Zhen
osqueryi
interactive mode, but the same query won’t work in Osquery config schedule
, neither did see any error in the osquery\log
folder, any insights are greatly appreciated?windows_events
table 👉select * from windows_events LEFT JOIN (select data as data2 from windows_events where eventid=4688) ON printf('0x%x', json_extract(data, '$.EventData.ProcessID'))=json_extract(data2, '$.EventData.NewProcessId') where eventid in (5156,5157)
theopolis
Zhen
select data as data2 from windows_events where eventid=4688)
). For reference, I have other queries under schedule
works fine.
I wonder if there is additional way to get verbose diagnose info out of osquery daemon? osquery\log
didn’t record any error log.