Creating many SST files was a problem with an earl...
# core
m
Creating many SST files was a problem with an earlier version of osquery, are you running a recent version?
j
we are running 4.6.0
saw that before github issue before but i understood it would not apply to 4.6.0
t
Are you comfortable sharing your db with me to debug?
j
i cant share it unfortunately 😞 Is there any steps i could take to debug?
we have seen that at some point we created many powershell_events that were included there (pretty big ones). I have disabled powershell_events now, but would that not cleanup de db?
that table was never queried, tho it was enabled in the flags
t
That could be it, osquery will store the last 50k by default then start removing batches
j
older SST files do never get deleted? or should it remove them?
finally, i reproduced the symptoms locally and uploaded a database dump, i have created this: https://github.com/osquery/osquery/issues/7079
🆒 1