jaredl
02/05/2018, 8:24 PMfile_paths
configured for watching and none of these appear to be directly related to the activities of nagios
jaredl
02/05/2018, 10:09 PMjaredl
02/05/2018, 10:09 PMosquery.flags
file:jaredl
02/05/2018, 10:09 PM--audit_allow_config=true
--audit_allow_sockets=true
--audit_persist=true
--disable_audit=false
--events_expiry=1
--events_max=100000
--logger_min_status=1
--logger_plugin=syslog
--watchdog_memory_limit=350
--watchdog_utilization_limit=100
jaredl
02/05/2018, 10:10 PM--audit_allow_sockets=false
and restarting osqueryjaredl
02/05/2018, 10:10 PM-a always,exit -S connect
kernel audit rule that osqueryd
sets up.jaredl
02/05/2018, 10:14 PM