Hi,
I am running osqueryd in my windows and two output files are produced.
results.log and snapshot.log
However, it seems like i can only track one file through wazuh osquery with following attribute.
<log_path>/var/log/osquery/osqueryd.results.log</log_path>
Is there a way to keep track of both snapshot and results.log. I tried giving both values in separate log_path but only the second one was tracked.
--
Thanks and Regards,
Ranjit