Title
#windows
x

xiaoliuzi

05/03/2020, 3:54 PM
How to use ntfs_journal_events to monitor file operations´╝č
Mike Myers

Mike Myers

05/04/2020, 9:07 PM
x

xiaoliuzi

05/05/2020, 1:37 AM
I use this query without any results SELECT * FROM ntfs_journal_events WHERE path LIKE "C: \ Program Files \ osquery \%";
1:40 AM
yossarian

yossarian

05/06/2020, 2:53 PM
@xiaoliuzi make sure that your
osquery.conf
contains the file patterns that you want to query
x

xiaoliuzi

05/09/2020, 1:55 PM