Secf
10/18/2024, 12:16 PMJacob Burley
10/18/2024, 12:29 PMSecf
10/18/2024, 12:34 PMSecf
10/18/2024, 12:34 PMZay Hanlon
10/18/2024, 2:27 PMSecf
10/18/2024, 3:01 PMZay Hanlon
10/18/2024, 3:33 PMZay Hanlon
10/18/2024, 3:33 PMSecf
10/18/2024, 4:05 PMRebecca Cowart
10/18/2024, 5:44 PMSELECT * FROM orbit_info
If it returns that the scripts are enabled, you could try refetching the hosts.Secf
10/19/2024, 4:10 PMRebecca Cowart
10/21/2024, 5:48 PMSecf
10/23/2024, 11:25 AMSecf
10/23/2024, 2:40 PMSecf
10/25/2024, 6:34 AMRebecca Cowart
10/25/2024, 12:01 PMSecf
10/25/2024, 12:03 PMRebecca Cowart
10/25/2024, 12:35 PMSecf
10/25/2024, 12:56 PMSecf
10/25/2024, 12:59 PMRebecca Cowart
10/25/2024, 1:17 PMKathy Satterlee
10/25/2024, 2:45 PMSecf
10/25/2024, 4:03 PM2024-10-24T11:20:33+03:00 INF token TTL expired, rotating token
2024-10-24T11:21:08+03:00 ERR error rotating token error="saving token after 3 attempts: POST /api/fleet/orbit/device_token: Post \"<https://fleet-test.com/api/fleet/orbit/device_token\|https://fleet-test.com/api/fleet/orbit/device_token\>": dial tcp x.x.x.x:443: connect: operation timed out"
2024-10-24T11:21:08+03:00 INF token TTL expired, rotating token
2024-10-24T11:21:40+03:00 INF network error error="POST /api/fleet/orbit/config: Post \"<https://fleet-test.com/api/fleet/orbit/config\|https://fleet-test.com/api/fleet/orbit/config\>": dial tcp x.x.x.x:443: connect: operation timed out"
2024-10-24T11:21:43+03:00 ERR error rotating token error="saving token after 3 attempts: POST /api/fleet/orbit/device_token: Post \"<https://fleet-test.com/api/fleet/orbit/device_token\|https://fleet-test.com/api/fleet/orbit/device_token\>": dial tcp x.x.x.x:443: connect: operation timed out"
2024-10-24T11:21:43+03:00 INF token TTL expired, rotating token
2024-10-24T11:22:19+03:00 ERR error rotating token error="saving token after 3 attempts: POST /api/fleet/orbit/device_token: Post \"<https://fleet-test.com/api/fleet/orbit/device_token\|https://fleet-test.com/api/fleet/orbit/device_token\>": dial tcp x.x.x.x:443: connect: operation timed out"
2024-10-24T11:22:19+03:00 INF token TTL expired, rotating token
2024-10-24T11:22:54+03:00 ERR error rotating token error="saving token after 3 attempts: POST /api/fleet/orbit/device_token: Post \"<https://fleet-test.com/api/fleet/orbit/device_token\|https://fleet-test.com/api/fleet/orbit/device_token\>": dial tcp x.x.x.x:443: connect: operation timed out"
2024-10-24T11:22:54+03:00 INF token TTL expired, rotating token
2024-10-24T12:22:58+03:00 INF token TTL expired, rotating token
2024-10-24T13:22:58+03:00 INF token TTL expired, rotating token
2024-10-24T14:31:44+03:00 INF token TTL expired, rotating token
2024-10-24T15:33:19+03:00 INF token TTL expired, rotating token
2024-10-24T16:33:19+03:00 INF token TTL expired, rotating token
2024-10-24T18:06:13+03:00 INF token TTL expired, rotating token
2024-10-24T19:37:05+03:00 INF token TTL expired, rotating token
2024-10-24T20:47:55+03:00 INF token TTL expired, rotating token
2024-10-24T21:47:55+03:00 INF token TTL expired, rotating token
2024-10-24T22:47:55+03:00 INF token TTL expired, rotating token
2024-10-24T23:48:09+03:00 INF token TTL expired, rotating token
2024-10-25T01:27:59+03:00 INF token TTL expired, rotating token
2024-10-25T02:38:09+03:00 INF token TTL expired, rotating token
2024-10-25T04:01:55+03:00 INF token TTL expired, rotating token
2024-10-25T05:18:02+03:00 INF token TTL expired, rotating token
2024-10-25T07:21:22+03:00 INF network error error="POST /api/fleet/orbit/config: Post \"<https://fleet-test.com/api/fleet/orbit/config\|https://fleet-test.com/api/fleet/orbit/config\>": read tcp 192.168.1.10:57324->x.x.x.x:443: read: operation timed out"
2024-10-25T07:41:49+03:00 INF token TTL expired, rotating token
2024-10-25T08:42:52+03:00 INF token TTL expired, rotating token
2024-10-25T09:42:52+03:00 INF token TTL expired, rotating token
2024-10-25T10:10:12+03:00 INF periodic check of token failed, initiating rotation error="HEAD /api/latest/fleet/device/2404791b-23b7-4543-8e99-72401f90ec6f/ping: Head \"<https://fleet-test.com/api/latest/fleet/device/2404791b-23b7-4543-8e99-72401f90ec6f/ping\|https://fleet-test.com/api/latest/fleet/device/2404791b-23b7-4543-8e99-72401f90ec6f/ping\>": net/http: TLS handshake timeout"
2024-10-25T12:58:04+03:00 INF network error error="POST /api/fleet/orbit/config: Post \"<https://fleet-test.com/api/fleet/orbit/config\|https://fleet-test.com/api/fleet/orbit/config\>": read tcp 192.168.1.10:57781->x.x.x.x:443: read: operation timed out"
2024-10-25T13:59:30+03:00 INF token TTL expired, rotating token
2024-10-25T14:59:30+03:00 INF token TTL expired, rotating token
2024-10-25T15:59:30+03:00 INF token TTL expired, rotating token
2024-10-25T17:03:01+03:00 INF token TTL expired, rotating token
2024-10-25T18:40:31+03:00 INF token TTL expired, rotating token
Secf
10/25/2024, 4:05 PMTim Lee
10/25/2024, 5:20 PMnc -z <http://fleet-test.com|fleet-test.com> 443
work from the macOS host?Secf
10/25/2024, 5:36 PMRebecca Cowart
10/25/2024, 5:39 PMSecf
10/25/2024, 5:43 PMSecf
10/25/2024, 5:44 PMTim Lee
10/25/2024, 5:49 PMorbit
and fleet-desktop
are both unable to connect to the server. Possibly more info in the server logs. the orbit service only exists on devices, the server service i believe is named fleet
Tim Lee
10/25/2024, 5:49 PMSecf
10/25/2024, 5:50 PMSecf
10/25/2024, 5:51 PMmysql:
address: localhost:3306
database: fleet
username: fleet
password:
max_open_conns: 1000
mysql_max_idle_conns: 1000
redis:
address: 127.0.0.1:6379
redis_username:
redis_password:
server:
address: 127.0.0.1:8080
# this is certbot certs
# not automated copy them from certbot
# need to do it by hands
cert: /etc/fleet/certs/server.crt
key: /etc/fleet/certs/server.key
private_key:
websockets_allow_unsafe_origin: true
logging:
json: true
osquery:
label_query_update_interval: 12h
detail_update_interval: 15m
host_identifier: instance
filesystem:
status_log_file: /var/log/osquery/status.log
result_log_file: /var/log/osquery/result.log
enable_log_rotation: true
license:
key:
mdm:
windows_wstep_identity_cert: /etc/fleet/certs/fleet-mdm-win-wstep.crt
windows_wstep_identity_key: /etc/fleet/certs/fleet-mdm-win-wstep.key
Tim Lee
10/25/2024, 5:55 PMsudo journalctl -u fleet.service -f
or possibly cloudwatch if deployed on EC2Secf
10/25/2024, 6:01 PMOct 25 17:56:04 fleet[1599]: {"cron":"integrations","level":"info","msg":"no cooldowns to process","ts":"2024-10-25T17:56:04.44230538Z"}
Oct 25 17:56:04 fleet[1599]: {"cron":"integrations","instanceID":"YKRrdQQBOmCPHG2cFypm382a83FsQjAd6YbC8uJiH9UxkDXTjD9jSFHKa4RCEgu7vNBvZbDzTgrRAf4kOxSt/A==","level":"info","schedule":"integrations","status":"completed","ts":"2024-10-25T17:56:04.446250684Z"}
Oct 25 17:56:04 fleet[1599]: {"cron":"apple_mdm_apns_pusher","instanceID":"YKRrdQQBOmCPHG2cFypm382a83FsQjAd6YbC8uJiH9UxkDXTjD9jSFHKa4RCEgu7vNBvZbDzTgrRAf4kOxSt/A==","level":"info","schedule":"apple_mdm_apns_pusher","status":"pending","ts":"2024-10-25T17:56:04.472148254Z"}
Oct 25 17:56:04 fleet[1599]: {"cron":"apple_mdm_apns_pusher","instanceID":"YKRrdQQBOmCPHG2cFypm382a83FsQjAd6YbC8uJiH9UxkDXTjD9jSFHKa4RCEgu7vNBvZbDzTgrRAf4kOxSt/A==","level":"info","schedule":"apple_mdm_apns_pusher","status":"completed","ts":"2024-10-25T17:56:04.476894292Z"}
Oct 25 17:56:04 fleet[1599]: {"component":"nanodep-syncer","cron":"apple_mdm_dep_profile_assigner","instanceID":"YKRrdQQBOmCPHG2cFypm382a83FsQjAd6YbC8uJiH9UxkDXTjD9jSFHKa4RCEgu7vNBvZbDzTgrRAf4kOxSt/A==","level":"info","schedule":"apple_mdm_dep_profile_assigner","status":"pending","ts":"2024-10-25T17:56:04.533700345Z"}
Oct 25 17:56:04 fleet[1599]: {"component":"nanodep-syncer","cron":"apple_mdm_dep_profile_assigner","instanceID":"YKRrdQQBOmCPHG2cFypm382a83FsQjAd6YbC8uJiH9UxkDXTjD9jSFHKa4RCEgu7vNBvZbDzTgrRAf4kOxSt/A==","level":"info","schedule":"apple_mdm_dep_profile_assigner","status":"completed","ts":"2024-10-25T17:56:04.537580555Z"}
Oct 25 17:56:13 fleet[1599]: {"cron":"mdm_apple_profile_manager","instanceID":"YKRrdQQBOmCPHG2cFypm382a83FsQjAd6YbC8uJiH9UxkDXTjD9jSFHKa4RCEgu7vNBvZbDzTgrRAf4kOxSt/A==","level":"info","schedule":"mdm_apple_profile_manager","status":"pending","ts":"2024-10-25T17:56:13.539888484Z"}
Oct 25 17:56:13 fleet[1599]: {"cron":"mdm_apple_profile_manager","instanceID":"YKRrdQQBOmCPHG2cFypm382a83FsQjAd6YbC8uJiH9UxkDXTjD9jSFHKa4RCEgu7vNBvZbDzTgrRAf4kOxSt/A==","level":"info","schedule":"mdm_apple_profile_manager","status":"completed","ts":"2024-10-25T17:56:13.546960204Z"}
Oct 25 17:56:23 fleet[1599]: {"component":"iphone-ipad-refetcher","cron":"apple_mdm_iphone_ipad_refetcher","instanceID":"YKRrdQQBOmCPHG2cFypm382a83FsQjAd6YbC8uJiH9UxkDXTjD9jSFHKa4RCEgu7vNBvZbDzTgrRAf4kOxSt/A==","level":"info","schedule":"apple_mdm_iphone_ipad_refetcher","status":"pending","ts":"2024-10-25T17:56:23.46988026Z"}
Oct 25 17:56:23 fleet[1599]: {"component":"iphone-ipad-refetcher","cron":"apple_mdm_iphone_ipad_refetcher","instanceID":"YKRrdQQBOmCPHG2cFypm382a83FsQjAd6YbC8uJiH9UxkDXTjD9jSFHKa4RCEgu7vNBvZbDzTgrRAf4kOxSt/A==","level":"info","schedule":"apple_mdm_iphone_ipad_refetcher","status":"completed","ts":"2024-10-25T17:56:23.476075717Z"}
Oct 25 17:56:33 fleet[1599]: {"cron":"calendar","instanceID":"YKRrdQQBOmCPHG2cFypm382a83FsQjAd6YbC8uJiH9UxkDXTjD9jSFHKa4RCEgu7vNBvZbDzTgrRAf4kOxSt/A==","level":"info","schedule":"calendar","status":"pending","ts":"2024-10-25T17:56:33.924923873Z"}
Oct 25 17:56:33 fleet[1599]: {"cron":"calendar","instanceID":"YKRrdQQBOmCPHG2cFypm382a83FsQjAd6YbC8uJiH9UxkDXTjD9jSFHKa4RCEgu7vNBvZbDzTgrRAf4kOxSt/A==","level":"info","schedule":"calendar","status":"completed","ts":"2024-10-25T17:56:33.932109788Z"}
Oct 25 17:56:43 fleet[1599]: {"cron":"mdm_apple_profile_manager","instanceID":"YKRrdQQBOmCPHG2cFypm382a83FsQjAd6YbC8uJiH9UxkDXTjD9jSFHKa4RCEgu7vNBvZbDzTgrRAf4kOxSt/A==","level":"info","schedule":"mdm_apple_profile_manager","status":"pending","ts":"2024-10-25T17:56:43.559908038Z"}
Oct 25 17:56:43 fleet[1599]: {"cron":"mdm_apple_profile_manager","instanceID":"YKRrdQQBOmCPHG2cFypm382a83FsQjAd6YbC8uJiH9UxkDXTjD9jSFHKa4RCEgu7vNBvZbDzTgrRAf4kOxSt/A==","level":"info","schedule":"mdm_apple_profile_manager","status":"completed","ts":"2024-10-25T17:56:43.569016791Z"}
Oct 25 17:57:04 fleet[1599]:
{"cron":"integrations","instanceID":"YKRrdQQBOmCPHG2cFypm382a83FsQjAd6YbC8uJiH9UxkDXTjD9jSFHKa4RCEgu7vNBvZbDzTgrRAf4kOxSt/A==","level":"info","schedule":"integrations","status":"pending","ts":"2024-10-25T17:57:04.454662097Z"}
Oct 25 17:57:04 fleet[1599]: {"cron":"integrations","level":"info","msg":"no cooldowns to process","ts":"2024-10-25T17:57:04.456109445Z"}
Tim Lee
10/25/2024, 6:03 PMSecf
10/25/2024, 6:27 PMSecf
10/25/2024, 6:28 PMTim Lee
10/25/2024, 6:45 PM<http://fleet-test.com|fleet-test.com>
is not a publicly accessible domainSecf
10/25/2024, 6:49 PMTim Lee
10/25/2024, 8:29 PMSecf
10/28/2024, 6:46 AM#!/bin/zsh
echo "test" > ~/test.txt
Secf
10/28/2024, 6:47 AMSecf
10/29/2024, 7:35 AMSecf
10/30/2024, 5:53 PMTim Lee
10/30/2024, 6:09 PM/etc/hosts
could be a workaround. Orbit is responsible for script execution, so no surprise on the errors if it cannot connect to Fleet.Secf
11/01/2024, 8:02 AM