interactive mode, but the same query won’t work in Osquery config
, neither did see any error in the
folder, any insights are greatly appreciated?
select * from windows_events LEFT JOIN (select data as data2 from windows_events where eventid=4688) ON printf('0x%x', json_extract(data, '$.EventData.ProcessID'))=json_extract(data2, '$.EventData.NewProcessId') where eventid in (5156,5157)
). For reference, I have other queries under
select data as data2 from windows_events where eventid=4688)
works fine. I wonder if there is additional way to get verbose diagnose info out of osquery daemon?
didn’t record any error log.