3

Improve explanations of event control flags by mike-myers-tob · Pull Request #69...

 2 years ago
source link: https://github.com/osquery/osquery/pull/6954
Go to the source link to view the article. You can view the picture content, updated content and better typesetting reading experience. If the link is broken, please click the button below to view the snapshot at that time.
neoserver,ios ssh client

Conversation

Users trying to simply turn on evented tables on Windows are often confused that --disable_events=false is not enough. Afterwards, they are confused when they query an evented table twice and some or all of the data from the first query is still there. They are confused again when they get warnings about evented tables' events overfilling and losing events. So the docs could be better. This is my attempt.

Addresses @muffins comment on recent changes to the flags that control evented tables.

Closes #6763


About Joyk


Aggregate valuable and interesting links.
Joyk means Joy of geeK