apply optimizations when SELECTing from events-based tables, enabled by default. - Events you select with your slimed down query will be. deleted.
the lifetime of buffered events in seconds with a default value of 86000. - This option should expire ALL events after the threshold is met
the maximum number of events to store in the buffer before expiring them with a default value of 1000 - So only 1000 events will be stored in RocksDB.
osquery events optimization
this combination would keep the RocksDB from eternally growing. A quick test case would be to enable process monitoring with
and then do:
SELECT * FROM process_events