Hi folks, I am using Wazuh to ship osquery results...
# general
m
Hi folks, I am using Wazuh to ship osquery results to my Wazuh cloud console but the Wazuh agent seems to get flooded with too many logs. When I investigate it looks as if the interval for the osquery packs run at the same time and might be the reason the Wazuh agent gets flooded with too many events per second. Can someone explain to me what "schedule_splay_percent": 10 would do to potentially fix this problem? The docs seem to suggest that it would not allow all the pack queries to run at the same time. Source - https://osquery.readthedocs.io/en/stable/installation/cli-flags/ and https://osquery.readthedocs.io/en/3.4.0/deployment/configuration/