what version are you using?
The current version does not use the accessor parameter to the watch_usn() plugin since it is not possible to watch a usn file with any other accessor anyway. That artifact does not have the accessor parameter in the current version.
You can test the watch_usn plugin like this
velociraptor-v0.73.3-windows-amd64.exe query "SELECT * FROM watch_usn(device='c:')" -v
should see a log like this
[INFO] 2025-01-24T17:35:09-08:00 Registering USN log watcher for \\.\C: with handle 1 and frequency 30 seconds
you should start receiving events after 30 seconds
Thanks
Mike
| Mike Cohen Digital Paleontologist, Velocidex Enterprises |
| | | | |
|
|