Skip to content
osctrl
Search
Ctrl
K
Cancel
GitHub
Select theme
Dark
Light
Auto
1. Components
Overview
osctrl-tls
osctrl-api
osctrl-mcp
osctrl-frontend
osctrl-cli
nginx
Backend
Metrics
osctrld
2. Deployment
Overview
Using Docker
Install on Ubuntu
3. Configuration
Configuration
4. Usage
Overview
osctrl-tls
osctrl-api
osctrl-mcp
Auth providers
osctrl-cli
Overview
alert
audit-logs
carve
check-api
check-db
environment
login
node
query
settings
shell
tag
tui
user
osctrld
provision.sh
5. Contributing
Contributing
osctrl-api (OpenAPI)
Overview
system
API root liveness check
API error response
API forbidden response
API health check
alerts
Apply alert changes (hot reload)
List alert channels
Create an alert channel
Get one alert channel
Update an alert channel
Delete an alert channel
Test an alert channel
List supported alert channel types
Recent alert history
List alert rules
Create an alert rule
Get one alert rule
Update an alert rule
Delete an alert rule
queries
List queries
List queries
Run query
Execute query action
Get query
List paginated queries
Get query results
Export query results CSV
List query samples
audit
List audit logs
auth-providers
Fetch IdP metadata XML
auth
Complete OIDC login
Start OIDC login
Complete SAML login
Start SAML login
Get SAML metadata
Log in
Log in
List login environments
Complete a login with a second factor
Begin enrollment during login
Finish enrollment during login
Begin a WebAuthn login ceremony
Finish a WebAuthn login ceremony
Log out
carves
List file carves
Run file carve
Execute carve action
Get file carve
Download carve archive
List file carves
List carve queries
List carve samples
checks
Authenticated API check
Unauthenticated API check
environments
List environments
Create environment
Get environment
Delete environment
Update environment
Execute enrollment action
Get enrollment values
List enrolling packages
Add enrolling package
Remove enrolling package
Execute removal action
Get removal values
Execute environment action
Get environment config
Update environment config
Update environment expiration
Get environment inactivity threshold
Set environment inactivity threshold
Reset environment inactivity threshold
Update environment intervals
Map environments
Update enrolling package URL
Events
Subscribe to resource change notifications
Features
Get enabled API features
health
Deployment health
log-sinks
List log sinks
Create a log sink
Get one log sink
Update a log sink
Delete a log sink
Revert sink to service config
Apply log sink changes (hot reload)
Clone sinks from one environment to another
List supported log sink types
logs
Get node logs
mfa
Multi-factor status
Regenerate recovery codes
Begin TOTP enrollment
Remove TOTP
Confirm TOTP enrollment
Begin WebAuthn registration
Remove a WebAuthn credential
Finish WebAuthn registration
nodes
List paginated nodes
List active nodes
List all nodes
Delete node
List inactive nodes
Get node
Get node posture
Get node posture risk score
Tag node
Lookup node
osquery
List osquery tables
platforms
List platforms
posture
List posture profiles
Get posture profile
saved-queries
List saved queries
Create saved query
Delete saved query
Update saved query
service-config
List all service config sections
List service config sections for a service
Get one service config section
Update service config section
Apply config changes and restart
Write config changes to disk
Service config file status
settings
List settings
List service settings
List service environment settings
Update setting
stats
Get dashboard stats
Get environment activity
Get environment activity tiles
Top erroring nodes for an environment
Get node activity batch
Get node activity tiles batch
Get per-node activity tiles
Get node activity
Get osquery version stats
tags
List tags
List environment tags
Execute tag action
Get environment tag
users
List users
Get user
Execute user action
Get user permissions
Set user permissions
Set all user permissions
Delete user token
Refresh user token
Get current user
Update current user
Change current user password
GitHub
Select theme
Dark
Light
Auto
Usage
You can’t know how to use
osctrl
components if you don’t read the documentation…