theopolis
osquery> select * from file;
W0927 14:58:22.711781 3126973376 virtual_table.cpp:504] Table file was queried without a required column in the WHERE clause
W0927 14:58:22.711817 3126973376 virtual_table.cpp:515] Please see the table documentation: <https://osquery.io/docs/#file>
osquery> select * from file where path like '/etc/pass%';
+------------------------------+-----------+-------------------------+-----------+-----+-----+------+--------+------+------------+------------+------------+------------+------------+------------+---------+
| path | directory | filename | inode | uid | gid | mode | device | size | block_size | atime | mtime | ctime | btime | hard_links | type |
+------------------------------+-----------+-------------------------+-----------+-----+-----+------+--------+------+------------+------------+------------+------------+------------+------------+---------+
| /etc/passw | /etc | passw | 76659120 | 0 | 0 | 0644 | 0 | 0 | 4096 | 1473445099 | 1446856997 | 1474861711 | 1446856997 | 1 | regular |
| /etc/passwd | /etc | passwd | 159639 | 0 | 0 | 0644 | 0 | 5253 | 4096 | 1475013232 | 1449653044 | 1449900741 | 1400530452 | 1 | regular |
| /etc/passwd~orig | /etc | passwd~orig | 113519665 | 0 | 0 | 0644 | 0 | 6393 | 4096 | 1469907156 | 1469907156 | 1474861344 | 1469907156 | 1 | regular |
| /etc/password_change_message | /etc | password_change_message | 21911409 | 0 | 0 | 0644 | 0 | 96 | 4096 | 1473445108 | 1418673879 | 1474861711 | 1418673879 | 1 | regular |
+------------------------------+-----------+-------------------------+-----------+-----+-----+------+--------+------+------------+------------+------------+------------+------------+------------+---------+