Configured osquery for all the events. Still I am getting below error. "Table syslog_events is event-based but events are disabled". However osquery log is getting syslog.
z
zwass
05/30/2019, 2:33 PM
Are you getting that error in osqueryi? By default events are disabled there.
s
Sudeep
06/07/2019, 7:20 AM
Please add the below line to the config and restart osquery
"disable_events": "false",