https://github.com/osquery/osquery logo
Title
p

Prakhar

10/17/2018, 11:27 AM
Hey I've some pretty basic doubt. If osqueryd is running and collecting events and I restart the daemon for some reason, would I lose events that were not queried before the restart ? Assuming all those buffer/Rocksdb etc do not run out of size and are well within defined thresholds.
z

zwass

10/17/2018, 5:04 PM
Events that were not queried before the restart will not be lost. They will remain in the RocksDB buffer. Of course, you will miss any events that happened while osquery was not running.
p

Prakhar

10/24/2018, 9:46 AM
Thanks