Home
Docs
Join the conversation
Join Slack
Channels
# arm-architecture
# code-review
# core
# ebpf
# eclecticiq-polylogyx-extension
# extensions
# file-carving
# fleet
# foundation
# general
# golang
# kolide
# linux
# macos
# officehours
# osctrl
# plugins
# process-auditing
# sql
# website
# windows
# zeek
Powered by Linen
Channels
arm-architecture
code-review
core
ebpf
eclecticiq-polylogyx-extension
extensions
file-carving
fleet
foundation
general
golang
kolide
linux
macos
officehours
osctrl
plugins
process-auditing
sql
website
windows
zeek
Topic
Authors
Views
Replies
Activity
Share
Can osquery-go be used to write
_event
based tables? If so, is there any example code?
a
1
2
2 years ago
Copy to Clipboard
I will try this, thanks for the clarifications!
a
1
2
2 years ago
Copy to Clipboard
It should show CMake detecting the compiler etc
0
3
2 years ago
Copy to Clipboard
I’m not sure you’re going to get a better set of answers than you did in
https://osquery.slack.com/archives/C08V7KTJB/p1581915978247200
While here, or
#windows
would have been more appropriate, it’s still t...
s
1
3
2 years ago
Copy to Clipboard
hello all...is there a osquery table that contains ethernet/mac addresses of the machine?
s
0
2
2 years ago
Copy to Clipboard
@Ski alot
can you restart osquery with the --verbose flag and paste here the output?
s
0
2
2 years ago
Copy to Clipboard
normally the extension just connects to an already running osquery instance
a
1
3
2 years ago
Copy to Clipboard
anyone ever run into problems with
tearDown()
and destructors not being called when exiting osqueryi or osqueryd?
2
3
2 years ago
Copy to Clipboard
this should work...but my first problem still remains....I am on another VM and I see that a orphan osqueryd(started by service) is holding db LOCK file..and since my extension could not connect to osquery it try to rest...
a
1
3
2 years ago
Copy to Clipboard
@seph
what do you mean? I am trying to open History db, but it is locked by Chrome/Chomium so I can't run ATC queries. the only way is to copy the file
s
1
4
2 years ago
Copy to Clipboard
Can osquery-go be used to write
_event
based tables? If so, is there any example code?
2 Replies
2 years ago
n
I will try this, thanks for the clarifications!
2 Replies
2 years ago
It should show CMake detecting the compiler etc
3 Replies
2 years ago
s
I’m not sure you’re going to get a better set of answers than you did in
https://osquery.slack.com/archives/C08V7KTJB/p1581915978247200
While here, or
#windows
would have been more appropriate, it’s still t...
3 Replies
2 years ago
a
hello all...is there a osquery table that contains ethernet/mac addresses of the machine?
2 Replies
2 years ago
a
@Ski alot
can you restart osquery with the --verbose flag and paste here the output?
2 Replies
2 years ago
a
normally the extension just connects to an already running osquery instance
3 Replies
2 years ago
anyone ever run into problems with
tearDown()
and destructors not being called when exiting osqueryi or osqueryd?
3 Replies
2 years ago
a
this should work...but my first problem still remains....I am on another VM and I see that a orphan osqueryd(started by service) is holding db LOCK file..and since my extension could not connect to osquery it try to rest...
3 Replies
2 years ago
v
@seph
what do you mean? I am trying to open History db, but it is locked by Chrome/Chomium so I can't run ATC queries. the only way is to copy the file
4 Replies
2 years ago
Previous
1
2
3
4
Next