manikant singh
10/16/2020, 10:28 AMwe have 16 immutable memtables (waiting to flush), max_write_buffer_number is set to 16
Expiring events for subscriber: file_events (overflowed limit 50000)
Subscriber events file_events exceeded limit 5000 by: 200
Can someone please guide what is the problem here.
As of now I have only two users on the machine.
One is the root with which osqueryd is running and the other is guest user.
which has only access to machine is via ssh.
Not sure why would limit will exceed here.
I have also configured FIM as follows
file_accesses:
- homes
file_paths:
homes:
- /home/%%
Any help is appreciated ,thanks.seph
alessandrogario
manikant singh
10/16/2020, 12:11 PMalessandrogario
manikant singh
10/16/2020, 12:14 PMalessandrogario
ls -halt /path/to/database
/var/osquery/osquery.db
manikant singh
10/16/2020, 12:18 PMseph