Channels
doorman
infrastructure
random
zercurity
community-feeds
fleet-dev
code-review
queryhub
apple-silicon
carving
tls
fim
goquery
zentral
aws
querycon
golang
zeek
file-carving
fuzzing
auditing-warroom
linen-dev
fleetosquery
plugins
jobs
arm-architecture
darkbytes
process-auditing
uptycs
android_tests
selfgroup
vendor-feeds
fleet
eclecticiq-polylogyx-extension
ebpf
website
core
general
macos
kolide
osctrl
extensions
foundation
sql
officehours
linux
windows
Powered by
Title
z
zwass
08/03/2018, 5:57 PM
If you run the query like that with
osqueryi
it's going to try to get the results immediately which means there will be no events.
n
nebi
08/03/2018, 6:03 PM
@zwass
so how should I query for ?
3 Views
#general
Join Slack