Fixing the Splunk nullqueue
This commit is contained in:
@@ -15,8 +15,10 @@ TRUNCATE = 0
|
|||||||
|
|
||||||
[osquery:json]
|
[osquery:json]
|
||||||
TRANSFORMS-osquery_host = osquery_hostidentifier_as_host
|
TRANSFORMS-osquery_host = osquery_hostidentifier_as_host
|
||||||
TRANSFORMS-null = setnull
|
|
||||||
TIME_PREFIX = \"unixTime\"\:
|
TIME_PREFIX = \"unixTime\"\:
|
||||||
MAX_TIMESTAMP_LOOKAHEAD = 500
|
MAX_TIMESTAMP_LOOKAHEAD = 500
|
||||||
TIME_FORMAT = %s
|
TIME_FORMAT = %s
|
||||||
TRUNCATE = 0
|
TRUNCATE = 0
|
||||||
|
|
||||||
|
[osquery:status]
|
||||||
|
TRANSFORMS-null = setnull
|
||||||
Reference in New Issue
Block a user