Title
#kolide
s

Slackbot

01/14/2019, 9:47 PM
This message was deleted.
zwass

zwass

01/14/2019, 9:50 PM
What do you mean by faster? The query continues retrieving results from any machine that checks in and fits the targets. You are free to stop the query and/or use the results whenever you like.
j

jackjack

01/14/2019, 9:51 PM
9:51 PM
it has been stuck there for quite a while
zwass

zwass

01/14/2019, 9:51 PM
What do you want it to do?
j

jackjack

01/14/2019, 9:51 PM
checked the instance performance (AWS), not overloading
9:51 PM
Just wonder if we can skip the offline machines and only query the online ones
9:52 PM
and this is the query I entered....
zwass

zwass

01/14/2019, 9:52 PM
If it's been there for a while I would assume you got results from all the online machines
j

jackjack

01/14/2019, 9:52 PM
select * from shell_history where command LIKE '%chmod 4777%' OR command LIKE '%chmod u+s%';
9:52 PM
is there a way to only query online endpoints?
zwass

zwass

01/14/2019, 9:53 PM
Only online endpoints are receiving the query
9:53 PM
There is no way for an offline endpoint to receive that query
9:53 PM
Until it comes online
j

jackjack

01/14/2019, 9:54 PM
even though the process bar doesn't change?
9:54 PM
okay thank you Zach! As always
zwass

zwass

01/14/2019, 9:55 PM
I'm not sure what you mean. The progress bar indicates how many of the targeted hosts have responded. Offline hosts can't respond.
9:55 PM
If you want the query to stop you can hit the stop button or leave the page.
j

jackjack

01/14/2019, 9:56 PM
sorry fo the confusion. I think it makes sense to just see it from the query results, because I am parsing it anyway
zwass

zwass

01/14/2019, 9:57 PM
kk cool