Fixing the Splunk nullqueue

This commit is contained in:
Chris Long
2020-03-28 02:30:06 -07:00
parent c7e013558a
commit fd804a083d

View File

@@ -15,8 +15,10 @@ TRUNCATE = 0
[osquery:json]
TRANSFORMS-osquery_host = osquery_hostidentifier_as_host
TRANSFORMS-null = setnull
TIME_PREFIX = \"unixTime\"\:
MAX_TIMESTAMP_LOOKAHEAD = 500
TIME_FORMAT = %s
TRUNCATE = 0
TRUNCATE = 0
[osquery:status]
TRANSFORMS-null = setnull