Title
#general
Stefano Bonicatti

Stefano Bonicatti

03/02/2021, 3:39 PM
https://github.com/osquery/osquery/blob/master/osquery/tables/events/windows/windows_events.cpp for instance this is one of the tables/subscribers for the events that
windowseventlogpublisher
creates. There are multiple tables that will receive those events, and which receives what event is chosen by the
shouldFire
function in the publisher, which as you can see uses the event channel name that a subscriber listens to. Each subscriber selects the channels in their
init
function and put them in
channel_list
which is later used in
shouldFire
j

JoSeiler

03/02/2021, 3:45 PM
Thanks a lot!