fr1day
11/30/2018, 8:02 AMjulient
11/30/2018, 2:59 PMfr1day
12/03/2018, 3:01 AMverbose:false and logger_plugin:kafka instead of verbose:true and logger_plugin:kafka,filesystem in online environment, so it will not generate much logs in disk. And my schedule time for events tables is 1 minutes. I think it's low enough. Osquery didn't count older logs, and so can't remove it sometimes.