Hello! I am trying to get osquery on Windows to re...
# general
r
Hello! I am trying to get osquery on Windows to report to a Wazuh Dashboard. I find documentation for osquery on Windows much harder to find than for Linux OS. From what I gather, Wazuh monitors the osquery.results.log file via the agent. However, it seems that osqueryd is running but not doing much of anything (the osquery.results.log gets no changes). So in the Wazuh dashboard I can see all that wazuh learns from ingested logs on the machine, but there is nothing in the osquery module. Can anyone point me to a comprehensive guide/tutorial for operating osquery on Windows, and ideally for integrating it with Wazuh? If not, I'm happy to post my config and flag files here if someone is able to help me figure out where things are stuck. Thank you for any assistance you can provide!