Ashish Maikhuri
02/13/2023, 4:39 PMwennan.he
02/13/2023, 6:47 PMLailton Montenegro
02/13/2023, 10:17 PM/API/v1/osquery/*
. Other requests will go through a filter. The idea is to filter who can access the fleet api and FleetUI. Does that make sense to you? Tks.Ojas
02/14/2023, 5:53 AMwkleinhenz
02/14/2023, 3:21 PMZapier
02/14/2023, 5:21 PMMarcio Gustavo Chahad
02/15/2023, 1:06 PM{
"component": "http",
"err": ": Authentication required",
"internal": "authentication error: invalid orbit node key",
"level": "info",
"path": "/api/fleet/orbit/config",
"ts": "2023-02-15T12:16:08.980611594Z"
}
Mike S.
02/15/2023, 4:17 PMRafa
02/15/2023, 4:17 PMconfig:
options:
pack_delimiter: /
logger_tls_period: 10
distributed_plugin: tls
disable_distributed: false
logger_tls_endpoint: /api/osquery/log
distributed_interval: 10
distributed_tls_max_attempts: 3
decorators:
load:
- SELECT uuid AS host_uuid FROM system_info;
- SELECT hostname AS hostname FROM system_info;
overrides:
platforms:
darwin:
options:
disable_audit: false
disable_events: false
file_paths:
etc:
- /etc/%%
homes:
- /Volumes/%%
users:
- /Users/%/Library/%%
- /Users/%/Documents/%%
command_line_flags: {} # requires Fleet's osquery installer
Jason Roberts
02/15/2023, 6:10 PMArsenio
02/15/2023, 6:52 PMSELECT safari_extensions.* FROM users join safari_extensions USING (uid);
Ojas
02/16/2023, 6:24 AMBenjamin Heater
02/16/2023, 5:01 PMAuthentication required
.
I pulled this via the API using the /debug
endpoint:
{
"count": 1353044,
"chain": [
{
"message": "Authentication required"
},
{
"data": {
"timestamp": "2023-02-16T11:39:00-05:00"
},
"stack": [
"<http://github.com/fleetdm/fleet/v4/server/service.(*Service).AuthenticateOrbitHost|github.com/fleetdm/fleet/v4/server/service.(*Service).AuthenticateOrbitHost> (orbit.go:91)",
"<http://github.com/fleetdm/fleet/v4/server/service.authenticatedOrbitHost.func1|github.com/fleetdm/fleet/v4/server/service.authenticatedOrbitHost.func1> (endpoint_middleware.go:132)",
"<http://github.com/fleetdm/fleet/v4/server/service.logged.func1|github.com/fleetdm/fleet/v4/server/service.logged.func1> (endpoint_middleware.go:225)",
"<http://github.com/fleetdm/fleet/v4/server/service/middleware/authzcheck.(*Middleware).AuthzCheck.func1.1|github.com/fleetdm/fleet/v4/server/service/middleware/authzcheck.(*Middleware).AuthzCheck.func1.1> (authzcheck.go:31)",
"<http://github.com/go-kit/kit/transport/http.Server.ServeHTTP|github.com/go-kit/kit/transport/http.Server.ServeHTTP> (server.go:121)",
"<http://github.com/prometheus/client_golang/prometheus/promhttp.InstrumentHandlerRequestSize.func2|github.com/prometheus/client_golang/prometheus/promhttp.InstrumentHandlerRequestSize.func2> (instrument_server.go:245)",
"net/http.HandlerFunc.ServeHTTP (server.go:2109)",
"<http://github.com/prometheus/client_golang/prometheus/promhttp.InstrumentHandlerResponseSize.func1|github.com/prometheus/client_golang/prometheus/promhttp.InstrumentHandlerResponseSize.func1> (instrument_server.go:284)",
"net/http.HandlerFunc.ServeHTTP (server.go:2109)",
"<http://github.com/prometheus/client_golang/prometheus/promhttp.InstrumentHandlerCounter.func1|github.com/prometheus/client_golang/prometheus/promhttp.InstrumentHandlerCounter.func1> (instrument_server.go:142)",
"net/http.HandlerFunc.ServeHTTP (server.go:2109)"
]
}
]
}
Any other ideas or advice would be appreciated. Let me know if there's any additional information I can provide.Zapier
02/16/2023, 8:32 PMchrismsnz
02/16/2023, 9:13 PMShawn Maddock
02/16/2023, 10:05 PMfleet prepare db
to upgrade the database non-interactively? Currently it pauses and wants an interactive [Enter]
to proceedwennan.he
02/17/2023, 12:33 AMVlad Previn
02/17/2023, 8:30 AMTor Houghton
02/17/2023, 8:46 PMTor Houghton
02/17/2023, 8:46 PMTor Houghton
02/17/2023, 8:50 PMwennan.he
02/20/2023, 4:58 AMZapier
02/20/2023, 5:35 PMVlad Previn
02/21/2023, 8:39 AMos info
system info
osq version (agent) info
had a quick look at the os_version, system_info and osquery_info and not quite clear how we’d join them (by udid or serial ?) in particular for the osinfo oneOjas
02/21/2023, 1:22 PM2023-02-21T18:42:39+05:30 INF Shutdown was requested!
2023-02-21T18:42:39+05:30 INF exit
2023-02-21T18:43:48+05:30 INF fleet-desktop version=1.3.1
2023-02-21T18:43:48+05:30 INF Comm channel was acquired
2023-02-21T18:43:48+05:30 INF ready
2023-02-21T18:43:48+05:30 DBG successfully refetched the token from disk
2023-02-21T18:43:49+05:30 INF Shutdown was requested!
2023-02-21T18:43:49+05:30 ERR get device URL error="GET /api/latest/fleet/device/************/desktop received status 429 limit exceeded, retry after: 0s: limit exceeded, retry after: 0s"
2023-02-21T18:43:49+05:30 INF exit\
Adrian Junge
02/21/2023, 2:08 PMdefensivedepth
02/21/2023, 4:31 PMPublic
means publicly-routable? This seems to be a bug then? v4.27.1Adrian Junge
02/21/2023, 4:41 PMArsenio
02/21/2023, 9:11 PMchrismsnz
02/21/2023, 10:37 PM/api/osquery/log
which is where the scheduled queries/packs etc return to by default. Not sure why its not /api/v1/osquery/log
or something