Thomas Stromberg
11/04/2022, 12:41 PMprocess_events.env_size
from being populated? I have a query to find short-lived setuid overflow attempts but the field is always NULL. I suspect it's a bug relating to env whitelisting, but wanted to save the osquery maintainers some hassle if it was a known Kolide-specific issue.seph
11/04/2022, 2:13 PMThomas Stromberg
11/04/2022, 2:15 PMseph
11/04/2022, 2:15 PMes_process_events
is where the API is going, but Kolide doesn’t support the ES tables yet.Thomas Stromberg
11/04/2022, 2:16 PMbpf_process_events
?seph
11/04/2022, 2:18 PMThomas Stromberg
11/04/2022, 2:18 PM