jaredl
02/05/2018, 8:24 PMfile_paths configured for watching and none of these appear to be directly related to the activities of nagiosjaredl
02/05/2018, 10:09 PMjaredl
02/05/2018, 10:09 PMosquery.flags file:jaredl
02/05/2018, 10:09 PM--audit_allow_config=true
--audit_allow_sockets=true
--audit_persist=true
--disable_audit=false
--events_expiry=1
--events_max=100000
--logger_min_status=1
--logger_plugin=syslog
--watchdog_memory_limit=350
--watchdog_utilization_limit=100jaredl
02/05/2018, 10:10 PM--audit_allow_sockets=false and restarting osqueryjaredl
02/05/2018, 10:10 PM-a always,exit -S connect kernel audit rule that osqueryd sets up.jaredl
02/05/2018, 10:14 PM