Ojas
10/06/2022, 5:30 AMOjas
10/06/2022, 5:30 AMOjas
10/06/2022, 10:01 AMwennan.he
10/07/2022, 4:18 AMwennan.he
10/07/2022, 5:48 PMOjas
10/10/2022, 11:34 AMStephan M
10/10/2022, 3:32 PMconfig_refresh
via the agent options? Started to get Could not update settings. common config: json: unknown field "config_refresh"
with the latest version even though it's a valid option based on https://osquery.readthedocs.io/en/stable/installation/cli-flags/#configuration-control-flagsoneiroi
10/11/2022, 12:02 PMplatform:
though I wonder if there's any further more granular level filtering that could be applied, for example;
Alice 's machine - creates secrets to share with Bob; I'd like to author a query to check for the presence of Bob's pubkey, it would make sense for this to only be run on Alice's machine.
I am not sure if it is at all possible to apply filtering / targeting more granular than the OS in such packs?oneiroi
10/11/2022, 12:03 PMAlex Loewenthal
10/11/2022, 6:30 PMwennan.he
10/11/2022, 9:38 PMwennan.he
10/11/2022, 10:14 PMManu Odago
10/12/2022, 8:32 AMdefensivedepth
10/12/2022, 4:12 PMConfiguring osqueryd to communicate with Fleet is documented below in the "Native Osquery TLS Plugins" section.
But, there is no Native Osquery TLS Plugins
sectiondefensivedepth
10/12/2022, 4:20 PMwennan.he
10/12/2022, 7:28 PMwennan.he
10/12/2022, 8:21 PMwennan.he
10/13/2022, 3:51 AMJoe
10/13/2022, 2:08 PMwennan.he
10/13/2022, 4:49 PMTerra
10/13/2022, 5:32 PMwennan.he
10/13/2022, 7:09 PMwennan.he
10/13/2022, 10:07 PMKathy Satterlee
10/13/2022, 10:15 PMOjas
10/14/2022, 9:44 AMDuong Tran
10/14/2022, 4:57 PMwennan.he
10/14/2022, 10:17 PMErik Tank
10/16/2022, 4:53 AMpeanut butter
10/16/2022, 3:20 PMTerra
10/17/2022, 4:02 PMsystemctl status fleet.service
after upgrading from 4.17.0 to 4.21.0. The OSquery web UI was even working briefly after the upgrade! However, the fleet service continues to use up all memory on server until it kills itself. I don't know what to do next! This issue is not happening in our NP environment and they have almost identical hosts and queries on both