New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
differential osquery query output to base_topic #5890
Comments
I know @zwass and @alexwoolford were talking in slack, but I'm not sure if there was a conclusion |
Hey @directionless, @zwass suggested that I file a bug in Github: https://osquery.slack.com/archives/C08V7KTJB/p1571159030065500?thread_ts=1571098086.052800&cid=C08V7KTJB, and so I did. I'll gladly jump on a Zoom if you'd like to poke around in my environment to see what's going on. |
I don't know this part of the code base. I'm recording that the conversation happened. The bug is great. |
…0 to master * commit 'eeee0fb0957f5af983f817c2e6f19c53108d9e09': (83 commits) Add additional changelog items (osquery#6523) Changelog for 4.4.0 (osquery#6492) build: Add Azure tables to specs CMakeLists (osquery#6507) CMake: Correct macOS framework linking (osquery#6522) tables: Only populate table cache with star-like selects (osquery#6513) CMake: Fix and cleanup compile flags (osquery#6521) docs: Add note to bump the Homebrew cask (osquery#6519) tests: Fix atom_packages, processes, rpm_packages flakiness (osquery#6518) bug: Do not use system proxy for AWS local authority (osquery#6512) packaging: updating docs on cpack usage to include Chocolatey (osquery#6022) bug: Fix typed_row table caching (osquery#6508) Implement event batching support for Windows tables (osquery#6280) http: Use sync resolve (osquery#6490) Add support for basic chassis information (osquery#5282) Only emit 'denylist' warning once (osquery#6493) docs: Remove references to brew in macOS install (osquery#6494) Fix for osquery#5890: Event Format Results and the Kafka Logger (osquery#6449) make apt_sources table parsing much more resilient (osquery#6482) Make file and hash container columns hidden (osquery#6486) Update documentation to use 'allow list' and 'deny list' diction (osquery#6489) ...
Bug report
versions
CentOS 7.7
osquery 4.0.2
What steps did you take to reproduce the issue?
The
osquery.conf
has the following properties:The output is written to the
process-port
topic. If I toggle thesnapshot
property, the output is written to thebase_topic
. That is, in my opinion, a bug.links:
What did you expect to see?
The differential records should be written to the
process-port
.What did you see instead?
The records are written to
base_topic
.The text was updated successfully, but these errors were encountered: