wennan.he01/18/2023, 7:32 PM
Kathy Satterlee01/18/2023, 7:39 PM
wennan.he01/18/2023, 10:03 PM
Kathy Satterlee01/18/2023, 10:19 PM
This endpoint tells the server the carve is incoming
This is where the actual carve is sent. By default, carves are stored in the Fleet database and removed after 24 hours.
wennan.he01/18/2023, 10:29 PM
this one is used to send file? what about this one?
Kathy Satterlee01/18/2023, 10:30 PM
wennan.he01/18/2023, 10:30 PM
Kathy Satterlee01/18/2023, 10:32 PM
wennan.he01/18/2023, 10:38 PM
2 the agent will run the distributed query and fetch the file 3 the agent will sent it back to fleet by
is that the right order?
Kathy Satterlee01/18/2023, 10:46 PM
table 2. The host receives the query and osquery starts processing 3. When osquery is ready to send the carve, it sends a request to the
endpoint to start the process 4. The actual carve blocks are then sent by osquery to the
wennan.he01/18/2023, 10:50 PM
table this is happened on agent side right? but who told agent to activate carves feature?
Kathy Satterlee01/18/2023, 10:53 PM
table, either through
, or running a live query in the UI or REST API.
table (through the UI, API or
SELECT * FROM carves WHERE path = <filepath> and carve = 1;
is what tells osquery that this is a new carve.
and carve = 1
wennan.he01/18/2023, 11:08 PM
Kathy Satterlee01/18/2023, 11:09 PM
wennan.he01/18/2023, 11:11 PM
Kathy Satterlee01/18/2023, 11:11 PM