jake
09/08/2021, 10:34 PMoverrides:
platforms:
windows:
options:
logger_plugin: tls
pack_delimiter: /
logger_tls_period: 10
distributed_plugin: tls
disable_distributed: false
logger_tls_endpoint: /api/v1/osquery/log
distributed_interval: 10
distributed_tls_max_attempts: 3
enable_ntfs_event_publisher: true
enable_windows_events_subscriber: true
enable_powershell_events_subscriber: true
events_optimize: true
events_max: 100000
events_expiry: 900
disable_events: false
disable_logging: false
schedule_splay_percent: 10
schedule_max_drive: 15
windows_event_channels: >-
System,Application,Setup,Security,Microsoft-Windows-Windows Firewall
With Advanced Security/Firewall,Microsoft-Windows-Windows Firewall
With Advanced Security/ConnectionSecurity
utc: true
pack_refresh_interval: 1800
disable_watchdog: false
watchdog_level: 0
watchdog_memory_limit: 512
watchdog_delay: 120
enable_extensions_watchdog: true
decorators:
load:
- SELECT version FROM osquery_info
- SELECT uuid AS host_uuid FROM system_info
always:
- >-
SELECT user AS username FROM logged_in_users WHERE user <> '' ORDER
BY time LIMIT 1
interval:
'3600': SELECT total_seconds AS uptime FROM uptime
Martavis Parker
09/09/2021, 3:10 PMjake
09/10/2021, 1:04 AMMartavis Parker
09/10/2021, 7:27 PM