Martin Lee09/25/2019, 9:26 AM
seph09/25/2019, 2:29 PM
There is no database on disk to hit. I do not think it’s easy to connect osqueryi to the launcher distributed tables.
Martin Lee09/25/2019, 2:30 PM
from the docs
osqueryi uses an in-memory database by default. To connect to an existing events database, use the flag --database_path=/var/osquery/osquery.db (only one process may attach to the database; see Checking the database sanity).