actually he said "At least 2x per minute and pihole was letting them through"
s
seph
07/28/2021, 5:21 PM
The kolide endpoint agent is configured to request various configuration and live queries fairly often. Depending on various things, this might be as often as 2x minute.
I’m not sure how DNS cache, and the pihole all come into play though.
If you had a host configured to send all dns requests to a pihole, I imagine you’d see something like that.