Hi, could anyone please help me? I see the following error from osquery on some Linux machines and after this error osquery is stopped:
severity=2 location=events.cpp:473 message=Could not put Event Records
I haven’t tried to enable debug logs so far, as I have no direct access to those servers. I receive those errors by syslog.
There is a guess. Probably these errors show up because of auditd. We forgot to disable it. We will disable auditd and observe.