Stefano Bonicatti
05/26/2022, 9:57 PMJason Field
05/26/2022, 10:01 PMStefano Bonicatti
05/26/2022, 10:02 PMosqueryd --help
Jason Field
05/26/2022, 10:13 PMStefano Bonicatti
05/26/2022, 10:14 PMJason Field
05/27/2022, 12:06 AMStefano Bonicatti
05/27/2022, 2:18 PM--enable_file_events=true
for the file_events
table.Jason Field
05/27/2022, 3:08 PMsudo osqueryd --verbose --enable_file_events=true --disable_events=false --config_path /etc/osquery/osquerytest.conf
is there a way to stop that process or service? Sorry not as familiar with Linux still.
Second question would be how do I add that to the config or service so that just it happens when the server starts up etc. Just add a "enable_file_events": "true",
to the config as well?"disable_events": "false",
"enable_file_events": "true",
from the config file. Was that something that changed say maybe somewhere around year and a half ago? Where those would not have been needed? Sorry just trying to figure out why this stopped working.Stefano Bonicatti
06/02/2022, 2:11 PM