I’ve just found a neat way to abuse sqlite quoting...
# core
s
I’ve just found a neat way to abuse sqlite quoting to handle selecting against columns that may not exist in all versions. I’m not sure this is a good idea — it abuses a documented quoting quirk. But I’m laughing a bunch about it.
Copy code
osquery> select total_seconds, CASE WHEN "future_column" IS NOT 'future_column' THEN "future_column" END AS 'future_column' from uptime;
+---------------+---------------+
| total_seconds | future_column |
+---------------+---------------+
| 1176197       |               |
+---------------+---------------+