Macear
02/12/2021, 2:13 AMzwass
denylisted
in osquery_schedule
? That seems likely given the watchdog issues you describe.Macear
02/12/2021, 2:48 AMzwass
events_optimize
turned on (the default).Macear
02/12/2021, 2:52 AMzwass
_events
table will be constantly recording data into osquery's local store and the data will be read from the store when the query is run on the schedule._events
table, the more data is processed when the query runs. For a regular table all of the data is generated at query time, so the interval has no effect.Macear
02/12/2021, 3:00 AMzwass
Macear
02/12/2021, 3:03 AMzwass
Macear
02/12/2021, 3:07 AMzwass
Francisco Huerta
02/12/2021, 6:26 PMzwass
Francisco Huerta
02/12/2021, 6:41 PMzwass
Macear
02/15/2021, 5:31 PM