<https://github.com/facebook/osquery/issues/5381>
# general
I find that maybe the
watch_dog
settings aren't applied.
c
posted a response
u
osquery add his audit rule to the audit according to
audit_allow_config
. if the
audit_allow_config
is
false
,It means that the osquery will use the rules that exists before in the system but not add the rule it's own.
@clong