theopolis
Prateek Kumar Nischal
10/06/2020, 5:38 PMZach Zeid
10/06/2020, 6:10 PMwatchdog
?theopolis
Prateek Kumar Nischal
10/07/2020, 10:55 AMCPUQuota
and MemoryLimit
to the service and disable the watchdog. Which could cause the service to potentially exit.
if the watchdog is running at any other limit, restrictive or normal, osquery would get respawned due to cgroup view of the cpu usage.Zach Zeid
10/07/2020, 12:40 PMwatchdog
interacts with the osquery daemon service?theopolis
Zach Zeid
10/07/2020, 12:58 PMPrateek Kumar Nischal
10/07/2020, 1:11 PM--verbose
you can see watchdog killing osquery.
Oct 06 05:09:23 <hostname> osqueryd[17003]: osqueryd worker (17769) stopping: Maximum sustainable CPU utilization limit exceeded: 12
Zach Zeid
10/07/2020, 1:12 PM--verbose
in the flags file or something?Prateek Kumar Nischal
10/07/2020, 1:13 PMauditctl -s
advance over a 10 minute period.."logger_min_status": 1
theopolis
Prateek Kumar Nischal
10/07/2020, 1:24 PMZach Zeid
10/07/2020, 4:02 PMosquery_schedule
are the _time
columns in nanoseconds?average_memory
is in bytes?time
and everything is in seconds?Prateek Kumar Nischal
10/07/2020, 7:56 PMZach Zeid
10/07/2020, 8:06 PM