https://github.com/osquery/osquery logo
y

yossarian

07/13/2021, 7:32 PM
the fact that you're seeing that indicates either extremely high disk activity (we're reading from a ring buffer) or a bug in the NTFS journal reader, which might be possible if they changed formats underneath us
s

seph

07/13/2021, 8:43 PM
There's a ticket about this... can you dump this great summery into it?
y

yossarian

07/13/2021, 9:53 PM
yep!
could you link the ticket? i don't see it with a quick search, might just be missing it...
s

seph

07/13/2021, 9:58 PM
https://github.com/osquery/osquery/issues/5848 i added ntfs to the subject, since searching for it is impossible
Feel free to make it saner
y

yossarian

07/14/2021, 1:52 PM
thanks!
actually, that's a slightly different bug 😅 -- sometimes FRN-to-path mapping fails (maybe also because of high I/O load), but the failure that he's seeing is caused by record-to-previous-record mapping
i'll create a new issue tracking it
2 Views