clong
10/16/2023, 7:08 PMStefano Bonicatti
10/17/2023, 2:03 PMclong
10/17/2023, 4:48 PMsharvil
10/18/2023, 2:58 PMStefano Bonicatti
10/18/2023, 3:15 PMclong
10/18/2023, 3:17 PMsharvil
10/18/2023, 3:23 PMsharvil
10/18/2023, 3:24 PMSorry, this pull request couldn't be reverted automatically. It may have already been reverted, or the content may have changed since it was merged.
Will create a branch and try it that wayseph
clong
10/18/2023, 7:34 PMseph
clong
10/18/2023, 7:36 PMseph
John Speno
10/18/2023, 7:39 PMseph
clong
10/18/2023, 7:40 PMopen
event_type on MacOS
You have to enable a bunch of flags to enable it:
--enable_file_events
--disable_endpointsecurity=false
--disable_endpointsecurity_fim=false
--es_fim_enable_open_events=true
sharvil
10/18/2023, 7:41 PMseph
sharvil
10/18/2023, 7:43 PMUnless folks have a fix at the ready (days?) I don’t see this landing in 5.10I am working on a fix, cautiously optimistic that it can done in a few days
sharvil
10/18/2023, 7:44 PMseph
Stefano Bonicatti
10/18/2023, 7:46 PMopen
event or the filtering, or both. Because the issue is in the filtering (as far as I understood?), but nothing prevents (I think) having the open
event added?
Also again, is the open
event bugged or the filtering?sharvil
10/18/2023, 7:50 PMclong
10/18/2023, 7:51 PMsharvil
10/18/2023, 7:52 PMStefano Bonicatti
10/18/2023, 8:11 PMclong
10/18/2023, 8:13 PMsharvil
10/19/2023, 9:30 PMsharvil
10/20/2023, 8:27 PMclong
10/20/2023, 8:41 PMseph