jaredl
02/05/2018, 8:24 PMfile_paths
configured for watching and none of these appear to be directly related to the activities of nagios
osquery.flags
file:--audit_allow_config=true
--audit_allow_sockets=true
--audit_persist=true
--disable_audit=false
--events_expiry=1
--events_max=100000
--logger_min_status=1
--logger_plugin=syslog
--watchdog_memory_limit=350
--watchdog_utilization_limit=100
--audit_allow_sockets=false
and restarting osquery-a always,exit -S connect
kernel audit rule that osqueryd
sets up.