As soon as I change it back to the original, it st...
# general
z
As soon as I change it back to the original, it stops working.
p
check all your config and packs for same name? Maybe it's defined elsewhere and it's overriding it.
z
Also, is it running in differential or snapshot mode? If it's running in differential mode you should expect to only see each result logged once.
z
I actually only have that one running to narrow it down, so I don't think it's a name collision.
It's differential but it stops completely. When I change the query name, it behaves the way I'd expect (there are new network connections often).
I even changed the database_path (and restarted osqueryd) and it still doesn't work.
Is there any state stored outside of the DB?
z
There should not be any state stored outside the DB.