Title
#windows
t

Ted Dorosheff

02/07/2022, 3:13 PM
Morning all, wondering if this is a known issue: when running with logger_plugin=filesystem, osqueryd run from admin command prompt encounters an issue when it is unable to create C:\program Files\osquery\log\osquery.results.log, and then shuts down. If i manually delete the files in the logs directory, and then re-run osqueryd, it is able to create the log files and keeps running. But the next time the agent is run it encounters the same issue and shuts down.
3:20 PM
update: nvm i just needed to change
logger_mode=420
to
logger_mode=640