Hello everyone. I downloaded test malware files from 'theZoo' repository, and made YARA signatures for them. Now, when I am trying to implement YARA scanning through osquery and Kolide Fleet, it is giving me the following error (picture attached).
This error is occuring only when I am trying to search in relatively large directories, else it is working.
PS: I have tried increasing watchdog_memory_limit.
01/11/2021, 2:28 PM
Interesting, I can take a look at the potential error when reporting the scheduler run time delta. Though this also may be fixed in a newer osquery version.To help debug the issue causing the scheduler to end, can you re-run with
01/12/2021, 7:40 AM
How can I update osquery 4.5.1 to 4.6.0?
I cannot find any guide to install osquery 4.6.0 as a service.