Has anyone ever needed to/explored changing the niceness of osquery? I found this issue (https://github.com/osquery/osquery/issues/516) from a few years back talking about the idea of using it, would there be any merits/negatives to attempting this?
It’s just a small number of OSX workstations are having some problems with the subprocess eating up large amounts of system resources when we have process auditing enabled, I’m not sure where else to go in trying to address this
s
seph
2 years ago
Do you need to ingest that many events? What are you doing with them?