osquery> select * from ntfs_journal_events WHERE action = "FileWrite";
W0430 14:07:10.305126 17384 virtual_table.cpp:967] Table ntfs_journal_events is event-based but events are disabled
W0430 14:07:10.305126 17384 virtual_table.cpp:974] Please see the table documentation: https://osquery.io/schema/#ntfs_journal_events