@zwass good summary,
@marpaia, we removed some of that ambiguity:
https://github.com/facebook/osquery/blob/master/osquery/dispatcher/scheduler.cpp#L110 so queries against event-based tables are not subjected to the set difference calculations
Taking a step back, it might be time to rethink the event-based table data interaction. There are three guiding concepts: machines can potentially generate large amounts of disk-buffered event data that needs to be drained; queries against event-based tables can be considered intervals on which to drain those queues; queries against event-based tables may be joining, synthesizing or otherwise enhancing or limiting the content