Examples and solutions for 10 common osquery problems.
- User context when executing queries.
- Order of tables in
JOIN
can be significant.
- Large files and the
--read_max
flag.
- JSON escaping and query packs.
- CLI flags vs. configuration options.
- Understanding schedule intervals.
- Events in
osqueryd
and osqueryi
.
- Tuning event expiration flags.
- Event publisher status.
- Identifying expensive queries.
Download PDF