Ronny Nordstrand
12/07/2021, 12:59 PM{
"options": {
"config_plugin": "filesystem",
"logger_plugin": "filesystem",
"logger_path": "/var/log/osquery",
"pidfile": "/var/osquery/osquery.pidfile",
"database_path": "/var/osquery/osquery.db",
"disable_database": "true",
"force": "true",
"verbose": "true",
"schedule_default_interval": "300",
"host_identifier": "hostname"
},
"schedule": {
"system_info": {
"query": "SELECT hostname, cpu_brand, physical_memory FROM system_info;"
},
"Packages": {
"query": "select name, version, sha1, install_time, vendor from rpm_packages;"
},
"decorators": {
"load": [
"SELECT uuid AS host_uuid FROM system_info;",
"SELECT user AS username FROM logged_in_users ORDER BY time DESC LIMIT 1;"
]
}
}
}
slevchenko
12/07/2021, 1:02 PMinterval
statements in schedule block, I'd assume that you're relying on distributed execution, is that your case ?Ronny Nordstrand
12/07/2021, 1:05 PMzwass