we stumbled on an interesting nuance with updating osquery this morning. between stable and the upcoming 3.2 release, the schema changed for a table we had in a single device’s config.
we found a buffered log that was emitted, which had log lines from both versions of osquery. this created a structure like this:
[
{"foo": "bar", "bit": "baz},
{"foo": "bar", "bit": "baz},
{"foo": "bar", "bit": "baz, "bot": "buz"},
{"foo": "bar", "bit": "baz, "bot": "buz"}
]
this caught our downstream parsing off guard, so i figured i’d point it out