https://github.com/osquery/osquery logo
Title
x

xiaoliuzi

05/03/2020, 3:54 PM
How to use ntfs_journal_events to monitor file operations?
m

Mike Myers

05/04/2020, 9:07 PM
x

xiaoliuzi

05/05/2020, 1:37 AM
I use this query without any results SELECT * FROM ntfs_journal_events WHERE path LIKE "C: \\ Program Files \\ osquery \\%";
y

yossarian

05/06/2020, 2:53 PM
@xiaoliuzi make sure that your
osquery.conf
contains the file patterns that you want to query
x

xiaoliuzi

05/09/2020, 1:55 PM