• we use benchmarks to create artificial constant rate of process events per second
• we monitor CPU, RAM, & diskIO
• we monitor the osquery logs to see when event buffers overflow
one finding i wanted to share - we set
on our eventing queries and measured a 5X increase in the events per second throughput of
before we saw events buffers overflow
01/18/2020, 3:06 PM
Do your queries on
look similar to
select * from process_events
or are they more complex?
01/18/2020, 3:06 PM
they are more complex. we join on stuff like process table & process_containers table
those joins seemingly have no real perf impact
01/18/2020, 3:07 PM
ah, cool, I asked because I think there's some under the hood logic to detect simple queries against
tables and turn on
for you (I am going from memory though)
01/18/2020, 3:08 PM
we have about the same performance whether we join to the tables or not
this is worth investigating, thanks for sharing the analysis!
01/18/2020, 6:02 PM
One thing that this brings up for me... If someone has
on, then we can probably skip the diffing step on a differential query to an event-based table... the results should all be "added".
01/18/2020, 6:03 PM
@zwass - kinda naively assumed that was how things were working. we had
on our event queries and had
. it surprised me how much of a difference
made for the audit data.
01/18/2020, 6:06 PM
The major difference in perf I would anticipate for snapshot vs. differential would be the diffing step. Both generate the results in approximately the same way. Someone would have to have special-cased the diffing for event-based tables -- I'm not sure that has been done.
01/18/2020, 6:08 PM
my read says it hasn’t been
01/18/2020, 6:09 PM
Seems ripe for doing!
01/18/2020, 6:16 PM
there is code related to
that introspects the query on a specific event table. potentially a cheap spot to simply flip the
option on for the
sounds cleaner in some respects than special-casing the diffing logic
01/18/2020, 6:26 PM
It's an interesting idea. snapshot vs. diff queries have different log schema so that could be an issue.
01/18/2020, 8:58 PM
a doc update recommending
would even go a long way
people who care about event perf have read every doc