Open sharon-fdm opened 1 year ago
cc: @zayhanlon @marcosd4h @lucasmrod @zhumo @zwass
One approach to look at might be making osquery take a break between executing distributed queries. IIRC there may actually be a flag that does something like this already?
Yes. --table_delay
, though it applies to all queries, not just distributed, and it involves a delay between scans so a query that uses multiple tables will be delayed longer.
(PS: I found it while troubleshooting watchdog killing some of the macOS CIS queries. So this is on my list of things to try as a workaround.)
Goal
As the customer of Fleet who uses Fleet policies, I would like Fleet to trigger policy queries on my agents in a way that will use agent's resources in a sustainable way so that the agents will stay healthy and not crash.
Changes
This issue's estimation includes completing:
Context
QA
Risk assessment
Risk level: Low / High TODO
Risk description: TODO
Automated:
Manual testing steps
Testing notes
Confirmation