diff --git a/osquery/events/darwin/openbsm.cpp b/osquery/events/darwin/openbsm.cpp index 3f72bb468b5..cb231810018 100644 --- a/osquery/events/darwin/openbsm.cpp +++ b/osquery/events/darwin/openbsm.cpp @@ -47,7 +47,7 @@ Status OpenBSMEventPublisher::configureAuditPipe() { } if (ioctl(au_fd, AUDITPIPE_SET_QLIMIT, &kQLimit) == -1) { - LOG(INFO) << "The auditpipe:ioctl AUDITPIPE_SET_QLIMIT failed"; + LOG(WARNING) << "The auditpipe:ioctl AUDITPIPE_SET_QLIMIT failed"; } au_mask_t pr_flags = {0, 0}; diff --git a/osquery/events/windows/etw/etw_user_session.cpp b/osquery/events/windows/etw/etw_user_session.cpp index af0b0680e89..7a952502e34 100644 --- a/osquery/events/windows/etw/etw_user_session.cpp +++ b/osquery/events/windows/etw/etw_user_session.cpp @@ -176,6 +176,8 @@ void UserEtwSessionRunnable::initUserTraceSession( void UserEtwSessionRunnable::stopUserTraceSession( const std::string& sessionName) { if (sessionName.empty()) { + LOG(ERROR) << "Failed to stop user trace session - session does not have " + "a name."; return; } @@ -201,4 +203,4 @@ void UserEtwSessionRunnable::stopUserTraceSession( LOG(WARNING) << "ControlTrace() failed with error code " << retCtrl; } } -} // namespace osquery \ No newline at end of file +} // namespace osquery