clong
12/02/2020, 7:35 PMsigfile LIKE 'c:\path\to\yara\%.yar
?Juan Alvarez
12/02/2020, 7:49 PMDec 2 19:46:52 ubuntu-bionic osqueryd[1098]: I1202 19:46:52.229655 1590 distributed.cpp:121] Executing distributed query: kolide_distributed_query_245: SELECT * FROM yara where path LIKE "/home/%" and sigfile LIKE '/vagrant/tmp/%.sig'
Dec 2 19:46:52 ubuntu-bionic osqueryd[1098]: I1202 19:46:52.230664 1590 yara.cpp:333] Query must specify sig_group, sigfile, or sigrule for scan
clong
12/02/2020, 7:52 PMJuan Alvarez
12/02/2020, 7:52 PMclong
12/02/2020, 7:52 PMJuan Alvarez
12/02/2020, 7:52 PMclong
12/02/2020, 7:53 PM