I am new to osquery, I am trying to get my server Syslog from osquery using Syslog-ng. I tried by adding the below in Syslog-ng.conf file, however, am getting data till the syslog_pipe file. but not able to fetch it using osqueryi
Reformat log messages in a format that osquery accepts
source(s_src); filter(f_auth); destination(d_auth);
One more thing is;
Also, I have made changes in osquery.conf to enable FIM. When I tried Syslog-ng(client-master server), if disable FIM am getting data from the client machine for 'select * from Syslog;' in the master server machine. If enabled, no data for Syslog-ng(client-master server) or for the Syslog-ng(for my own server)
Could any one help me to figure this out.