Ari Weinberg
04/20/2022, 6:25 PMI0420 11:22:13.001909 6160 eventsubscriberplugin.cpp:492] Found 15 events for subscriber WindowsEventLogPublisher.powershell_events
I0420 11:22:13.533206 6160 events.cpp:70] Skipping subscriber: powershell_events: Required publisher is disabled by configuration
After which it gets stopped by the watchdog, and the whole thing repeats a few seconds later.
Any insights?fritz
04/20/2022, 7:04 PMusers
) which can have thousands of rows when the device in question is a domain controllerAri Weinberg
04/20/2022, 7:05 PMfritz
04/20/2022, 7:06 PMAri Weinberg
04/20/2022, 7:07 PM# Configuration
--config_plugin=tls
--config_tls_endpoint=/api/v1/osquery/config
--config_refresh=60
# Enable watchdog to stop queries that use too much resources
--disable_watchdog=false
--watchdog_level=1
# Live query
--disable_distributed=false
--distributed_plugin=tls
--distributed_interval=10
--distributed_tls_max_attempts=3
--distributed_tls_read_endpoint=/api/v1/osquery/distributed/read
--distributed_tls_write_endpoint=/api/v1/osquery/distributed/write
# Logging
--logger_plugin=tls,filesystem
--logger_tls_endpoint=/api/v1/osquery/log
--logger_tls_period=10
# File carving
--disable_carver=false
--carver_start_endpoint=/api/v1/osquery/carve/begin
--carver_continue_endpoint=/api/v1/osquery/carve/block
--carver_block_size=2000000
# Windows Configuration
#--enable_powershell_events_subscriber
#--enable_windows_events_publisher
#--enable_windows_events_subscriber
#--windows_event_channels=System,Application,Setup,Security
# Disable problamatic table
--disable_tables=chrome_extensions,google_chrome_profiles,mdm,munki_info
fritz
04/20/2022, 7:08 PMAri Weinberg
04/20/2022, 7:08 PMconfig:
options:
disable_tables: 'munki_info,google_chrome_profiles,mdm'
pack_delimiter: _
logger_tls_period: 10
distributed_plugin: tls
disable_distributed: false
logger_tls_endpoint: /api/v1/osquery/log
distributed_interval: 10
distributed_tls_max_attempts: 3
fritz
04/20/2022, 7:09 PMAri Weinberg
04/20/2022, 7:09 PMfritz
04/20/2022, 7:10 PMAri Weinberg
04/20/2022, 7:12 PMI0420 12:09:09.901724 6804 eventsubscriberplugin.cpp:492] Found 15 events for subscriber WindowsEventLogPublisher.powershell_events
I0420 12:09:10.429062 6804 events.cpp:70] Skipping subscriber: powershell_events: Required publisher is disabled by configuration
I0420 12:10:04.662425 6288 config.cpp:1218] Refreshing configuration state
I0420 12:10:04.662425 6288 tls.cpp:255] TLS/HTTPS POST request to URI: <https://FLEET_URL/api/v1/osquery/config>
W0420 12:10:05.193722 6532 watcher.cpp:391] osqueryd worker (6908) stopping: Maximum sustainable CPU utilization limit exceeded: 57
I0420 12:10:05.224970 6532 watcher.cpp:656] osqueryd watcher (4528) executing worker (6712)
I0420 12:10:05.307375 6104 init.cpp:354] osquery worker initialized [watcher=4528]
I0420 12:10:05.307375 6104 dispatcher.cpp:78] Adding new service: WatcherWatcherRunner (00000216390B03F0) to thread: 6152 (000002163908E400) in process 6712
I0420 12:10:05.307375 6104 rocksdb.cpp:132] Opening RocksDB handle: \Program Files\osquery\osquery.db
I0420 12:10:05.635535 6104 dispatcher.cpp:78] Adding new service: ExtensionWatcher (000002163A95DEF0) to thread: 4888 (000002163AE92B40) in process 6712
I0420 12:10:05.635535 6104 dispatcher.cpp:78] Adding new service: ExtensionRunnerCore (000002163A94B260) to thread: 5196 (000002163AE92AE0) in process 6712
I0420 12:10:05.635535 6104 auto_constructed_tables.cpp:99] Removing stale ATC entries
I0420 12:10:05.635535 5196 interface.cpp:299] Extension manager service starting: \\.\pipe\osquery.em
I0420 12:10:05.635535 6104 dispatcher.cpp:78] Adding new service: ConfigRefreshRunner (000002163904C7F0) to thread: 6188 (000002163AF02500) in process 6712
I0420 12:10:05.635535 6104 tls.cpp:255] TLS/HTTPS POST request to URI: <https://FLEET_URL/api/v1/osquery/config>
I0420 12:10:10.446698 6104 eventfactory.cpp:156] Event publisher not enabled: ntfs_event_publisher: NTFS event publisher disabled via configuration
I0420 12:10:11.479414 6104 eventsubscriberplugin.cpp:492] Found 15 events for subscriber WindowsEventLogPublisher.powershell_events
I0420 12:10:11.932579 6104 events.cpp:70] Skipping subscriber: powershell_events: Required publisher is disabled by configuration
fritz
04/20/2022, 7:17 PMAri Weinberg
04/20/2022, 7:20 PMfritz
04/20/2022, 7:21 PMStefano Bonicatti
04/20/2022, 7:21 PMosquery_events
table, and or also at the size of the RocksDB databaseAri Weinberg
04/20/2022, 7:23 PMStefano Bonicatti
04/20/2022, 7:24 PMAri Weinberg
04/20/2022, 7:25 PMevents
tables?Stefano Bonicatti
04/20/2022, 7:25 PMAri Weinberg
04/20/2022, 7:25 PMStefano Bonicatti
04/20/2022, 7:26 PMAri Weinberg
04/20/2022, 7:27 PMStefano Bonicatti
04/20/2022, 7:28 PMAri Weinberg
04/20/2022, 7:29 PMStefano Bonicatti
04/20/2022, 7:29 PM--database_dump
Ari Weinberg
04/20/2022, 7:33 PM--database_dump
supposed to show me? I just got an infinite scrollStefano Bonicatti
04/20/2022, 7:43 PMAri Weinberg
04/20/2022, 7:44 PMStefano Bonicatti
04/20/2022, 7:46 PMAri Weinberg
04/20/2022, 7:47 PMStefano Bonicatti
04/20/2022, 7:47 PMAri Weinberg
04/20/2022, 7:47 PMStefano Bonicatti
04/20/2022, 7:49 PMAri Weinberg
04/20/2022, 7:50 PMStefano Bonicatti
04/20/2022, 7:50 PMhardware_events
which is on Linux, and then the osquery_events
table which tracks the status of publisher and subscribers but that's itAri Weinberg
04/20/2022, 7:50 PM