<@U0JFM04MS> good summary, <@U08V7MASW>, we remove...
# general
t
@zwass good summary, @marpaia, we removed some of that ambiguity: https://github.com/facebook/osquery/blob/master/osquery/dispatcher/scheduler.cpp#L110 so queries against event-based tables are not subjected to the set difference calculations Taking a step back, it might be time to rethink the event-based table data interaction. There are three guiding concepts: machines can potentially generate large amounts of disk-buffered event data that needs to be drained; queries against event-based tables can be considered intervals on which to drain those queues; queries against event-based tables may be joining, synthesizing or otherwise enhancing or limiting the content
👍 2