Channels
doorman
zercurity
infrastructure
code-review
queryhub
apple-silicon
carving
goquery
aws
querycon
golang
file-carving
fuzzing
help-proxy
darkbytes
process-auditing
general
windows
random
fleet-dev
tls
fim
awallaby
zentral
zeek
auditing-warroom
linen-dev
fleetosquery
plugins
jobs
arm-architecture
uptycs
android_tests
selfgroup
vendor-feeds
fleet
eclecticiq-polylogyx-extension
ebpf
website
core
macos
kolide
osctrl
extensions
foundation
sql
officehours
linux
community-feeds
Powered by
#general
Title
# general
u
3k
10/23/2018, 1:48 AM
@clong
if you don’t mind sharing the conf file for your FIM. I created the conf but for reason, my log file hasn’t been created. I’m wondering if I should have enabled the event disabled flag as false in the conf
c
clong
10/23/2018, 7:53 AM
https://github.com/palantir/osquery-configuration/blob/master/Servers/Linux/osquery.conf
https://github.com/palantir/osquery-configuration/blob/master/Servers/Linux/osquery.flags
u
3k
10/24/2018, 3:27 AM
thanks 🙂
Post