Carl
02/19/2020, 5:04 PMselect
socket_events.remote_port,
socket_events.remote_address,
process_events.cmdline,
process_events.pid
from socket_events
join process_events on process_events.pid = socket_events.pid
seph
02/19/2020, 6:51 PMselect * process_events
won’t return the same data twice.
Maybe join against the process table instead?Carl
02/19/2020, 6:52 PMseph
02/19/2020, 6:52 PMCarl
02/19/2020, 6:52 PMseph
02/19/2020, 6:54 PMprocesses
is the current processes. process_events
is closer to to an event stream. In a CEP system, you’d want windowing functions on the event streams, but I haven’t seen stuff like that for osquery.Carl
02/19/2020, 6:54 PMseph
02/19/2020, 6:55 PM