moulik
07/18/2020, 9:18 AM<http://portquiz.net:1234|portquiz.net:1234>
If the osquery db and osquery pid is in /tmp/
folder, I see some inconsistency in the number of record in socket_events
table
Sometimes there is only 1 entry and sometimes there are 2 entries for every curl request
If I change the path to a permanent location then I see only one entry per curl requesttheopolis
07/18/2020, 5:06 PMmoulik
07/20/2020, 7:15 AMsocket_events
named mac_sockets_query
Everytime this query is changed, I am getting an extra events in socket_events table
It started with 1 and then increased to 6 events per curl request. Attached csv has data for two curl requests
and 1st time count was 5 and second time it was 6.