List pending updates/patch for MAC os x
SCHEMA
package_id | string | Label packageIdentifiers |
recommended | string | recommended |
restart | string | restart |
size | long | Size of the update |
title | string | Title of the update |
uid | long | The local user that owns the plugin |
version | string | Plugin short version |
-- pending_osx_updates_patch INFO SELECT -- Device ID DETAILS meta_hostname, meta_ip_address, -- Query Details query_name, package_id, recommended, restart, size, title, uid, version, -- Decoration meta_boot_time, meta_eid, meta_endpoint_type, meta_ip_mask, meta_mac_address, meta_os_name, meta_os_platform, meta_os_type, meta_os_version, meta_public_ip, meta_query_pack_version, meta_username, --- Generic calendar_time, counter, epoch, host_identifier, numerics osquery_action, unix_time, -- Data Lake customer_id, endpoint_id, upload_size FROM xdr_data WHERE query_name = 'pending_osx_updates_patch'
We need MAC in the data lake before we can test and confirm