Hey all, happy friday! Looking at some macOS FIM events where "uid" is blank, anyone know why this would be the case or what it could implicitly mean?
11/04/2022, 3:05 PM
I am assuming this is the
table (and not the
)…I will have to dive deeper in the code, but IIRC it’s only
that populates those (I will have to double check in a bit)
and it might require a join with the
columns might require a join with the
but could be just a bug
nvm, the join should be done by the code itself
11/04/2022, 3:08 PM
Correct, these come from file_events
11/04/2022, 4:26 PM
Is this on Ventura?
I am wondering is this this related to permissions (Full Disk Access and such), or this is on any file?
11/04/2022, 4:52 PM
This is on monterey, and primarily across a select number of files including primarily /private/etc/cups/certs/0 and some child objects in /private/var/root/Library/Caches/rtcreportingd/events/NRM_Events_*
all actions on /private/etc/cups/certs/0 is "DELETED"
I will probably end up excluding that file from the query
11/04/2022, 6:10 PM
Thanks for the additional context, this maybe a bug/caveat, I will try to dig in deeper