Fortinet white logo
Fortinet white logo

User Guide

Viewing osquery Templates

Viewing osquery Templates

FortiSIEM comes with default system defined osquery templates. These templates are available on the Resources > Osquery page. Pre-built Linux osquery templates are available under Resources > Osquery > Linux. Pre-built Windows osquery templates are available under Resources > Osquery > Windows. These templates, and any newly created osquery templates appear on this page. To select the column headings that appear in the table, click on the Column () drop-down, and add/remove the ü for any column heading you wish to include/remove from the table.

Column Description
Name The name of the osquery template.
Description

A description of what the osquery template does.

Osquery The actual osquery.
Frequency The frequency that the osquery template is run.
Event Type The event type name associated with any events that occur under the executed osquery.
Severity The configured severity for the osquery template, ranging from 1 to 10, with 10 being the highest severity.
Scope An osquery template is either a System template (a default osquery template), or a User template (created by the user).

Viewing osquery Templates

Viewing osquery Templates

FortiSIEM comes with default system defined osquery templates. These templates are available on the Resources > Osquery page. Pre-built Linux osquery templates are available under Resources > Osquery > Linux. Pre-built Windows osquery templates are available under Resources > Osquery > Windows. These templates, and any newly created osquery templates appear on this page. To select the column headings that appear in the table, click on the Column () drop-down, and add/remove the ü for any column heading you wish to include/remove from the table.

Column Description
Name The name of the osquery template.
Description

A description of what the osquery template does.

Osquery The actual osquery.
Frequency The frequency that the osquery template is run.
Event Type The event type name associated with any events that occur under the executed osquery.
Severity The configured severity for the osquery template, ranging from 1 to 10, with 10 being the highest severity.
Scope An osquery template is either a System template (a default osquery template), or a User template (created by the user).