https://github.com/osquery/osquery logo
Title
c

clong

05/05/2017, 3:41 AM
so for example, maybe i want to know about some set of data ASAP, but i only want that query to run once a week. normally i’d just set the interval to 604800, but then i would have to wait a week to get my initial set of results
s

Seshu

05/05/2017, 4:17 AM
clong: Don't think you can do that now. Unless you track when osquery was last active and use distributed read for running the queries immediately!
r

robert.davis

05/05/2017, 7:13 PM
@Seshu @clong that's how I am handling this as well. Have a distributed_read set of queries that are sent to the endpoint right after enrollment.
👍 2