if osqueryd runs a diff, then a snapshot, then a d...
# general
p
if osqueryd runs a diff, then a snapshot, then a diff, would the last run get the diffs since the snapshot or the last diff? i'm assuming the latter being that all snapshots have a counter of 0.