hold on, double-checked the docs. Appears I have to manually specify ‘removed: false’ in the pack config? I have not, but the UI shows that the pack/queries are set to diff-ignore.
07/16/2018, 11:47 PM
Did you configure these packs via the UI or
07/16/2018, 11:49 PM
fleetctl. This does appear to be a bug of some kind, still confirming.
When creating a query pack config file, if ‘removed:false’ is not specified, the mode defaults to including removals. However, the UI displays the ‘Differential (Ignore Removals)’ option.
When ‘removed:true’ is used, the UI displays the correct selection - ‘Differential’
I am unsure what is expected default mode if the ‘removed:true/false’ line is not included.