Victor Lyuboslavsky
01/05/2024, 2:03 PMconfig_tls_endpoint
. They are only set once at startup and cannot be changed afterwards.
--logger_tls_endpoint
--logger_tls_period
--logger_tls_max_lines
Is this a bug?
Or is the fact that these settings are set once and cannot be updated until osquery restart documented somewhere?
I'd like to see the ability to remotely restart osquery if a setting cannot be applied -- either as a separate config --osquery_restart=true
or automatically if an updated setting via config_tls_endpoint cannot be immediately applied.Stefano Bonicatti
01/05/2024, 2:18 PMStefano Bonicatti
01/05/2024, 2:19 PMStefano Bonicatti
01/05/2024, 2:19 PMStefano Bonicatti
01/05/2024, 2:21 PMStefano Bonicatti
01/05/2024, 2:23 PMVictor Lyuboslavsky
01/05/2024, 2:28 PMStefano Bonicatti
01/05/2024, 2:28 PMStefano Bonicatti
01/05/2024, 2:32 PMVictor Lyuboslavsky
01/05/2024, 2:33 PMStefano Bonicatti
01/05/2024, 2:36 PMosquery --help
which always has been the ultimate truth.
Again FLAGs will react to remote config file changes if the code has been written to do so, and that flag is not erroneously marked as FLAG
CLI_FLAGs will not react to remote config file changesStefano Bonicatti
01/05/2024, 2:37 PM--help
the "osquery command line flags" are the CLI_FLAGS, the "osquery configuration options (set by config or CLI flags):" are the FLAGsStefano Bonicatti
01/05/2024, 2:38 PMVictor Lyuboslavsky
01/05/2024, 2:39 PMStefano Bonicatti
01/05/2024, 2:42 PMStefano Bonicatti
01/05/2024, 2:43 PMStefano Bonicatti
01/05/2024, 2:43 PMVictor Lyuboslavsky
01/05/2024, 2:45 PMStefano Bonicatti
01/05/2024, 2:50 PMVictor Lyuboslavsky
01/05/2024, 2:53 PMStefano Bonicatti
01/05/2024, 3:16 PMStefano Bonicatti
01/05/2024, 3:18 PMseph
--help
output. This difference is partly around security/privacy, and partly around what makes sense implementation-wise
As Stefano said — there’s a lot of manual updating around this, so there may well be bug in how the docs are written. And even in which flags show up where. There’s almost certainly place to PR fixes…
It sounds like there is a separate question around some flags which can be set once via a remote config but then cannot be changed. I cannot decide if this is a bug, or if it’s a category of flag we should embrace. I’m curious where people are leaning.Stefano Bonicatti
01/08/2024, 1:16 PMStefano Bonicatti
01/08/2024, 1:16 PMseph
Stefano Bonicatti
01/08/2024, 1:21 PMStefano Bonicatti
01/08/2024, 1:22 PMseph
Stefano Bonicatti
01/08/2024, 1:27 PMStefano Bonicatti
01/08/2024, 1:35 PMseph
seph
Stefano Bonicatti
01/08/2024, 1:41 PMStefano Bonicatti
01/08/2024, 1:42 PMVictor Lyuboslavsky
01/08/2024, 1:55 PMseph
set once but remotelyFeels like it would only make sense with a lot of additional monitoring. And it’s feels like it’s getting a bit far outside our usual use case