Title
#general
t

Tomas Odehnal

03/28/2022, 3:07 PM
Hello all, can anyone please suggest if there is a way to get more debug logging from osquery beside
--verbose
? We use osquery with fleetdm and face this file carving issue. After creating file carving live query to carve several files, we obtain the carve ids and check the carve endpoint for results. Sometimes, several of the carve ids don't appear on the carve endpoint until a next carve query is requested. The verbose log on the osquery side just shows a bunch of
begin
and
block
calls, different number for 'failed' and 'successful' attempt.
zwass

zwass

03/28/2022, 5:43 PM
Hey Tomas, can you please provide more details on how we could reproduce this over in #fleet? We would like to fix this and/or advise you how to successfully use the file carving feature.
t

Tomas Odehnal

03/29/2022, 12:24 PM
Thanks. I'm trying to reproduce myself on fresh systems. Will get back to you.
8:30 PM
I could not reproduce when running the carving query with fleetctl. It happens when we call it via API. Fleet 4.12.0, osquery 5.0.1. What I found when checking
fleetctl query --labels 'All Hosts' --query 'select * from carves'
is that the missing carves are in the
SCHEDULED
state. Any idea why that might happen?
8:36 PM
I mean, they stay in the state even one hour after the carve request was created.
zwass

zwass

03/30/2022, 12:10 AM
So it works if you run the query via
fleetctl
, but doesn't work if you run the query via API?
12:10 AM
How are you calling the API?
t

Tomas Odehnal

03/30/2022, 12:48 PM
In the end I was able to reproduce with
fleetctl
. I ran 40 live queries, one
fleetctl query
command each 5 seconds. The carving query is the ninth and it contains 34 files to carve. 20 of the carves were stuck in the
SCHEDULED
state. Once I ran a simple carving query (one file) to 3 hosts with the stuck queries, all scheduled + the new 3 returned.
12:49 PM
Would this be sufficient to try to reproduce on your side? Please let me know if you need any additional info.
8:15 PM
@zwass Please is the above information sufficient or can I help in any way?