osquery-defense-kit/incident_response/unified_log_macos.sql
Dave Smith 3a005452ee
add extra tag to unified_log_macos.sql
Signed-off-by: Dave Smith <dave.smith@chainguard.dev>
2024-10-25 10:53:19 -04:00

9 lines
135 B
SQL

-- Retrieves recent entries from the macOS unified log
--
-- tags: postmortem extra
-- platform: darwin
SELECT
*
FROM
unified_log;