04/30/2021, 10:35 PM
what could be the reason why a query like
select * from os_version
would fail (not return any snapshot result) but a query like
SELECT * FROM processes
would succeed (returns snapshot result) on a given device when ran at the same time in a query pack?
Noah Talerman

Noah Talerman

05/03/2021, 1:27 PM
Do the results for the
query eventually appear? Or do you never see the results? If the results eventually appear, your host may be buffering logs (see the osquery documentation here on remote logging buffering).