wennan.he
10/13/2022, 5:40 PM--disable_events=false
, --enable_file_events=true, --disable_audit=false and --enable_ntfs_event_publisher=true, then i restart osquery but when i login osqueryi and check osquery_flags, i can see the value of them not changed. plz advice.Stefano Bonicatti
10/13/2022, 5:42 PMosqueryi
is not, by default, a client to the daemon; the osqueryi
binary is a link (or a copy on Windows) to the daemon, it’s the same binary that starts as a shell instead of a daemonwennan.he
10/13/2022, 5:43 PMStefano Bonicatti
10/13/2022, 5:44 PMosqueryi
shell you can use the .connect PATH
command, with PATH the path to the extensions socket.wennan.he
10/13/2022, 5:46 PMStefano Bonicatti
10/13/2022, 5:47 PMwennan.he
10/13/2022, 5:48 PMStefano Bonicatti
10/13/2022, 5:52 PM\\.\pipe\osquery.em
wennan.he
10/13/2022, 6:18 PMKeith Swagler
10/14/2022, 2:12 PM