mirror of
https://github.com/empayre/fleet.git
synced 2024-11-06 08:55:24 +00:00
14 lines
430 B
YAML
14 lines
430 B
YAML
|
name: disk_events
|
||
|
examples: >-
|
||
|
This is an evented table, and as such, is more useful if you are sending
|
||
|
osquery logs to a SIEM or other centralized destination via Fleet. Events must
|
||
|
be enabled. This query will contain the list of all actions related to
|
||
|
connecting and removing disks, including SMB drives and USB storage, which can
|
||
|
be very useful for investigative purposes.
|
||
|
|
||
|
```
|
||
|
|
||
|
SELECT * FROM disk_events;
|
||
|
|
||
|
```
|