osquery-1/osquery/core
Seshu Pasam 6fab8b6083 logging: adding "counter" to differentiate initial results (#3651)
When setting up alerts for differential logs data you might want to skip the
initial added records. counter can be used to identify if the added records
are all records from initial query of if they are new records. For initial
query results that includes all records counter will be "0". For subsequent
query executions counter will be incremented by 1. When epoch changes, counter
will be reset back to "0".
2017-09-07 15:01:15 -07:00
..
darwin corrected size in block_devices on darwin, linux (#3539) 2017-08-07 19:21:18 -07:00
posix Combine osqueryi and osqueryd into single binary (#2742) 2017-08-27 11:09:25 -07:00
tests logging: adding "counter" to differentiate initial results (#3651) 2017-09-07 15:01:15 -07:00
windows Combine osqueryi and osqueryd into single binary (#2742) 2017-08-27 11:09:25 -07:00
CMakeLists.txt Combine osqueryi and osqueryd into single binary (#2742) 2017-08-27 11:09:25 -07:00
conversions.cpp Add base64 encode and decoding functions (#3312) 2017-05-24 09:38:10 -07:00
conversions.h [Fix #2734] Remove OpenSSL link dependency for osquery core (#2750) 2016-12-22 00:37:59 -08:00
flags.cpp flags: Allow custom flags in configuration (#3301) 2017-05-25 21:29:31 -07:00
init.cpp worker: shutdown safely on Windows only if not worker (#3628) 2017-08-30 08:45:56 -07:00
json.h [Distributed] Moving to RapidJSON (#3265) 2017-08-07 16:34:44 -07:00
process.h extensions: Preserve environment in auto-loaded extensions (#3101) 2017-03-24 18:47:23 -07:00
query.cpp logging: adding "counter" to differentiate initial results (#3651) 2017-09-07 15:01:15 -07:00
system.cpp rocksdb: Implement a 'backup' and recover feature for RocksDB (#3635) 2017-09-01 22:31:03 -07:00
tables.cpp Allow caching for tables with indexes and additionals (#3472) 2017-07-18 00:08:38 -07:00
utils.h Updating processes table to include memory (#2573) 2016-10-02 22:41:05 -07:00
watcher.cpp extensions: Call wait on all extensions before respawning (#3516) 2017-08-01 15:16:22 -07:00
watcher.h extensions: Call wait on all extensions before respawning (#3516) 2017-08-01 15:16:22 -07:00