02/11/2021, 10:59 PM
Hi, could anyone please help me? I see the following error from osquery on some Linux machines and after this error osquery is stopped: severity=2 location=events.cpp:473 message=Could not put Event Records I haven’t tried to enable debug logs so far, as I have no direct access to those servers. I receive those errors by syslog.
3:12 AM
There is a guess. Probably these errors show up because of auditd. We forgot to disable it. We will disable auditd and observe.