theopolis
output_size from the osquery_schedule table (one of the scheduled queries is against that table). That column reports the bytes used by each of the queries in your schedule. We run new queries on a test host for 24 hours and submit that count as our test results. You can also set up alerts for that column, if it goes over an aggregate amount for example.