ccombs
02/09/2021, 7:30 PMepoch
works when it comes to distributed queries. I've tried looking through the documentation but it doesn't seem to be very clear, if epoch
isn't set in the osquery configuration files then is it 0 by default? I'm asking because I'm trying to make differential distributed queries, but I keep getting results back with epoch
and counter
both set to 0 which seems odd.zwass
ccombs
02/09/2021, 7:55 PMzwass
zwass
ccombs
02/09/2021, 8:41 PM