John Kornfeld
12/23/2021, 12:33 AMabraham linkolan
12/23/2021, 3:11 PMJason
12/23/2021, 7:46 PMGlen
12/23/2021, 8:13 PMDavid J Davis
12/28/2021, 3:31 PMCyberUnify
12/28/2021, 5:03 PMHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\...
the check will take a long time to return the results ... is there any option to optimize this search?Daniel Weeber
12/29/2021, 8:06 PMJohn S
12/30/2021, 11:41 AMuser
12/30/2021, 10:50 PMmikermcneil
01/04/2022, 8:43 PMfleetctl
at a different Fleet server URL for a single command? (Or to reconfigure it to point at a different Fleet server URL?)ryan
01/04/2022, 8:59 PMselect * from chrome_extensions;
from osqueryi but when I run in Fleet it doesn't return any results. No errors either. Running 4.8Chad
01/05/2022, 8:40 AMSaulo Guilhermino
01/06/2022, 7:54 PMFLEET_VULNERABILITIES_CURRENT_INSTANCE_CHECKS
set to "no", will it still download the necessary databases for the check? More context in the thread 👇Ayan
01/07/2022, 3:39 PMauthentication error: find host
errors and all of the osquery agents are having connection timed out. I looked into the previous conversations related with this error in this Slack but could not really find anything relative. The fleet server is on 4.4.3
. Any guidance possible?David J Davis
01/07/2022, 5:34 PMuser
01/07/2022, 10:33 PMdefensivedepth
01/10/2022, 5:06 PMRyan
01/10/2022, 5:08 PM• Add ability to configure Fleet to send a webhook request with all hosts that failed a policy. Documentation on what data is included the webhook request and when the webhook request is sent can be found here on fleedm.com/docs.Is there already a way to retrieve the list of policies and which hosts are failing a policy, as the
pull
method would fit better than push
, with a use-case I have in mind.zwass
defensivedepth
01/10/2022, 9:04 PMVulnerability processing is enabled by default.
The 2nd section states: To enable vulnerability processing, first enable the software inventory feature by setting the following app config:
As of 4.8.0 - Is Vuln Processing enabled by default? What about new installs vs. upgrades?zhong
01/11/2022, 6:29 PM/etc/resolv.conf
with the domain nameserver IP and edited /etc/NetworkManager/NetworkManager.conf
so that the changes are on /resolv.conf
stay the same even after reboot. I've also disabled SELINUX
because it was not letting the hosts connect. Currently am stumped on what could be blocking the connection or why the hosts go offline. Any help on what could be the issue?demonbhao
01/12/2022, 8:41 AMSK
01/12/2022, 10:04 AMfleetctl package
to create a package, does it also automatically enable the update channels or are they disabled by default? I want to create a static package that does not use the update channelsRafael
01/13/2022, 9:23 AMuser
01/13/2022, 7:25 PMwkleinhenz
01/13/2022, 7:50 PMTor Houghton
01/14/2022, 10:06 AMStephan
01/14/2022, 2:10 PMzhong
01/14/2022, 3:12 PMTed Dorosheff
01/14/2022, 7:13 PMdecorators
?
or are file_paths
a sub parameter of decorators
?
Thanks!