teoseller
07/05/2018, 12:57 PMyuvalapidot
07/05/2018, 1:44 PMteoseller
07/05/2018, 3:01 PMyuvalapidot
07/09/2018, 8:22 AMteoseller
07/09/2018, 10:40 AMyuvalapidot
07/09/2018, 10:56 AMselect * from windows_events
.
Afaik, the windows_events tables (though ends with '_events') is not a pure osquery event table - thus you can try query it even in osqueryi if you use the proper flags. Nevertheless, using scheduled query for event tables is probably preferable - using Kolide fleet or any other fleet management tool can be useful for you but not mandatory, you can also log scheduled queries to a log file and read it from there.teoseller
07/09/2018, 12:30 PM