👋 I know you can specify the name of a saved query in
option but is it possible to pass in an entire query pack to
to run multiple distributed queries? I can see this being useful for IR — and you could pipe the results of those queries into custom tooling for further parsing or automation.
06/30/2020, 10:54 PM
That wouldn't be hard to implement with a script.
07/01/2020, 6:19 PM
Thanks @zwass I can look to script that up. Related
question. When running the following distributed query,
query --hosts 1234 --query SELECT * FROM file where path like '/Users/%/Desktop/%'
But I can see the actual results of that query in the Fleet UI. I was running this query to make sure that the osquery had Full Disk Access but I was curious why it wouldn't print those results to my terminal.
07/01/2020, 6:20 PM
It's definitely the exact same query text in the UI vs. fleetctl?
07/01/2020, 6:27 PM
Yup. I also just tried
SELECT * FROM users LIMIT 1
in the UI and with
. I can see results in the UI but I get the following with