osquery> select * from ntfs_journal_events WHERE action = "FileWrite";
W0430 14
0710.305126 17384 virtual_table.cpp:967] Table ntfs_journal_events is event-based but events are disabled
W0430 14
0710.305126 17384 virtual_table.cpp:974] Please see the table documentation:
https://osquery.io/schema/#ntfs_journal_events