fleetdm / fleet

Open-source platform for IT, security, and infrastructure teams. (Linux, macOS, Chrome, Windows, cloud, data center)
https://fleetdm.com
Other
2.94k stars 409 forks source link

Fleet Desktop: Live query my own computer #14846

Open mikermcneil opened 10 months ago

mikermcneil commented 10 months ago

Problem

see below for a much lighter weight version if we’re unable to prioritize this whole thing

As one of the many end users at an organization which uses Fleet, as I look at the Fleet Desktop menu in the menubar,
I want to notice an option that lets me compose and run a live query on my own device (without being able to save the query),
so that I can explore the osquery schema, get curious and understand what my employer can query about my device, and eventually contribute bug reports if I notice any incorrect data.

Consider that there are 999x more end users than security/IT admins, so even a slight effect on boosting contributions is helpful.

Potential solutions

  1. Add live query button to “My device” page
  2. Or add “Explore data” item to Fleet Desktop menubar icon on all platforms. (<< this would be a lightweight first pass that would require very low effort)
mikermcneil commented 10 months ago

@noahtalerman @rachaelshaw Originally I was thinking this could be a fast follow to phase 3 of query reporting, once query report data is included on the “My device” page.

Hard to prioritize right now though, audit transparency for end users is more important first.

So instead, a much faster win is to include “Explore data” in the Fleet Desktop menubar and have that link to fleetdm.com/tables.

That still boosts contributions, with very little work. Meanwhile there’s no way for end users to actually play with the SQL, but maybe that’s a problem we can solve separately in the fleetdm.com code base. (I’m thinking something on the home page. Will get with @mike-j-thomas about that in a separate issue.)

noahtalerman commented 10 months ago

Feature fest: Great idea. Not core. Let's take this on later.

noahtalerman commented 10 months ago

cc @mikermcneil ^^