zwass
08/09/2018, 4:56 PM_events
tables will be collecting events as long as osqueryd
is running, and then when you query them you will get all the events since the last query was executed.Mustafa
08/09/2018, 6:01 PMzwass
08/09/2018, 6:03 PMusb_events
table? I can only find usb_devices
which is not event based. There is also hardware_events
which is event based.Mustafa
08/09/2018, 6:04 PMzwass
08/09/2018, 6:09 PMusb_devices
gives you the state when the query is runhardware_events
will catch all events