niba nazar
08/30/2022, 9:17 AMniba nazar
08/30/2022, 9:28 AMniba nazar
09/01/2022, 1:52 PMniba nazar
09/01/2022, 2:07 PMsudo useradd -r -s /bin/false <username>
sudo systemctl stop osqueryd
sudo mkdir /var/run/osquery
sudo chown -R osquery:osquery /var/osquery
sudo chown -R osquery:osquery /var/run/osquery
sudo mkdir /etc/systemd/system/osqueryd.service.d
cat << EOF | sudo tee /etc/systemd/system/osqueryd.service.d/nonroot.conf
[Service]
User=<username>
Group=<username>
AmbientCapabilities=CAP_AUDIT_CONTROL CAP_AUDIT_READ CAP_DAC_READ_SEARCH
PIDFile=/var/osquery/osqueryd.pidfile
EOF
echo "--pidfile=/var/osquery/osqueryd.pidfile" | sudo tee -a /etc/osquery/osquery.flags
sudo systemctl daemon-reload
sudo systemctl start osqueryd
After this as a root user and non-root user I was able to fetch syslog data, however, after some time I start to get the error as I shown above : and no data obtained for syslog till now(both as root and non-root user.
E0901 110339.587262 10114 udev.cpp:89] udev monitor returned invalid device: No buffer space availableSlackbot
09/02/2022, 6:30 PMPraveen Kumar
09/03/2022, 2:37 PMPraveen Kumar
09/03/2022, 2:37 PMPraveen Kumar
09/03/2022, 2:37 PMPraveen Kumar
09/03/2022, 2:38 PMPraveen Kumar
09/04/2022, 5:09 AMPraveen Kumar
09/04/2022, 9:02 AMKunal
09/05/2022, 5:32 AMKunal
09/05/2022, 5:33 AMgeneratePluginsLoggerShhlogger()
function(generatePluginsLoggerShhlogger)
add_osquery_library(plugins_logger_shhlogger EXCLUDE_FROM_ALL
shh_logger_linux.cpp
)
enableLinkWholeArchive(plugins_logger_shhlogger)
target_link_libraries(plugins_logger_shhlogger PUBLIC
osquery_cxx_settings
plugins_logger_commondeps
osquery_filesystem
osquery_utils_config
osquery_utils_conversions
)
set(public_header_files
shh_logger_linux.h
)
generateIncludeNamespace(plugins_logger_shhlogger "plugins/logger" "FILE_ONLY" ${public_header_files})
endfunction()
------------------------------------
I have observed that, it does generate some cmake artifacts related to this plugin in the "build" folder.
Eg: "/build/plugins/logger/CMakeFiles/plugins_logger_shhlogger.dir".
But, the cmake build does not generate symbolic link for the header file "shh_logger_linux.h" under "build" folder.
For eg, I was expecting following symlink to be generated: /build/ns_plugins_logger_shhlogger/plugins/logger/shh_logger_linux.h. But 'ns_plugins_logger_shhlogger' was not generated.
However, other default logger plugins do generate such symlink, eg "tls" logger plugin generates (/build/ns_plugins_logger_tlslogger/plugins/logger/tls_logger.h).
Somehow, the cmake build is not building this plugin. Does anybody have any suggestions to resolve this ?
(PS: I have observed the same behavior with plugins_logger_windowseventlog. Though, it produces some artifacts in "/build/plugins/logger/CMakeFiles/", it does not get built)
Thanks
KunalBoubacary Diallo
09/05/2022, 5:25 PMHello, how are you, I hope you are well!
I deployed a fleet of which I deployed osquery agents. Getting to a certain number of agents, often when a new host is deployed, it downgrades another one from the list. I get the following errors on the output to the osquery server:
1/osquery/distributed/read","ts":"2022-09-05T152012.164277378Z"}
Sep 5 152015 osquery fleet[69161]: {"component":"http","err":"authentication error: invalid node key: /uLuK4hiUVdU3hZVXS5dcivDzQFpwfAX","level":"info","path":"/api/v1/osquery/config","ts":"2022-09-05T152015.9287988Z"slevchenko
09/06/2022, 6:44 AMPraveen Kumar
09/06/2022, 6:16 PMPraveen Kumar
09/06/2022, 6:47 PMMike Myers
09/06/2022, 8:39 PMPraveen Kumar
09/07/2022, 3:53 AMVanDT
09/08/2022, 8:45 AMTyson Supasatit
09/08/2022, 8:21 PMRobert R. Henry
09/13/2022, 9:20 PMr
09/14/2022, 11:14 AMag4ve
09/14/2022, 8:02 PMVenky
09/15/2022, 11:28 AMBrandon Mesa
09/16/2022, 3:09 PMAndrea
09/16/2022, 4:23 PMDECLARE_PUBLISHER
and`REGISTER` macros. Overridden all the virtual methods etc. Set it to return a failure status from setUp()
so that I could see the “wiring” succeeding. I was expecting this to be enough but I don’t see it registered or even failing as expected. headdesk
Nothing seems working. Any suggestion ?Mystery Incorporated
09/17/2022, 7:11 AMStefano Bonicatti
09/17/2022, 8:33 AMMystery Incorporated
09/17/2022, 9:34 AM