Faraz Jafri
12/28/2020, 9:48 AMCptOfEvilMinions
12/28/2020, 3:30 PMosqueryd
uses a watchdog process to monitor the memory and CPU utilization of threads executing the query schedule. If any performance limit is violated, the “worker” process will be restarted.
The default threshold per the documentation is 200MB. I would increase this threshold with the following Osquery flag: --watchdog_memory_limit=X
https://osquery.readthedocs.io/en/stable/installation/cli-flags/Faraz Jafri
12/29/2020, 7:52 AMCptOfEvilMinions
12/29/2020, 3:29 PM