Woogs
03/15/2019, 10:41 PMzwass
03/15/2019, 10:44 PMWoogs
03/16/2019, 8:01 PMzwass
03/17/2019, 7:54 PMWoogs
03/18/2019, 3:52 AM"filename":"query.cpp","line":"115","message":"Scheduled query has been updated: pack/
followed by the pack name/query name that it thinks is changing. Except its listing queries that definitely haven't changed in months. So for some reason osquery thinks the query is changing.zwass
03/19/2019, 2:42 AMWoogs
03/19/2019, 5:57 PMzwass
03/20/2019, 4:23 PMWoogs
03/20/2019, 5:50 PMI0320 15:21:37.129468 33521 scheduler.cpp:100] Executing scheduled query pack/BaseSystemInfo/groups: SELECT * FROM groups where gid<10000;
I0320 15:21:37.137094 33521 query.cpp:115] Scheduled query has been updated: pack/BaseSystemInfo/groups
"groups": {
"query": "SELECT * FROM groups where gid\u003c10000;",
"interval": 86400,
"platform": "",
"version": "",
"removed": true
},