Jamie Windley
01/03/2020, 5:18 PMExpiring events for subscriber: process_events (overflowed limit 50000)
. I have added a flag for --events_expiry=1
and rebooted but still no luck. I get no results when running select * from process_events
in the osqueryi
shell. Any advice/ideas please? My configuration is exactly as per the osquery documentation and was working fine a few months ago