01/22/2019, 7:21 AM
Hi I'm working on writing a discovery query for a pack. My use case is to disable event based queries (in a pack) if 'auditd' is running on the system. So, discovery query should return 0 rows if any process name matching '%auditd%' is present else return 1 or more rows. Any pointers on how to achieve this ? Thanks
9:27 PM
i’m not sure if you can disable queries via a discovery query though, which seems to be what you are asking
9:28 PM
you might be able to do some craziness with sql to have it return “null” if auditd is running