mirror of
https://github.com/valitydev/osquery-1.git
synced 2024-11-07 09:58:54 +00:00
9011123f2d
It is often helpful to know the local timezone of the machine. For this use local_timezone, as the base timezone will use local or UTC depending on the --utc flag. This will be default=UTC in osquery 1.8.0. The datetime field is added to mimic ISO 8601, along with iso_8601. The timestamp field remains as the time stamp used for logging (within osquery) and commonly outside of osquery. The goal for adding multiple representations is to allow joining/augmenting of other tables. |
||
---|---|---|
.. | ||
file.table | ||
hash.table | ||
osquery_events.table | ||
osquery_extensions.table | ||
osquery_flags.table | ||
osquery_info.table | ||
osquery_packs.table | ||
osquery_registry.table | ||
osquery_schedule.table | ||
time.table |