demonbhao
01/04/2021, 10:13 AMNoah Talerman
01/04/2021, 10:02 PMdemonbhao
01/05/2021, 6:27 AMNoah Talerman
01/06/2021, 5:19 PMdemonbhao
01/07/2021, 2:32 AMNoah Talerman
01/07/2021, 5:18 PMGeneral indicators
and ossec_rootkit
) also generating logs in kibana?
I wonder if the machines generating the listening_external_port_V1
logs have had their osquery configuration changed since you deleted this query pack. Meaning they know that the only query packs they should be running are the two in your second screenshot.
I’m going to attempt to recreate your issue later today.demonbhao
01/08/2021, 2:19 AMNoah Talerman
01/08/2021, 4:24 PMdemonbhao
01/11/2021, 6:31 AM