Macear07/10/2020, 11:07 AM
CptOfEvilMinions07/10/2020, 5:28 PM
apply optimizations when `SELECT`ing from events-based tables, enabled by default. - Events you select with your slimed down query will be. deleted.
the lifetime of buffered events in seconds with a default value of 86000. - This option should expire ALL events after the threshold is met
the maximum number of events to store in the buffer before expiring them with a default value of 1000 - So only 1000 events will be stored in RocksDB.
osquery events optimization
Macear07/10/2020, 6:37 PM
CptOfEvilMinions07/10/2020, 7:18 PM
this combination would keep the RocksDB from eternally growing. A quick test case would be to enable process monitoring with
and then do:
SELECT * FROM process_events
Macear07/11/2020, 7:40 AM