Hey friends, for events while audit is capturing timestamps with milliseconds in its logs, osquery’s audit publisher is dropping them here: https://github.com/osquery/osquery/blob/master/osquery/events/linux/auditeventpublisher.cpp#L283 — that granularity and data would be great, as audit is already capturing it . Maybe a new column just for the milliseconds can solve this? (not sure if that’s the best idea)