2 questions: 1) if I use kafka as logger without a...
# general
v
2 questions: 1) if I use kafka as logger without any fleet manager, how can I push new packs/scheduled queries to the agent? 2) with events tables configured with --event_expiry 1 , the events are evicted only with scheduled queries or also with manual query via kolide/etc?