Allow set and override of osquery flags #613
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Adds a new option
--osquery_flag
that allows the user to provide aflag that will be passed directly to osquery. These flags are appended
to all other default and computed flags, allowing them to potentially
override the default and computed flags. This allows users to set flags
that would not otherwise be possible to use with Launcher (like
windows_event_channels
), and also opens up additional uses of Launcherwith overridden options, plugins, etc.
Support is also added to the package tooling to build packages with this
flag set.
Closes #96