https://github.com/osquery/osquery logo
Title
d

demonbhao

10/22/2020, 7:26 AM
Hello, does differentiore (lgnore Removals) mean Differential query?For example, when querying the server for an abnormal process, the content of the query in this hour is compared to the query in the last hour. If there are other processes in this hour, the result log will be generated. Another question is what does action: add mean in the results log.
b

blaedj

10/22/2020, 1:13 PM
yep, I think that you're understanding it correctly
d

demonbhao

10/23/2020, 1:34 AM
But the actual result of the query is not what I understand it to be, and the same process warnings often appear in the result log
b

blaedj

10/23/2020, 1:49 PM
hm, can you give an example of the log you don't expect? (just a snippet is fine, and feel free to redact any sensitive information)
d

demonbhao

10/26/2020, 2:26 AM
The time I sent the pack was 11:00 the interval was 3600s but the log time was not just an hour later