03/06/2019, 7:38 AM
Hi There, does anyone know how to solve the following issue? : Expiring events for subscriber: windows_events (overflowed limit 50000)


03/06/2019, 6:47 PM
Are you selecting from the windows_events tables? It's normal for events to expire so that the osquery db doesn't fill the disk.


03/06/2019, 9:50 PM
Yeah what @zwass said. That table fills up pretty quickly, so you'll wanna have a relatively frequent interval. We typically use like 3 minutes? So 180.
9:51 PM
Also check what WEL channels you've subscribed to. It's common to just want all of the data, but currently osquery doesn't have great support for forwarding out huge amounts of data, but this is on the way. For now it's better to try and be more selective about what event logs you'd like to get out of the system, and only subscribe to those channels