Eric
06/01/2020, 6:20 PMMike Myers
06/01/2020, 8:00 PMEric
06/01/2020, 8:16 PMMike Myers
06/01/2020, 8:24 PMevent_expiry
and events_max
configuration options and see that they're set to appropriate values, and then also check the osquery_events
table to see which tables are receiving events. If there are tables receiving events that are not getting periodically queried, then osquery will buffer up those events according to the configuration.Eric
06/02/2020, 3:24 PM