Where to next”ComponentsHow osctrl-tls, osctrl-api, osctrl-cli and the rest fit together.
DeploymentDeploy with Docker, or natively with the provisioning script.
ConfigurationThe single YAML configuration file used by each service.
UsageDay-to-day use of every osctrl component and the CLI.
API referenceThe osctrl-api OpenAPI reference, rendered with Stoplight Elements.
ContributingReport bugs, improve these docs, or send a pull request.
