theopolis
theopolis
theopolis
Prateek Kumar Nischal
10/06/2020, 5:38 PMPrateek Kumar Nischal
10/06/2020, 5:39 PMZach Zeid
10/06/2020, 6:10 PMwatchdog?theopolis
Prateek Kumar Nischal
10/07/2020, 10:55 AMCPUQuota and MemoryLimit to the service and disable the watchdog. Which could cause the service to potentially exit.
if the watchdog is running at any other limit, restrictive or normal, osquery would get respawned due to cgroup view of the cpu usage.Zach Zeid
10/07/2020, 12:40 PMwatchdog interacts with the osquery daemon service?theopolis
Zach Zeid
10/07/2020, 12:58 PMPrateek Kumar Nischal
10/07/2020, 1:11 PM--verbose you can see watchdog killing osquery.
Oct 06 05:09:23 <hostname> osqueryd[17003]: osqueryd worker (17769) stopping: Maximum sustainable CPU utilization limit exceeded: 12Zach Zeid
10/07/2020, 1:12 PM--verbose in the flags file or something?Prateek Kumar Nischal
10/07/2020, 1:13 PMauditctl -s advance over a 10 minute period..Prateek Kumar Nischal
10/07/2020, 1:14 PM"logger_min_status": 1theopolis
Prateek Kumar Nischal
10/07/2020, 1:24 PMZach Zeid
10/07/2020, 4:02 PMosquery_schedule are the _time columns in nanoseconds?Zach Zeid
10/07/2020, 4:02 PMaverage_memory is in bytes?Zach Zeid
10/07/2020, 5:28 PMtime and everything is in seconds?Prateek Kumar Nischal
10/07/2020, 7:56 PMZach Zeid
10/07/2020, 8:06 PMZach Zeid
10/08/2020, 1:01 PMZach Zeid
10/08/2020, 1:01 PM