file, then it cannot be subscribed to, so no events will be generated that osquery can catch. Maybe though those can be queried via the
Maybe am i missing something? Or i just hit a limitation?
osquery> SELECT * FROM windows_eventlog where channel="Microsoft-Windows-DNSServer/Analytical"; W0921 17:39:11.236779 5024 windows_eventlog.cpp:294] Failed to search event log for query with 50