CptOfEvilMinions
03/24/2022, 8:40 PM2022-03-23 07:53:27
Worker returned exit status
2022-03-23 07:53:08
Error logging the results of query: pack/test-pack/BPF_PROC_EVENTS: IOError: Bad file descriptor
2022-03-23 07:53:08
Error adding new results to database for query pack/test-pack/BPF_PROC_EVENTS: IOError: Bad file descriptor
2022-03-23 07:52:53
RocksDB: [ERROR] [db/db_impl/db_impl_compaction_flush.cc:2541] Waiting after background compaction error: IO error: While appending to file: /var/osquery/osquery.db/052008.sst: Bad file descriptor, Accumulated background error counts: 1
2022-03-23 07:52:53
RocksDB: [WARN] [db/error_handler.cc:334] Background IO error IO error: While appending to file: /var/osquery/osquery.db/052008.sst: Bad file descriptor
2022-03-23 07:52:53
RocksDB: [WARN] [db/db_impl/db_impl_compaction_flush.cc:3019] Compaction error: IO error: While appending to file: /var/osquery/osquery.db/052008.sst: Bad file descriptor
eBPF flags
#### Process Auditing ####
--disable_events=false
--enable_bpf_events=true
--events_optimize=true
--events_expiry=3600
--events_max=200000
Pack queries:
SELECT * FROM bpf_socket_events WHERE local_port != 0;
SELECT * FROM bpf_process_events;
alessandrogario
CptOfEvilMinions
03/24/2022, 9:19 PMosqueryd --version
osqueryd version 5.1.0
alessandrogario
CptOfEvilMinions
03/28/2022, 6:44 PMalessandrogario
CptOfEvilMinions
03/29/2022, 5:22 PMalessandrogario
npamnani
03/30/2022, 7:28 AMCptOfEvilMinions
04/06/2022, 5:09 PM-1
.alessandrogario