Jian Zheng
03/21/2024, 5:07 PMFG
03/21/2024, 6:10 PMosqueryd -S you essentially get osqueryi. passing your config arguments to that should get you close to what you are trying to do. caveat: i haven't tried to run the profile tool myself in this way.Jian Zheng
03/21/2024, 11:33 PMosqueryd -S is the same as running osqueryi directly.
I think what I want to achieve is let the profile.py script connect osqueryd extension socket. So cmd osqueryi --connect /var/osquery/osqeury.em probably works.Jian Zheng
03/21/2024, 11:35 PMosqueryi --connect /var/osquery/osqeury.em . But, looks like psutil can't record the right process stats.