Channels
android_tests
apple-silicon
arm-architecture
auditing-warroom
aws
carving
code-review
community-feeds
core
darkbytes
doorman
ebpf
eclecticiq-polylogyx-extension
extensions
file-carving
fim
fleet
fleet-dev
fleetosquery
foundation
fuzzing
general
golang
goquery
infrastructure
jobs
kolide
linen-dev
linux
macos
officehours
osctrl
plugins
process-auditing
querycon
queryhub
random
selfgroup
sql
tls
uptycs
vendor-feeds
website
windows
zeek
zentral
zercurity
Powered by
Title
u
3k
10/23/2018, 1:48 AM
@clong
if you don’t mind sharing the conf file for your FIM. I created the conf but for reason, my log file hasn’t been created. I’m wondering if I should have enabled the event disabled flag as false in the conf
c
clong
10/23/2018, 7:53 AM
https://github.com/palantir/osquery-configuration/blob/master/Servers/Linux/osquery.conf
https://github.com/palantir/osquery-configuration/blob/master/Servers/Linux/osquery.flags
u
3k
10/24/2018, 3:27 AM
thanks 🙂
#general
Join Slack