Andrew Farley

11/09/2021, 11:11 PM
Suppose I should have checked that before posting! Assuming none of those apply, what reasons could there be that no events are populating in file_events. I've modified my config file to include the paths I want monitored and included the options mentioned in the documentation. Still that table is sitting empty.

Mike Myers

11/10/2021, 5:34 PM
With evented tables, you'll want to make sure you are passing the osquery flags for explicitly enabling events and the "event publisher" within osquery, otherwise the table might be empty. Run with
to see if there are any errors starting the publisher.