10/11/2021, 3:41 PM
Please see https://osquery.readthedocs.io/en/stable/development/pubsub-framework/ on how osqueryi and _events tables are not compatible. In other words, run osquery as a daemon for the FIM feature.
Stefano Bonicatti

Stefano Bonicatti

10/11/2021, 5:12 PM
@Jams @sonal k It’s possible to receive events while in the shell, for testing; but as far as I can see the table used is a Windows one, and the file paths configured are for Linux
5:13 PM
Also, I wouldn’t modify the pidfile; it has its own default

sonal k

10/12/2021, 12:11 PM
I was able to resolve it. 👍