Jian Zheng
03/21/2024, 5:07 PMFG
03/21/2024, 6:10 PMosqueryd -S
you essentially get osqueryi. passing your config arguments to that should get you close to what you are trying to do. caveat: i haven't tried to run the profile tool myself in this way.Jian Zheng
03/21/2024, 11:33 PMosqueryd -S
is the same as running osqueryi
directly.
I think what I want to achieve is let the profile.py script connect osqueryd extension socket. So cmd osqueryi --connect /var/osquery/osqeury.em
probably works.Jian Zheng
03/21/2024, 11:35 PMosqueryi --connect /var/osquery/osqeury.em
. But, looks like psutil can't record the right process stats.