zwass
_events tables will be collecting events as long as osqueryd is running, and then when you query them you will get all the events since the last query was executed.Mustafa
08/09/2018, 6:01 PMMustafa
08/09/2018, 6:02 PMMustafa
08/09/2018, 6:03 PMzwass
usb_events table? I can only find usb_devices which is not event based. There is also hardware_events which is event based.Mustafa
08/09/2018, 6:04 PMMustafa
08/09/2018, 6:05 PMzwass
usb_devices gives you the state when the query is runzwass
hardware_events will catch all events