Hi everyone! Is there any reason why osquery doesn...
# general
m
Hi everyone! Is there any reason why osquery doesn’t refresh configuration? Only when started it gets config from Kolide fleet, and I can’t see no more tries to refresh conf further, but config_refresh parameter is set to 60. Checked the osquery behavior with verbose and tls_dump settings. Osquery is installed on Linux, version 4.2.0 Help me to understand it please? For now there is no way to update config except osquery restart. Also if it’s the very first start of osquery, osquery doesn’t ever get scheduled queries from packs (restart helps as well)...