saw that before github issue before but i understood it would not apply to 4.6.0
t
theopolis
04/22/2021, 6:07 PM
Are you comfortable sharing your db with me to debug?
j
Juan Alvarez
04/22/2021, 6:11 PM
i cant share it unfortunately 😞 Is there any steps i could take to debug?
we have seen that at some point we created many powershell_events that were included there (pretty big ones). I have disabled powershell_events now, but would that not cleanup de db?
that table was never queried, tho it was enabled in the flags
t
theopolis
04/23/2021, 1:06 PM
That could be it, osquery will store the last 50k by default then start removing batches
j
Juan Alvarez
04/23/2021, 1:12 PM
older SST files do never get deleted? or should it remove them?