@here I am new to osquery like to clarify few ques...
# general
p
@here I am new to osquery like to clarify few questions. 1) if there is no change in the table the schedule interval query result will not be added to log file ? 2) is there a way to configure to output each query into a new output file
p
For regular queries, only new / different rows are written to the log stream. To make the output write everytime, you need to make the schedule query
snapshot
type. Then they will be written into the osqueryd.snapshot.log file.
p
@Prateek Kumar Nischal please also suggest on the 2 point
p
New output file, for that you will need to write your own logging plugin. At the time AFAIK, there isn't much control (intentionally) on the logger..
p
@Prateek Kumar Nischal ok thanks
s
I like this post a lot explaining how it works https://blog.kolide.com/osquery-under-the-hood-c1a8df46bb7a
p
thanks @spookerlabs nice article
👍 1