are they a asleep? also, there is a built in concept of splay/delay so that all hosts never return results to the same query at the same time. lots of variables to think through.
k
Kathy Satterlee
02/21/2025, 10:06 PM
It could certainly be the case that queries ran while hosts were offline, and then results sent when they came back online.
The built in splay is +-10%, so that's likely not a huge factor here.
Kathy Satterlee
02/21/2025, 10:10 PM
Your osquery logger settings could also be a factor.
v
Vinny
02/22/2025, 3:45 AM
Anything pops out?
k
Kathy Satterlee
02/22/2025, 9:06 PM
That all looks pretty standard, it sounds like the hosts were likely unable to send logs, then batched them together when they were. If other hosts were able to send during the time, it points to these specific hosts not being online.