I think Scheduled queries can be directed where ev...
# fleet
f
I think Scheduled queries can be directed where ever(S3, stout, firehose etc) Is there a way to point the result or live queries to be stored.
g
Greetings Frederick, Logging destinations can currently be configured for Osquery status logs, scheduled query logs, and Fleet's audit logs. https://fleetdm.com/docs/using-fleet/log-destinations There is on the roadmap (think end of Q4 into Q1) a feature for Cached Query Results that might be what looking for with the adhoc/live query results
b
You could set https://fleetdm.com/docs/configuration/fleet-server-configuration#redis-duplicate-results And then write your own redis pubsub subscriber
f
@Jiayu Chang for vis
Thanks for that information. Yeah looking forward to that. I can test the redis pubsub on the side
j
We are seeing discrepancy in output from scheduled query and live query on the same host. Does anyone know how to troubleshot?
k
Hey @Jiayu Chang, please start a new thread for this so that things don't get confusing 🙂