hello, i want to ask, why i run query select * fr...
# fleet
d
hello, i want to ask, why i run query select * from process_events; , i recive Your live query returned no results. on os: ubuntu and centos,
k
by default events are disabled add
--disable_events=false
to your osquery flags to enable event tables
Oh and you do need to have a few other flags as well. See: https://osquery.readthedocs.io/en/stable/deployment/process-auditing/