https://github.com/osquery/osquery logo
Title
z

zen

01/08/2019, 1:21 AM
As soon as I change it back to the original, it stops working.
p

packetzero

01/08/2019, 1:33 AM
check all your config and packs for same name? Maybe it's defined elsewhere and it's overriding it.
z

zwass

01/08/2019, 1:44 AM
Also, is it running in differential or snapshot mode? If it's running in differential mode you should expect to only see each result logged once.
z

zen

01/08/2019, 1:50 AM
I actually only have that one running to narrow it down, so I don't think it's a name collision.
It's differential but it stops completely. When I change the query name, it behaves the way I'd expect (there are new network connections often).
I even changed the database_path (and restarted osqueryd) and it still doesn't work.
Is there any state stored outside of the DB?
z

zwass

01/08/2019, 1:55 AM
There should not be any state stored outside the DB.