Title
#general
Erich Stoekl

Erich Stoekl

04/29/2020, 9:05 PM
Can anyone give me an example of a long-running osquery command?
zwass

zwass

04/29/2020, 9:26 PM
Something that consumes a lot of resources?
Erich Stoekl

Erich Stoekl

04/29/2020, 9:54 PM
something that just runs for a while
9:54 PM
something like a sleep
10:24 PM
but yes, something that uses a lot of resources would be good
zwass

zwass

04/29/2020, 10:28 PM
osquery> .timer ON
osquery> select count(*) from processes;
+----------+
| count(*) |
+----------+
| 400      |
+----------+
Run Time: real 0.003 user 0.001090 sys 0.001459
osquery> select count(*) from processes, processes;
+----------+
| count(*) |
+----------+
| 160000   |
+----------+
Run Time: real 0.417 user 0.137328 sys 0.279141
osquery> select count(*) from processes, processes,processes;
10:28 PM
That will give you exponential growth on runtime
Erich Stoekl

Erich Stoekl

04/29/2020, 10:39 PM
nice, that worked!
10:39 PM
thank you
s

seph

05/01/2020, 11:27 AM
Adding a hashing will consume resources and take longer.
11:27 AM
Curl, maybe