fleet/schema/tables/asl.yml
Eric 02437a098e
Schema: change default block scalar used in schema override files (#19296)
Closes: #19271
Closes: #19286

Changes:
- Updated the example in the schema folder readme
- Updated the block scalar used in Fleet's osquery override
documentation (`>-` » `|-`) and removed extra newlines
- Updated the block scalar used in URLs used to create new yaml override
files
- Regenerated osqeury_fleet_schema.json
2024-05-27 18:18:56 -05:00

9 lines
354 B
YAML

name: asl
examples: |-
Apple System Logger (ASL) is deprecated since macOS 10.12. On older Macs, this
table can be used to read logs. On newer ones, see the *unified_log* table.
This example is from the osquery documentation.
```
SELECT time, message FROM asl WHERE facility = 'authpriv' AND sender = 'sudo' AND message LIKE '%python%';
```