demonbhao
Noah Talerman
demonbhao
Noah Talerman
demonbhao
Noah Talerman
General indicators
and ossec_rootkit
) also generating logs in kibana?
I wonder if the machines generating the listening_external_port_V1
logs have had their osquery configuration changed since you deleted this query pack. Meaning they know that the only query packs they should be running are the two in your second screenshot.
I’m going to attempt to recreate your issue later today.demonbhao
Noah Talerman