<@U0F36DQTY> Regarding your questions about events...
# general
z
@coffee Regarding your questions about events expiration, IIRC the events are expired only when you query from that table. So I think the answer to (c) is that everything should be alright if you have only one scheduled query hitting that table, but you may have problems if another query is also hitting that table and causing expiration to take place. This could be prevented by ensuring that the expiration period is some amount longer than the longest period on a query hitting that table. Re (b), I believe that a differential query would not output duplicate data (because the diff is stored and compared). A snapshot query probably would, but I don't think it is common practice to snapshot event-based tables. Re (a), by default osqueryi has events turned off and doesn't connect to the osqueryd db so it would have no effect. If events are turned on and osqueryi is connected to the DB, I imagine the behavior would also occur there. It would be good to get confirmation from someone else on this. If you're using an older version of osquery, keep in mind https://github.com/facebook/osquery/issues/2656
👍 1