defensivedepth09/20/2021, 1:04 PM
Juan Alvarez09/20/2021, 1:39 PM
Stefano Bonicatti09/20/2021, 2:58 PM
file, then it cannot be subscribed to, so no events will be generated that osquery can catch. Maybe though those can be queried via the
Juan Alvarez09/20/2021, 3:22 PM
Maybe am i missing something? Or i just hit a limitation?
osquery> SELECT * FROM windows_eventlog where channel="Microsoft-Windows-DNSServer/Analytical"; W0921 17:39:11.236779 5024 windows_eventlog.cpp:294] Failed to search event log for query with 50