I am using osquery for FIM. Have installed the osquery version 5.11. It working fine with mac but for window 11 I am not getting file events. Below errors are printed on consoleā¦
I0221 221847.304080 11332 ntfs_event_publisher.cpp:554] Parent FRN lookup failed: Failed to open the file in volume C:\. Error: The parameter is incorrect.
I0221 221847.306871 11332 ntfs_event_publisher.cpp:544] FRN pathname lookup failed, trying parent: Failed to open the file in volume C:\. Error: The parameter is incorrect.
I0221 221847.310052 11332 ntfs_event_publisher.cpp:554] Parent FRN lookup failed: Failed to open the file in volume C:\. Error: The parameter is incorrect.
I0221 221847.310052 11332 ntfs_event_publisher.cpp:544] FRN pathname lookup failed, trying parent: Failed to open the file in volume C:\. Error: The parameter is incorrect.
I0221 221847.310052 11332 ntfs_event_publisher.cpp:554] Parent FRN lookup failed: Failed to open the file in volume C:\. Error: The parameter is incorrect.
I0221 221847.317608 11332 ntfs_event_publisher.cpp:544] FRN pathname lookup failed, trying parent: Failed to open the file in volume C:\. Error: The parameter is incorrect.
I0221 221847.320739 11332 ntfs_event_publisher.cpp:554] Parent FRN lookup failed: Failed to open the file in volume C:\. Error: The parameter is incorrect.
I0221 221847.320739 11332 ntfs_event_publisher.cpp:544] FRN pathname lookup failed, trying parent: Failed to open the file in volume C:\. Error: The parameter is incorrect.
I0221 221847.327277 11332 ntfs_event_publisher.cpp:554] Parent FRN lookup failed: Failed to open the file in volume C:\. Error: The parameter is incorrect.
I0221 221847.330112 11332 ntfs_event_publisher.cpp:544] FRN pathname lookup failed, trying parent: Failed to open the file in volume C:\. Error: The parameter is incorrect.