Darshal Shah
01/23/2024, 7:11 PMselect * from rpm_packages;
","severity":"1","filename":"config.cpp","line":"326","message":"Scheduled query may have failed: pack/Global/rpm_packages","version":"5.9.1","decorations":
When we run it manually in the console, it works! Just doesnt work when its scheduled. These are the options we have:
Frequency: 6 hours
logging: snapshot
Shard: 100
Can someone please help?Darshal Shah
01/25/2024, 2:09 PMGrant Bilstad
01/25/2024, 4:56 PMDarshal Shah
01/25/2024, 5:17 PMDarshal Shah
01/25/2024, 5:17 PMDarshal Shah
01/25/2024, 6:04 PMKathy Satterlee
01/29/2024, 6:51 PMDarshal Shah
01/29/2024, 9:02 PMSELECT name, query FROM osquery_schedule WHERE denylisted='1';
and got results back two from 2 hosts and both of them had the select * from rpm_packages;
under query
But we have about 73 online hosts. Does scheduled osquery not return any results even if fails for just one host? and where and how do I add --disable_watchdog=true
?Darshal Shah
01/29/2024, 9:02 PMKathy Satterlee
01/29/2024, 9:19 PMKathy Satterlee
01/29/2024, 9:21 PM