I'm trying to capture fim events. I would prefer audit events over inotify but when I query process_file_events table, it doesn't return anything. But if I query file_events table, I get all the fim events. I;m using following flags:
I've written a script which generates FIM events in directory '/app/osquery/fim'
Am I missing something ? Any misconfiguration ?
using osquery version: 3.2.6
07/20/2018, 9:52 PM
Did you get it to work? I just tested on macOS at least and it was working for me.
07/25/2018, 10:01 AM
hey, I was trying on amazon_linux VM (AWS) and wasn't able to make it work few days back. After that I didn't get time to try it on some other OS or my mac. Will give it a try and let you know. Thanks.