Hi, could anyone please help me? I see the followi...
# general
m
Hi, could anyone please help me? I see the following error from osquery on some Linux machines and after this error osquery is stopped: severity=2 location=events.cpp:473 message=Could not put Event Records I haven’t tried to enable debug logs so far, as I have no direct access to those servers. I receive those errors by syslog.
There is a guess. Probably these errors show up because of auditd. We forgot to disable it. We will disable auditd and observe.