Viewing osquery Templates
FortiSIEM comes with default system defined osquery templates. These templates are available on the Resources > Osquery page. Pre-built Linux osquery templates are available under Resources > Osquery > Linux. Pre-built Windows osquery templates are available under Resources > Osquery > Windows. These templates, and any newly created osquery templates appear on this page. To select the column headings that appear in the table, click on the Column (
) drop-down, and add/remove the ü for any column heading you wish to include/remove from the table.
| Column | Description |
|---|---|
| Name | The name of the osquery template. |
| Description |
A description of what the osquery template does. |
| Osquery | The actual osquery. |
| Frequency | The frequency that the osquery template is run. |
| Event Type | The event type name associated with any events that occur under the executed osquery. |
| Severity | The configured severity for the osquery template, ranging from 1 to 10, with 10 being the highest severity. |
| Scope | An osquery template is either a System template (a default osquery template), or a User template (created by the user). |