Isaac
05/14/2018, 9:28 PMWe can't seem to find a happy place where we can exclude specific directories/files and get a guaranteed output of events to be logged based on the 120 second interval setup in the FIM conf.
We have a lot of very active and/or large files (10+GB) coming in and out and OSquery seems to be lagging when trying to analyze the files at service start. The behavior we are seeing is that the FIM query never gets executed or will not be reliable as to when it may report back.
Please let me know if there is a better way to report this type of stuff Ill be happy to go deep in details if neededclong
05/14/2018, 10:36 PMIsaac
05/14/2018, 10:51 PMclong
05/14/2018, 10:53 PMIsaac
05/14/2018, 11:06 PM