Juan Alvarez
04/06/2021, 2:23 PMwindows_events
table. I have configured a pack to retrieve all the events generated, but mainly returning empty every time. Sporadically, some output comes out but almost all events are never returned. Same setup was working properly in 4.6.0. Have anyone experienced something similar? Can anybody suggest a good way to debug this? If I enable --verbose
when running osqueryd i can only see the packs running properly but no output comes from the queries.