Sure, sorry... say for example you've got a set of instances in an elastic scaling group (all identical of course).
Say you have osqueryd running a scheduled query to list all listening tcp ports every 60 seconds.
The first time it runs it will of course log all listening ports, and then future runs will only log the delta, if something's changed.
This is great for long running servers.
Say though for arguments sake these instances only live for 10 mins and then are replaced. Every time a new instance spins up it will log the initial run. Is it possible to describe the initial expected state for some query, instead of having to filter the initial query results later in the pipeline?