如何解决OSQuery中etw_process_publisher未启用的配置错误?
解决osquery中etw_process_publisher未启用的问题
问题场景
配置的osquery.conf内容如下:
{ // Configure the daemon below: "options": { "event_publisher": "etw_process_publisher", "enable_ntfs_event_publisher": true }, "schedule": { "chrome_extensions": { "query": "SELECT * from users;", "interval": 3600 } } }
执行命令 osqueryd.exe --config_path="C:\Program Files\osquery\osquery.conf" 后,出现错误日志:
I0212 13:55:33.071751 8240 eventfactory.cpp:156] Event publisher not enabled: etw_process_publisher: etw_process_publisher publisher disabled via configuration.
解决方法
- 确认osquery版本兼容性
etw_process_publisher是osquery 4.3.0及后续版本引入的功能,先执行以下命令检查当前版本:
osqueryd.exe --version
如果版本低于4.3.0,需要升级到符合要求的版本。
- 修改配置文件启用发布器
在配置文件的options节点中添加"enable_etw_process_publisher": true参数,显式启用该事件发布器。修改后的完整配置如下:
{ // Configure the daemon below: "options": { "event_publisher": "etw_process_publisher", "enable_ntfs_event_publisher": true, "enable_etw_process_publisher": true }, "schedule": { "chrome_extensions": { "query": "SELECT * from users;", "interval": 3600 } } }
- 重启osquery服务
重新执行启动命令,验证错误日志是否不再出现:
osqueryd.exe --config_path="C:\Program Files\osquery\osquery.conf"
内容的提问来源于stack exchange,提问作者tarlan aliyev
相关产品推荐
相关产品推荐

