fr1day
11/30/2018, 8:02 AMjulient
11/30/2018, 2:59 PMfr1day
12/03/2018, 3:01 AMverbose:false
and logger_plugin:kafka
instead of verbose:true
and logger_plugin:kafka,filesystem
in online environment, so it will not generate much logs in disk. And my schedule time for events tables is 1 minutes. I think it's low enough. Osquery didn't count older logs, and so can't remove it sometimes.