ET
03/02/2021, 8:11 PMsanjaykcse
03/05/2021, 10:41 AMmanoj434
03/08/2021, 4:06 AMDan Achin
03/08/2021, 6:39 PM--enroll_secret_path=
--tls_hostname=
--host_identifier=
--enroll_tls_endpoint=/api/v1/osquery/enroll
--config_plugin=tls
--config_tls_endpoint=/api/v1/osquery/config
--config_refresh=3600
--disable_distributed=false
--distributed_plugin=tls
--distributed_interval=60
--distributed_tls_max_attempts=3
--distributed_tls_read_endpoint=/api/v1/osquery/distributed/read
--distributed_tls_write_endpoint=/api/v1/osquery/distributed/write
--logger_plugin=tls
--logger_tls_endpoint=/api/v1/osquery/log
--logger_tls_period=10
I'd just like to confirm the recommended approach to do that would be to remove the following settings from our osquery.flags file (and remove the config we are setting at Fleet - the stuff in osquery options / fleetctl get options):
--config_refresh
--config_plugin
--config_tls_endpoint
Anything else?zwass
RocksDB: [WARN] [db/db_impl/db_impl_open.cc:1805] Persisting Option File error: OK
? This seems to be perhaps associated with the database getting reset (we notice a new instance
host identifier) right around the time this is logged.Bacarus
03/09/2021, 2:04 PMRudra Sarkar
03/10/2021, 4:58 PMJams
03/11/2021, 5:15 PMAntoinette
03/11/2021, 9:25 PMshell_history
table?Bryan Brewer
03/12/2021, 9:41 PMosqueryi --extension /etc/osquery/foo.ext
or
osqueryi --nodisable_extensions
and other session /usr/bin/python /etc/osquery/foo.ext --socket /root/.osquery/shell.em
the very same extension autoloads fine on an older box different distro...
double checked the configs. they match on working and non-working endpoints.
turned on --verbose, but all I see in the non-working logs is
/var/log/osquery/osqueryd.INFO.20210312-185550.13594:I0312 18:55:58.125411 13630 registry_factory.cpp:107] Extension 37844 registered table plugin foo
/var/log/osquery/osqueryd.INFO.20210312-203820.19041:I0312 20:38:29.640424 19081 interface.cpp:110] Registering extension (foo, 26890, version=1.0.0, sdk=1.8.0)
I see it registered
osquery> select * from osquery_extensions;
+-------+-------------------+---------+-------------+-------------------------------+-----------+
| uuid | name | version | sdk_version | path | type |
+-------+-------------------+---------+-------------+-------------------------------+-----------+
| 0 | core | 4.5.1 | 0.0.0 | /root/.osquery/shell.em | core |
| 35494 | foo | 1.0.0 | 1.8.0 | /root/.osquery/shell.em.35494 | extension |
+-------+-------------------+---------+-------------+-------------------------------+-----------+
but when auto-loading
osquery> select * from foo;
Error: no such table: foo
just wondering if there's any other pointers out there that I'm not finding in the docs.Alexander
03/15/2021, 6:17 PMdefensivedepth
03/15/2021, 6:36 PMetsang
03/15/2021, 10:53 PMJason Lockwood
03/16/2021, 6:14 PMDan Achin
03/16/2021, 8:18 PMJuue
03/17/2021, 6:58 AMChris Benninger
03/17/2021, 4:49 PMAshwin Kawade
03/18/2021, 11:33 PM# Server
--tls_hostname=xxxxx:8412
--tls_server_certs=/home/dell/fleet.pem
# Enrollment
--host_identifier=instance
--enroll_secret_path=/home/dell/secret.txt
--enroll_tls_endpoint=/api/v1/osquery/enroll
# Configuration
--config_plugin=tls
--config_tls_endpoint=/api/v1/osquery/config
--config_refresh=10
# Live query
--disable_distributed=false
--distributed_plugin=tls
--distributed_interval=10
--distributed_tls_max_attempts=3
--distributed_tls_read_endpoint=/api/v1/osquery/distributed/read
--distributed_tls_write_endpoint=/api/v1/osquery/distributed/write
# Logging
--logger_plugin=tls
--logger_tls_endpoint=/api/v1/osquery/log
--logger_tls_period=10
# File carving
--disable_carver=false
--carver_start_endpoint=/api/v1/osquery/carve/begin
--carver_continue_endpoint=/api/v1/osquery/carve/block
--carver_block_size=2000000
secret.txt and fleet.pem are at home directory.
please help me to resolve this issue. Thank youzwass
Mystery Incorporated
03/19/2021, 6:51 PMMystery Incorporated
03/20/2021, 9:52 AMehrhardt
03/22/2021, 7:03 PMThe carves table returns data based on the current user by default, consider JOINing against the users table
I don't see a uid or shared data field between the carves table and the users table. What can be done to address this message?etsang
03/23/2021, 4:36 PMetsang
03/23/2021, 5:46 PMthomaseldredge
03/23/2021, 9:15 PMdownload target osquery/windows/stable/osqueryd: tuf: unknown target file: osqueryd/windows/stable/osqueryd.exe
I'm running a fleet preview instance with fleetctl3.9.0 on ubuntu server.
The client is a windows10 desktop with osquery4.7.0 installed. I'm using the orbit v0.0.1 release binaries running from an elevated command prompt.Dan Achin
03/24/2021, 7:19 PMBrandon
03/25/2021, 12:15 AMPrakash Choudhary
03/26/2021, 3:54 AMjavuto
03/28/2021, 6:22 PMubuntu:20.04
images identify the architecture as aarch64
instead of arm64
. Does it make sense to duplicate the published package to be both arm64
and aarch64
?togal
03/30/2021, 7:14 AM