"schedule": { // This is a simple example quer...
# general
y
"schedule": { // This is a simple example query that outputs basic system information. "system_info": { // The exact query to run. "query": "SELECT hostname, cpu_brand, physical_memory FROM system_info;", // The interval in seconds to run this query, not an exact interval. "interval": 3600 }, "file_events": { "query": "SELECT * FROM file_events;", "removed": false, "interval": 300 } }, "file_paths": { "homes": [ "/root/.ssh/%%", "/home/%/.ssh/%%" ], "etc": [ "/etc/%%" ], "tmp": [ "/tmp/%%" ] }, "exclude_paths": { "homes": [ "/home/not_to_monitor/.ssh/%%" ], "tmp": [ "/tmp/too_many_events/" ] },