Channels
doorman
infrastructure
random
zercurity
community-feeds
fleet-dev
code-review
queryhub
apple-silicon
carving
tls
fim
goquery
zentral
aws
querycon
golang
zeek
file-carving
fuzzing
auditing-warroom
linen-dev
fleetosquery
plugins
jobs
arm-architecture
darkbytes
process-auditing
uptycs
android_tests
selfgroup
vendor-feeds
fleet
eclecticiq-polylogyx-extension
ebpf
website
core
general
macos
kolide
osctrl
extensions
foundation
sql
officehours
linux
windows
Powered by
Title
z
zen
01/08/2019, 1:21 AM
As soon as I change it back to the original, it stops working.
p
packetzero
01/08/2019, 1:33 AM
check all your config and packs for same name? Maybe it's defined elsewhere and it's overriding it.
z
zwass
01/08/2019, 1:44 AM
Also, is it running in differential or snapshot mode? If it's running in differential mode you should expect to only see each result logged once.
z
zen
01/08/2019, 1:50 AM
I actually only have that one running to narrow it down, so I don't think it's a name collision.
It's differential but it stops completely. When I change the query name, it behaves the way I'd expect (there are new network connections often).
I even changed the database_path (and restarted osqueryd) and it still doesn't work.
Is there any state stored outside of the DB?
z
zwass
01/08/2019, 1:55 AM
There should not be any state stored outside the DB.
2 Views
#general
Join Slack