ccombs
02/09/2021, 7:30 PMepoch
works when it comes to distributed queries. I've tried looking through the documentation but it doesn't seem to be very clear, if epoch
isn't set in the osquery configuration files then is it 0 by default? I'm asking because I'm trying to make differential distributed queries, but I keep getting results back with epoch
and counter
both set to 0 which seems odd.zwass
02/09/2021, 7:33 PMccombs
02/09/2021, 7:55 PMzwass
02/09/2021, 8:00 PMccombs
02/09/2021, 8:41 PM