07/02/2020, 7:56 AM
hi, I'm writing a custom logger plugin on a windows server that logs to one of my rest services, running "select value from osquery_extensions;" from osqueryi gives "\.\pipe\shell.em", running the same query from osqueryd schedule gives "\.\pipe\osquery.em", when my plugin runs, it hangs on connecting to the named pipe, I wonder how I can fix it.


07/02/2020, 11:02 AM
On windows, names pipes are in their own pseudo file systems. The pipe part denotes that. You can't find it on the filesystem directly.
11:03 AM
Usually osquery would start the extension, and pass it the name/path of the pipe as an argument.