mason kemmerer
02/02/2024, 3:31 PMKathy Satterlee
02/02/2024, 9:46 PMmason kemmerer
02/02/2024, 10:23 PMSELECT name, query, interval, executions, last_executed, denylisted, output_size,
IFNULL(system_time / executions, 0) AS avg_sys_time,
IFNULL(user_time / executions, 0) AS avg_usr_time,
IFNULL(wall_time / executions, 0) AS avg_wall_time,
ROUND((average_memory * '10e-7'), 2) AS avg_mem_mb
FROM osquery_schedule;
When reviewing the results of the above query in splunk it seemed the logs were showing that the denylisted query's avg sys, usr, and wall times and memory usage were zero leading up to the query being denylisted on the host. which was a huge bummer.
FWIW, i have the watchdog service set to default settings (200M or 10% cpu for 12 secs) which also makes me wonder if theres something i misunderstood...
is that 10% of the total CPU on the system, available at query execution time, or even a single core?
Just trying to make sense where my miss was so I can adjust my osquery and splunk dashboard accordinglyKathy Satterlee
02/02/2024, 11:09 PMKathy Satterlee
02/02/2024, 11:10 PMKathy Satterlee
02/02/2024, 11:11 PMKathy Satterlee
02/02/2024, 11:12 PMKathy Satterlee
02/02/2024, 11:14 PMmason kemmerer
02/05/2024, 2:36 PMmason kemmerer
02/05/2024, 4:22 PMKathy Satterlee
02/05/2024, 7:15 PMmason kemmerer
02/05/2024, 7:20 PMmason kemmerer
02/05/2024, 7:21 PMKathy Satterlee
02/05/2024, 8:29 PMKathy Satterlee
02/05/2024, 8:30 PMmason kemmerer
02/05/2024, 8:31 PMKathy Satterlee
02/05/2024, 8:33 PMmason kemmerer
02/05/2024, 8:33 PMselect * from process_memory_map;
Daily frequencymason kemmerer
02/05/2024, 8:35 PMmason kemmerer
02/05/2024, 8:36 PM