João Godinho
12/23/2019, 12:00 AMlast
table only shows logins (type 7). After pulling hairs and compiling osquery myself, I found this PR: https://github.com/osquery/osquery/pull/5274 (btw I couldn’t find any reference to this on the releases) which is filtering for USER_PROCESS
only. Should I open an issue for this? or can I just open a PR and also add the DEAD_PROCESS
event?seph
12/23/2019, 11:47 AMJoão Godinho
12/23/2019, 11:50 AMseph
12/23/2019, 11:52 AMJoão Godinho
12/23/2019, 11:56 AM