demonbhao
11/11/2020, 9:11 AMtheopolis
11/12/2020, 12:42 AMdemonbhao
11/12/2020, 2:22 AMtheopolis
11/12/2020, 2:29 AMSELECT * FROM system_info
then change that query to SELECT * from system_info
the results will be invalidated and the epoch will restart at 0. The action indicates if the row was observed as added (newly observed) or removed (no longer existing). This page goes into some detail about these metadata fields: https://osquery.readthedocs.io/en/latest/deployment/logging/#schedule-resultsdemonbhao
11/12/2020, 2:36 AMtheopolis
11/16/2020, 6:57 PMsnapshot:true
query? I am not sure what this looks like in the Fleet UI but a snapshot-type query skips the differential comparison.demonbhao
11/17/2020, 2:05 AMtheopolis
11/20/2020, 1:36 AMdemonbhao
11/20/2020, 3:35 AM