the fact that you're seeing that indicates either ...
# general
y
the fact that you're seeing that indicates either extremely high disk activity (we're reading from a ring buffer) or a bug in the NTFS journal reader, which might be possible if they changed formats underneath us
s
There's a ticket about this... can you dump this great summery into it?
y
yep!
could you link the ticket? i don't see it with a quick search, might just be missing it...
s
https://github.com/osquery/osquery/issues/5848 i added ntfs to the subject, since searching for it is impossible
Feel free to make it saner
y
thanks!
actually, that's a slightly different bug 😅 -- sometimes FRN-to-path mapping fails (maybe also because of high I/O load), but the failure that he's seeing is caused by record-to-previous-record mapping
i'll create a new issue tracking it