core
  • s

    seph

    08/19/2022, 7:25 PM
    close and reopen the changelog?
  • Stefano Bonicatti

    Stefano Bonicatti

    08/19/2022, 7:30 PM
    Yeah it wasn’t flaky, it was always failing; 7742 should fix it
  • Mike Myers

    Mike Myers

    08/22/2022, 6:24 PM
    5.5.0 Change log is ready to approve / merge https://github.com/osquery/osquery/pull/7737
  • Mike Myers

    Mike Myers

    08/22/2022, 6:24 PM
    I mean 5.5.1
  • s

    seph

    08/22/2022, 7:08 PM
    I think you can reasonably approve that
  • Mike Myers

    Mike Myers

    08/23/2022, 6:30 AM
    not I, but maybe @Stefano Bonicatti can when he returns
  • zwass

    zwass

    08/23/2022, 4:45 PM
    Fleet has been running osquery 5.5.0 for ~a week internally now and our automated tests also seem to be working.
  • Mike Myers

    Mike Myers

    08/26/2022, 6:10 PM
    A user has opened a couple of issues about the documentation of
    hidden
    columns in tables. https://github.com/osquery/osquery/issues/7750 Are they intended to be documented? They're hidden by default, not because they are secret or intended not to be used, right?
  • Mike Myers

    Mike Myers

    08/31/2022, 4:38 PM
    Anything we can do today to move 5.5.1 to official release?
  • s

    seph

    09/01/2022, 12:16 AM
    Oops I forgot before I left town. Let me see if I can do this from my phone.
  • s

    seph

    09/01/2022, 1:14 AM
    I clicked some buttons. Release is probably going
  • a

    Artemis Tosini

    09/21/2022, 3:27 PM
    I'm working on porting forward an old patch for containerd support, which requires grpc. I can get it to run but it fails when upgrading grpc with a linking error. I'd rather not keep an ancient grpc version, so does anyone with experience with cmake have troubleshooting suggestions?
  • a

    Artemis Tosini

    09/21/2022, 3:27 PM
  • zwass

    zwass

    09/22/2022, 4:38 PM
    Hey folks, are we ready to mark 5.5.1 as stable?
  • s

    seph

    09/22/2022, 5:39 PM
    This was just blocked on making a website PR. Let me see…
  • s

    seph

    09/22/2022, 5:46 PM
    I do not even remember how to tell how what’s in the doanloads
  • s

    seph

    09/22/2022, 5:57 PM
    I’ll just re-gen erate things
  • s

    seph

    09/22/2022, 5:59 PM
  • terracatta

    terracatta

    09/29/2022, 1:16 PM
    @zwass @mikermcneil Hey guys. Not sure if this is the best place to discuss this with the core team. I recently noticed that FleetDM is mirroring many of the conversations happening in this Slack on your website. https://osquery.fleetdm.com/t/2679/hi-i-am-trying-to-get-the-values-associated-to-a-windows-reg I have a problem with this because it’s taking content that you have no ownership of (including content written by me and my employees) and placing it on your webpages which have clear CTAs to try your product. I don’t mind things I say and contribute here being used to help and promote the osquery project itself, but I take issue with it being used on your domain and branding. I think that this Slack archiving capability is a great idea that will absolutely help the community, but I would be much more comfortable with it living on osquery.io not on fleetdm.com. It would be great if you guys could work with the right folks and host it on osquery.io and with osquery branding, but if you don’t have the time to do that, then I insist you take it down as soon as possible.
  • s

    seph

    09/29/2022, 2:13 PM
    Thanks for raising this @terracatta. For myself, and maybe for the core team, I feel uncomfortable with slack archives there. I recognize the value in archives, but it does feel weird in the fleet branding.
  • s

    seph

    10/11/2022, 1:03 AM
    A bit later than planned, but 5.6.0 has been cut and there are builds up at https://github.com/osquery/osquery/releases/tag/5.6.0
  • zwass

    zwass

    10/13/2022, 5:16 PM
    Hey folks, any concern with adding Fleet as a sponsor on the bottom of osquery.io? We are currently the biggest backer on LFX crowdfunding, invest significant development resources into osquery, and now maintain and pay for the slack archives.
  • a

    Artemis Tosini

    10/14/2022, 4:55 PM
    I'm for that but I'm a bit biased
  • j

    JanRC

    10/21/2022, 1:55 PM
    Hello. I have created an issue https://github.com/osquery/osquery/issues/7797. The suggested thing is to widen the info available in windows_optional_features table.
  • Stefano Bonicatti

    Stefano Bonicatti

    10/25/2022, 5:58 PM
    By the way, the sqlite one I forgot that we did update the library already since it's easy to update. So beyond not being affected by the original CVE, in 5.5.1 we had already updated it.
  • happy-dude

    happy-dude

    11/18/2022, 7:48 PM
    hey team, I was wondering if I can get some help tweaking or investigating this further: on certain hosts with osquery, I frequently see
    Linesize exceeds TLS logger maximum:
    warnings at 5MB, 10MB, and 13MB values I believe this indicates that a query result from osquery is larger than the
    logger_tls_max_linesize
    value and is being dropped/not sent to the TLS endpoint. At the moment, that value is set to the default 1MB currently, I configured osqueryd to run with the following
    --config_tls_max_attempts=6
    --database_path=/state/osquery.db
    --decorations_top_level=true
    --disable_events=true
    --disable_extensions=false
    --disable_watchdog=false
    --docker_socket=/run/docker.sock
    --enroll_secret_path=/etc/osquery/enroll_secret.txt
    --enroll_tls_endpoint=<endpoint>
    --host_identifier=hostname
    --logger_plugin=tls
    --logger_tls_endpoint=<endpoint>
    --logger_tls_max_linesize=1048576
    --logger_tls_period=60
    --read_max=209715200
    --table_delay=200
    --tls_hostname=<endpoint>
    --tls_session_reuse=true
    --tls_session_timeout=3600
    --utc=true
    --watchdog_memory_limit=900
    I was curious if anyone would know if there are settings I can tweak to avoid dropping these results, or if there was a way I can investigate which query pack was causing such a large result?
  • j

    JanRC

    11/29/2022, 12:03 PM
    Hello, is there an option to run osquery on windows without without installing it? E.g. using powershell (winRM) to invoke portable osquery without installing it on target servers.
  • j

    jurelou

    12/05/2022, 7:55 PM
    Hello guys, I noticed that osquery is trying to resolve AWS ip addresses on startup (using osqueryi). I am not using any AWS related tables nor uploading results to AWS. Has anyone experienced something similar ?