Dulal
01/30/2022, 9:45 AMNafisa Tasneem
01/31/2022, 6:07 AMuser
01/31/2022, 4:52 PMpvirani
02/01/2022, 12:32 AMCould not read SMBIOS memory
I0201 00:31:42.133729 1860 tls.cpp:255] TLS/HTTPS POST request to URI: <https://fleetdm.segment.build/api/v1/osquery/enroll>
I0201 00:31:42.152062 1860 http_client.cpp:420] HTTP(S) request re-directed to: <https://segment.okta.com/oauth2/v1/authorize?client_id=**********************************>
^CW0201 00:31:42.745014 1860 tls_enroll.cpp:101] Failed enrollment request to <https://fleetdm.segment.build/api/v1/osquery/enroll> (Cannot parse JSON: Invalid value. Offset: 0) retrying...
Tor Houghton
02/02/2022, 12:29 PMRyan
02/02/2022, 3:30 PMrwa
02/02/2022, 3:55 PMfleetctl package
command to build installers. All of the clients are on osquery 5.0.1 which they started with. I would just like to monitor that they update when a new version is specified (my understanding is that this is the default with no special settings).Ryan
02/02/2022, 5:12 PM--tls-skip-verify
for Redis instances? I see the option is available for MySQL, but itās not listed in the docs for Redis. https://fleetdm.com/docs/deploying/configuration#redisTor Houghton
02/02/2022, 5:12 PMzhong
02/02/2022, 5:49 PMFrequency
affect certain queries in the packs?n8felton
02/02/2022, 10:25 PMdram
02/02/2022, 11:52 PMzwass
J
02/03/2022, 7:41 AMRafael
02/03/2022, 3:03 PMn8felton
02/03/2022, 4:57 PMuser
02/03/2022, 5:57 PMdram
02/03/2022, 9:28 PMNicolas
02/04/2022, 6:51 AMArtem
02/07/2022, 5:21 PMW0207 18:02:24.934172Ā 4352 watcher.cpp:391] osqueryd worker (560) stopping: Maximum sustainable CPU utilization limit exceeded: 18
close after executing fleet_detail_query_software_windows
⢠Adding --disable_watchdog=false --watchdog_delay=120 --watchdog_level=0 --watchdog_memory_limit=400 --watchdog_utilization_limit=21
was with no luck;
And now I have no thoughts..Ted Dorosheff
02/07/2022, 8:38 PMW0207 12:30:36.535475 6440 options.cpp:101] Cannot set unknown or invalid flag: enable_file_events
as well as:
I0207 12:30:47.051750 6440 eventfactory.cpp:156] Event publisher not enabled: ntfs_event_publisher: NTFS event publisher disabled via configuration
I0207 12:30:47.113627 6440 events.cpp:70] Skipping subscriber: powershell_events: Required publisher is disabled by configuration
both of those event publishers are enabled within the overrides section of my config, and the enable_file_events: true
is set outside by overrides key. So its fleetDM is not respecting the overrides key...user
02/08/2022, 12:53 AMJason
02/08/2022, 4:15 AMagent_options:
config:
decorators:
load:
- SELECT uuid AS host_uuid FROM system_info;
- SELECT computer_name AS hostname FROM system_info;
Ryan
02/08/2022, 6:20 PMlevel=error ts=2022-02-08T18:18:27.469599841Z op=QueriesForHost err="load active queries: EOF"
pvirani
02/08/2022, 7:11 PMbenbass
02/08/2022, 7:54 PMbenbass
02/08/2022, 7:55 PMBacarus
02/09/2022, 9:53 AMKrasheninnikov Denis
02/09/2022, 2:59 PMError: app_not_configured_for_user
Ā from google SSO? Was followingĀ this instructuions
Getting this error for any user: existing/non-existing, with/without SSO enabledbenbass
02/09/2022, 8:10 PM