Configure Osqueryd schedule for SAM total usage metrics
SAM total usage metrics works by relying on the Osqueryd service running on the target host. Configure the Osqueryd service to run the required schedule Osquery on the host.
Before you begin
Role required: admin
Procedure
Navigate to Osqueryd installation folder.
Find and edit the osquery.conf file.
Add the below Osquery pack under the packs keyword.
For Windows:
"packs": { "sam-metering": "C:\\ProgramData\\ServiceNow\\agent-client-collector\\cache\\acc-visibility-modules\\bin\\sam-metering.conf" }For macOS:
"packs": { "sam-metering": "/Library/Application\ Support/servicenow/agent-client-collector/cache/acc-visibility-modules/bin/sam-metering.conf" }
Result
You can now Configure Osquery logs for SAM total usage metrics.