Title
#process-auditing
p

Prash

08/27/2019, 7:24 AM
When I add "- -a never,exit -F exe=/usr/bin/osqueryd -S all" in goaudit.yaml and start process
Loqpa

Loqpa

08/27/2019, 2:38 PM
Does your osquery have events enabled?
p

Prash

08/28/2019, 8:06 AM
Yes I have set "disable_events": "false" flag in osquery
Loqpa

Loqpa

09/09/2019, 7:06 AM
In docs there is a line saying "Auditd should not be running when using osquery's process auditing, as it will conflict with osqueryd over access to the audit netlink socket." I feel like goaudit is actually doing the same here, that may be the reason it failes.