Skip to content

fix(schema): CU-17tkuw5w11d document Windows event-log filters - #112

Merged
yevhenii-flamingo merged 1 commit into
masterfrom
feat/document-windows-eventlog-filters
Oct 9, 2026
Merged

yevhenii-flamingo merged 1 commit into
masterfrom
feat/document-windows-eventlog-filters

Conversation

@yevhenii-flamingo

@yevhenii-flamingo yevhenii-flamingo commented Oct 9, 2026 •

Copy link
Copy Markdown

Ticket: https://app.clickup.com/t/9013925967/17tkuw5w11d
Change-Set: feat-document-windows-eventlog-filters

Summary

  • Document windows_eventlog.time_range as semicolon-separated UTC timestamps with inclusive bounds, including its precedence over timestamp.
  • Explain that timestamp is a lookback duration in milliseconds relative to the device clock.
  • Document the QueryList XML format for xpath and its incompatibility with channel, time_range, and timestamp.
  • Add examples for a fixed UTC interval and the last three hours of errors/warnings.

Compatibility

  • Metadata-only change in one Windows table specification; column names, types, flags, table registration, and query implementation are unchanged.
  • Generated native/foreign C++ and typed-row header are byte-identical before and after the change. No frontend, persistence, or event contracts change.
  • The existing schema exporter includes these descriptions and examples in release JSON without a format change; no tenant/library code change is required to consume them.

Release risks

  • Publish a new osquery release, then select that tag on QA. Existing stable 0.0.9 assets do not gain the new metadata from this PR.
  • A successfully cached catalog has no expiry. Republishing mutable latest does not refresh an existing AI-process cache; use a new stable tag for QA verification.
  • No migrations, feature flags, or dependency changes. This improves the schema information supplied to the model, but does not enforce SQL correctness or prove absence of events; model/device regression remains required.
  • Fifteen exporter tests and Windows catalog generation passed locally; generated C++ is unchanged. A full binary rebuild and live Windows/model regression were not performed locally.

Change set flamingo-stack/feat-document-windows-eventlog-filters: this pull request is the only one in it so far. Another pull request joins by naming this one in a Depends-On line, or by carrying the same Change-Set line.

Linked work

Linked by the Depends-On / Change-Set lines in these descriptions; this block is maintained by the hub.

@github-actions

github-actions Bot commented Oct 9, 2026

Copy link
Copy Markdown

🦩 Flamingo Code Review

Not reviewed yet. Reviews start when you ask, so the reviewer reads this pull request when it is ready, not when it is opened.

When it is ready:

  • Review this pull request

Or comment @flamingo-review. Add the flamingo-review-always label to review every push.

Updated 2026-10-09 18:28 UTC · workflow run

@yevhenii-flamingo
yevhenii-flamingo merged commit a957569 into master Oct 9, 2026
15 checks passed
@yevhenii-flamingo
yevhenii-flamingo deleted the feat/document-windows-eventlog-filters branch October 9, 2026 18:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants