Join Slack
Channels
general
android_tests
apple-silicon
arm-architecture
auditing-warroom
awallaby
aws
beyond-identity
carving
code-review
community-feeds
core
darkbytes
doorman
ebpf
eclecticiq-polylogyx-extension
extensions
file-carving
fim
fleet
fleet-dev
fleetosquery
foundation
fuzzing
golang
goquery
help-proxy
infrastructure
jobs
kolide
linen-dev
linux
loonsecio
macos
officehours
osctrl
plugins
process-auditing
qingteng
querycon
queryhub
random
selfgroup
sql
tls
uptycs
vendor-feeds
website
windows
zeek
zentral
zercurity
Powered by
Hi. What are the differences between the file_even...
# general
j
Jams
03/11/2021, 5:15 PM
Hi. What are the differences between the
file_events
and
process_file_events
table? For example, one table leverages inotify publisher while the latter table requires the Linux audit framework.
m
Mike Myers
03/11/2021, 5:38 PM
I see that the documentation on FIM is pretty out of date, it doesn't even mention process_file_events
https://osquery.readthedocs.io/en/latest/deployment/file-integrity-monitoring/#file-integrity-monitoring-with-osquery
3
Views
Open in Slack
Previous
Next