Shane Sanborn
03/01/2022, 7:31 PMhimanshu
03/07/2022, 4:32 AM40% combined
usage. at the same time, please share osquery.flags and osquery.conf being used.OpenPlgx
03/07/2022, 9:35 AMShane Sanborn
03/07/2022, 2:50 PMhimanshu
03/07/2022, 4:23 PMplgx_win.conf
and spread interval of scheduled queries to a higher time value.. most of the queries are scheduled for "interval": 30
which may be eating up CPU.OpenPlgx
03/07/2022, 4:42 PMShane Sanborn
03/08/2022, 3:03 PM*.exe
filter is even working because I am seeing data come in that has a target_path that doesn't include that.. do I have to provide like an exclude all filter for this to work or?himanshu
03/13/2022, 5:27 PMwin_file_timestomp_events
. win_file_events
filter should work for file timestomp events.Shane Sanborn
03/28/2022, 2:34 PMhimanshu
03/31/2022, 12:47 PMShane Sanborn
03/31/2022, 7:55 PMhimanshu
04/02/2022, 11:45 AMShane Sanborn
04/05/2022, 2:42 PMhimanshu
04/05/2022, 5:45 PMShane Sanborn
04/12/2022, 6:01 PMOpenPlgx
04/13/2022, 4:15 AMShane Sanborn
04/13/2022, 1:53 PMOpenPlgx
04/13/2022, 4:31 PMShane Sanborn
04/13/2022, 4:49 PMwin_image_load_events
in there, thats when the spike is occuringOpenPlgx
04/15/2022, 3:15 AM