clong
11/08/2018, 10:39 PMshed7
11/09/2018, 9:21 AMaudit_debug
as a flag, osquery was logging the auditd type records, but there were no osquery json logs of the same events, and as I said auditctl -s
said it was osquery who had the handle on the socket