How to use ntfs_journal_events to monitor file ope...
# windows
x
How to use ntfs_journal_events to monitor file operations?
m
x
I use this query without any results SELECT * FROM ntfs_journal_events WHERE path LIKE "C: \\ Program Files \\ osquery \\%";
y
@xiaoliuzi make sure that your
osquery.conf
contains the file patterns that you want to query
x