Luis Gomez
05/26/2021, 7:15 AMosquery_schedule have a last_executed = 0 ? I have enabled the osx-attack pack but no queries seem to be running, I left the default Intervals and I'm using filesystem logging. If this is not the right place to ask this let me know where thanks! :)Luis Gomez
05/26/2021, 7:16 AMallister
05/26/2021, 8:44 AMallister
05/26/2021, 8:44 AMLuis Gomez
05/26/2021, 8:50 AMLuis Gomez
05/26/2021, 8:50 AMLuis Gomez
05/26/2021, 8:51 AM➜ ~ sudo osqueryctl status
com.facebook.osqueryd is running. pid: 10799allister
05/26/2021, 8:52 AMallister
05/26/2021, 8:54 AMallister
05/26/2021, 8:55 AMallister
05/26/2021, 8:56 AMLuis Gomez
05/26/2021, 8:57 AMosquery_schedule tableLuis Gomez
05/26/2021, 8:58 AMlast_executed = 0?Luis Gomez
05/26/2021, 8:58 AMosqueryd.results.log which is fineLuis Gomez
05/26/2021, 8:58 AMLuis Gomez
05/26/2021, 8:58 AMLuis Gomez
05/26/2021, 8:59 AMLuis Gomez
05/26/2021, 8:59 AMLuis Gomez
05/26/2021, 8:59 AMallister
05/26/2021, 9:00 AMLuis Gomez
05/26/2021, 9:00 AMLuis Gomez
05/26/2021, 9:00 AMallister
05/26/2021, 9:01 AMLuis Gomez
05/26/2021, 9:04 AMlast_executed column in the osquery_schedule was doing that but not sure anymoreLuis Gomez
05/26/2021, 9:05 AMLuis Gomez
05/26/2021, 9:05 AMLuis Gomez
05/26/2021, 9:05 AMallister
05/26/2021, 9:49 AMallister
05/26/2021, 9:49 AMLuis Gomez
05/26/2021, 10:11 AMzwass
osquery_schedule in osqueryi?Luis Gomez
05/26/2021, 4:02 PMLuis Gomez
05/26/2021, 4:03 PMSELECT * from osquery_schedule WHERE last_executed > 0 ; running this query in osqueryi gives nothingLuis Gomez
05/26/2021, 4:06 PMLuis Gomez
05/26/2021, 4:08 PMLuis Gomez
05/26/2021, 4:08 PMzwass
zwass
zwass
Luis Gomez
05/26/2021, 4:32 PMLuis Gomez
05/26/2021, 4:32 PMzwass
osquery_schedule table, but that new .connect command is a good option for ad-hoc analysis)Luis Gomez
05/26/2021, 4:44 PM