I posed this question awhile back, and figured an ...
# general
b
I posed this question awhile back, and figured an upgrade would fix my issues, but, still seeing it. I'm sending all my osquery logs to Splunk locally, and I'm working on alerting on
/etc/hosts
modifications, and it seems every 7 days I see the event being
added
again, thus generating an alert. It looks like this is happening for
hosts_file
and
disk_encryption
, but I'm sure there are others, just two that I noticed right away.