osquery-defense-kit/kernel/unusually-long-uptime.sql

9 lines
256 B
SQL

-- Indicative of a machine that probably needs a reboot
SELECT os_version.name AS os_name,
os_version.version AS os_version,
kernel_info.version AS kernel,
days AS uptime_days
FROM kernel_info,
os_version,
uptime
WHERE uptime.days > 60;