dose the osqueryd return the osuqery results interval as you define in the schedule? what's your meaning of "is it generally considered good practice to limit scheduled queries to return results only for the period since the last time the query ran"? @shed7
11/06/2018, 8:27 AM
The queries return fine, it was just a general question about how to do scheduled queries. For example a scheduled query that joins rows from socket_events and process_events every 30 seconds, should itbalso have a WHERE clause restricting the results being joined to only those that were generated since the last query ran 30 seconds ago? But then I see the audit_expiry flag that when set to 1 means results will only last one query, so maybe it's not needed.
11/06/2018, 9:35 AM
yeah，you can have a WHERE clause like this "WHERE time > strftime('%s','now')-360"