mason kemmerer
01/04/2024, 9:05 PMKathy Satterlee
01/09/2024, 9:59 PMmason kemmerer
01/10/2024, 3:02 PMmason kemmerer
01/10/2024, 3:04 PMSELECT * from osquery_schedule
and can see the results going to the query_results table in mysql with current timestamps...
just ever since this upgrade the result.log has not been updated, when i reviewed the mysql binlogs it looked like result data that was base64 encodedmason kemmerer
01/10/2024, 3:05 PMmason kemmerer
01/10/2024, 6:39 PMSELECT * from osquery_schedule WHERE query LIKE "select * from rpm_packages"
mason kemmerer
01/10/2024, 6:40 PMKathy Satterlee
01/11/2024, 10:04 PMKathy Satterlee
01/11/2024, 10:11 PMmason kemmerer
01/12/2024, 3:01 PMKathy Satterlee
01/12/2024, 11:23 PMmason kemmerer
01/13/2024, 12:41 AMmason kemmerer
01/13/2024, 12:46 AM{
"component": "http",
"err": "error writing result logs (if the logging destination is down, you can reduce frequency/size of osquery logs by increasing logger_tls_period and decreasing logger_tls_max_lines): writing log: can't rename log file: rename /var/log/osquery/result.log /var/log/osquery/result-2024-01-13T00-45-30.101.log: permission denied",
"ip_addr": "172.18.38.205",
"level": "error",
"method": "POST",
"took": "231.858647ms",
"ts": "2024-01-13T00:45:30.101966418Z",
"uri": "/api/v1/osquery/log",
"uuid": "c8c7e695-684d-414c-8973-ece403f823c5",
"x_for_ip_addr": "172.18.38.205"
}
mason kemmerer
01/13/2024, 12:49 AMfilesystem:
status_log_file: /var/log/osquery/status.log
result_log_file: /var/log/osquery/result.log
enable_log_rotation: true
mason kemmerer
01/13/2024, 12:53 AMmason kemmerer
01/13/2024, 1:01 AM### Setup logging directory ###
RUN mkdir /var/log/osquery && \
chown root:root /var/log/osquery && \
touch /var/log/osquery/status.log && \
touch /var/log/osquery/result.log && \
chown fleet:fleet /var/log/osquery/result.log && \
chown fleet:fleet /var/log/osquery/status.log
mason kemmerer
01/13/2024, 1:20 AMmason kemmerer
01/13/2024, 1:20 AM/var/log/osquery $ ls -l
total 536648
-rw-r--r-- 1 root root 25176131 Nov 7 19:40 masonk@10.0.0.5
-rw-r--r-- 1 fleet fleet 524287805 Jan 2 17:30 result.log
-rw-r--r-- 1 fleet fleet 52335 Jan 5 16:47 status.log
mason kemmerer
01/13/2024, 1:23 AMmason kemmerer
01/13/2024, 1:56 AMcp result.log result.log.bk
then touch result.log
and chown fleet:fleet result.log
within moments the "new" result.log filled up, so I believe I am on the right track:
/var/log/osquery # ls -l
total 1048652
-rw-r--r-- 1 root root 25176131 Nov 7 19:40 masonk@10.0.0.5
-rw-r--r-- 1 fleet fleet 524287744 Jan 13 01:55 result.log
-rw-r--r-- 1 root root 524287805 Jan 13 01:50 result.log.bk
-rw-r--r-- 1 fleet fleet 52951 Jan 13 01:53 status.log
mason kemmerer
01/13/2024, 2:08 AM/var/log/osquery # ls -l
total 1153456
-rw-r--r-- 1 root root 25176131 Nov 7 19:40 mkemmerer@10.64.121.211
-rw-r--r-- 1 fleet fleet 524287744 Jan 13 01:55 result-2024-01-13T02-06-40.494.log
-rw-r--r-- 1 fleet fleet 107312777 Jan 13 02:07 result.log
-rw-r--r-- 1 root root 524287805 Jan 13 01:50 result.log.bk
-rw-r--r-- 1 fleet fleet 52951 Jan 13 01:53 status.log
mason kemmerer
01/13/2024, 2:09 AMmason kemmerer
01/13/2024, 2:10 AMfilesystem:
max_age: 0
specified in my fleetdm.yml config file?mason kemmerer
01/13/2024, 2:25 AMfilesystem:
max_backups: 0