Jams
01/06/2020, 10:55 PMwall_time
from osquery_schedule
table is that it’s the unix time difference between the start and end of a query. However, does that imply it’s the difference of when the query was last executed? Further, system_time
& user_time
are both milliseconds and I would have to divide by executions
to understand its performance profile?theopolis
01/06/2020, 11:51 PMJams
01/07/2020, 6:33 PM