Hussainsab Gurgunni
03/25/2025, 2:40 PM{
"schedule": {
"foobar_win": {
"query": "SELECT * FROM foobar;",
"interval": 10,
"snapshot": true
}
}
}
Working smaple:
{
"snapshot": [
{
"baz": "baz",
"foo": "bar"
},
{
"baz": "baz",
"foo": "bar"
}
],
"action": "snapshot",
"name": "foobar_win",
"hostIdentifier": "DESKTOP-CLKS76M",
"calendarTime": "Sat Mar 22 14:09:26 2025 UTC",
"unixTime": 1742652566,
"epoch": 0,
"counter": 0,
"numerics": false
}
What i have noticed? (in linux it works but in windows it's not)
when i get the error E0322 195053.988317 2444 scheduler.cpp:128] Error executing scheduled query foobar_win: vtable constructor failed: foobar
memory usage and disk usage goes to 100% and also cpu usage goes to 70% which is not consumed by osquery.
this 100% usage issue comes right after i get the vtable constructor failed: foobar
"also noticed 2 process running in the task manager not sure why"
System Information:
• OS: [windows 11 version: 24H2]
• osquery Version: [5.16.0]
Logs and Errors:
I have attached a zip file containing logs, including both working and error states, to help debug the issue.
Let me know if you need any additional details.