Title
#fleet
w

wennan.he

09/22/2022, 11:40 PM
hi fleet team, our fleet has a /var/log/fleet/result.log file storing lots of logging long time ago, could anyone help to explain what is it about?
Rachel Perkins

Rachel Perkins

09/23/2022, 3:31 PM
Could you give us an example or screenshot to help us understand what you're experiencing?
Benjamin Edwards

Benjamin Edwards

09/23/2022, 5:31 PM
Hey, I think this might just be the default logging destination for osquery results (scheduled queries in Fleet). So this would be expected. https://fleetdm.com/docs/deploying/configuration#filesystem More on osquery logs here: https://fleetdm.com/docs/using-fleet/osquery-logs
w

wennan.he

09/23/2022, 5:37 PM
yes sure, we have some issue before and we found this file storing logging 2 weeks ago like:
5:37 PM
{"name":"ksoftirqd/71","path":"","pid":"366"},{"name":"kworker/94:2-rcu_gp","path":"","pid":"366483"},{"name":"kworker/70:0-events","path":"","pid":"3674345"},{"name":"kworker/95:0-cgroup_destroy","path":"","pid":"3674844"},{"name":"kworker/71:0H-kblockd","path":"","pid":"368"},{"name":"cpuhp/72","path":"","pid":"369"},{"name":"migration/72","path":"","pid":"370"},{"name":"ksoftirqd/72","path":"","pid":"371"},{"name":"kworker/35:2-mm_percpu_wq","path":"","pid":"3719825"},{"name":"kworker/86:2-cgroup_destroy","path":"","pid":"3721198"},{"name":"sh","path":"/usr/bin/dash","pid":"372875"},{"name":"timeout","path":"/usr/bin/timeout","pid":"372876"},{"name":"top","path":"/usr/bin/top","pid":"372877"},{"name":"kworker/20:1-mm_percpu_wq","path":"","pid":"3729918"},{"name":"kworker/72:0H-kblockd","path":"","pid":"373"},{"name":"kworker/47:2","path":"","pid":"3737829"},{"name":"cpuhp/73","path":"","pid":"374"},{"name":"kworker/78:0-cgroup_destroy","path":"","pid":"3746549"},{"name":"migration/73","path":"","pid":"375"},{"name":"ksoftirqd/73","path":"","pid":"376"},{"name":"kworker/73:0H-kblockd","path":"","pid":"378"},{"name":"kworker/88:2-mm_percpu_wq","path":"","pid":"3788051"},{"name":"cpuhp/74","path":"","pid":"379"},{"name":"sh","path":"/usr/bin/dash","pid":"3793518"},{"name":"timeout","path":"/usr/bin/timeout","pid":"3793519"},{"name":"top","path":"/usr/bin/top","pid":"3793521"},{"name":"sh","path":"/usr/bin/dash","pid":"3798270"},{"name":"timeout","path":"/usr/bin/timeout","pid":"3798272"},{"name":"top","path":"/usr/bin/top","pid":"3798275"},{"name":"kworker/5:0H-kblockd","path":"","pid":"38"},{"name":"migration/74","path":"","pid":"380"},{"name":"kworker/31:0-cgroup_destroy","path":"","pid":"3801152"},{"name":"sh","path":"/usr/bin/dash","pid":"380431"},{"name":"timeout","path":"/usr/bin/timeout","pid":"380433"},{"name":"top","path":"/usr/bin/top","pid":"380435"},{"name":"ksoftirqd/74","path":"","pid":"381"},{"name":"kworker/74:0H-kblockd","path":"","pid":"383"},{"name":"kworker/27:1-mm_percpu_wq","path":"","pid":"3839111"},{"name":"cpuhp/75","path":"","pid":"384"},{"name":"sh","path":"/usr/bin/dash","pid":"3840840"},{"name":"timeout","path":"/usr/bin/timeout","pid":"3840842"},{"name":"top","path":"/usr/bin/top","pid":"3840844"},{"name":"kworker/35:1H-kblockd","path":"","pid":"3842"},{"name":"kworker/39:1H-kblockd","path":"","pid":"3843"},{"name":"kworker/60:0-events","path":"","pid":"3847709"},{"name":"migration/75","path":"","pid":"385"},{"name":"kworker/55:2-events","path":"","pid":"3855558"},{"name":"ksoftirqd/75","path":"","pid":"386"},{"name":"kworker/74:0-cgroup_destroy","path":"","pid":"3866703"},{"name":"kworker/85:1-events","path":"","pid":"3878029"},{"name":"kworker/75:0H-kblockd","path":"","pid":"388"},{"name":"sh","path":"/usr/bin/dash","pid":"3883776"},{"name":"timeout","path":"/usr/bin/timeout","pid":"3883780"},{"name":"top","path":"/usr/bin/top","pid":"3883781"},{"name":"sh","path":"/usr/bin/dash","pid":"3884497"},{"name":"timeout","path":"/usr/bin/timeout","pid":"3884499"},{"name":"top","path":"/usr/bin/top","pid":"3884500"},{"name":"cpuhp/76","path":"","pid":"389"},{"name":"cpuhp/6","path":"","pid":"39"},{"name":"migration/76","path":"","pid":"390"},{"name":"ksoftirqd/76","path":"","pid":"391"},{"name":"kworker/35:0","path":"","pid":"3911613"},{"name":"kworker/25:1-events","path":"","pid":"3916849"},{"name":"kworker/17:0-events","path":"","pid":"3918665"},{"name":"sh","path":"/usr/bin/dash","pid":"3926313"},{"name":"timeout","path":"/usr/bin/timeout","pid":"3926318"},{"name":"top","path":"/usr/bin/top","pid":"3926319"},{"name":"kworker/76:0H-kblockd","path":"","pid":"393"},{"name":"sh","path":"/usr/bin/dash","pid":"3931843"},{"name":"timeout","path":"/usr/bin/timeout","pid":"3931845"},{"name":"top","path":"/usr/bin/top","pid":"3931846"},{"name":"cpuhp/77","path":"","pid":"394"},{"name":"kworker/19:2-cgroup_destroy","path":"","pid":"3949589"},{"name":"migration/77","path":"","pid":"395"},{"name":"kworker/51:2-events","path":"","pid":"3955484"},{"name":"ksoftirqd/77","path":"","pid":"396"},{"name":"sh","path":"/usr/bin/dash","pid":"3968910"},{"name":"timeout","path":"/usr/bin/timeout","pid":"3968915"},{"name":"top","path":"/usr/bin/top","pid":"3968916"},{"name":"kworker/77:0H-kblockd","path":"","pid":"398"},{"name":"cpuhp/78","path":"","pid":"399"},{"name":"sh","path":"/usr/bin/dash","pid":"399604"},{"name":"timeout","path":"/usr/bin/timeout","pid":"399606"},{"name":"top","path":"/usr/bin/top","pid":"399607"},{"name":"rcu_par_gp","path":"","pid":"4"},{"name":"migration/6","path":"","pid":"40"},{"name":"migration/78","path":"","pid":"400"},{"name":"ksoftirqd/78","path":"","pid":"401"},{"name":"sh","path":"/usr/bin/dash","pid":"4011588"},{"name":"timeout","path":"/usr/bin/timeout","pid":"4011589"},{"name":"top","path":"/usr/bin/top","pid":"4011591"},{"name":"kworker/34:0-events","path":"","pid":"4022473"},{"name":"kworker/u192:2-events_unbound","path":"","pid":"4026290"},{"name":"kworker/78:0H-kblockd","path":"","pid":"403"},{"name":"cpuhp/79","path":"","pid":"404"},{"name":"migration/79","path":"","pid":"405"},{"name":"sh","path":"/usr/bin/dash","pid":"4054443"},{"name":"timeout","path":"/usr/bin/timeout","pid":"4054445"},{"name":"top","path":"/usr/bin/top","pid":"4054448"},{"name":"sh","path":"/usr/bin/dash","pid":"4054503"},{"name":"timeout","path":"/usr/bin/timeout","pid":"4054507"},{"name":"top","path":"/usr/bin/top","pid":"4054508"},{"name":"ksoftirqd/79","path":"","pid":"406"},{"name":"kworker/79:0H-kblockd","path":"","pid":"408"},{"name":"sh","path":"/usr/bin/dash","pid":"4081526"},{"name":"timeout","path":"/usr/bin/timeout","pid":"4081528"},{"name":"top","path":"/usr/bin/top","pid":"4081529"},{"name":"cpuhp/80","path":"","pid":"409"},{"name":"sh","path":"/usr/bin/dash","pid":"4097256"},{"name":"timeout","path":"/usr/bin/timeout","pid":"4097260"},{"name":"top","path":"/usr/bin/top","pid":"4097262"},{"name":"ksoftirqd/6","path":"","pid":"41"},{"name":"migration/80","path":"","pid":"410"},{"name":"kworker/61:1-events","path":"","pid":"4103587"},{"name":"ksoftirqd/80","path":"","pid":"411"},{"name":"kworker/17:1","path":"","pid":"411633"},{"name":"kworker/80:0H-kblockd","path":"","pid":"413"},{"name":"sh","path":"/usr/bin/dash","pid":"4135290"},{"name":"timeout","path":"/usr/bin/timeout","pid":"4135292"},{"name":"top","path":"/usr/bin/top","pid":"4135293"},{"name":"sshd","path":"/usr/sbin/sshd","pid":"4137692"},{"name":"sh","path":"/usr/bin/dash","pid":"4139838"},{"name":"timeout","path":"/usr/bin/timeout","pid":"4139842"},{"name":"top","path":"/usr/bin/top","pid":"4139843"},{"name":"cpuhp/81","path":"","pid":"414"},{"name":"kworker/82:2-cgroup_destroy","path":"","pid":"4141932"},{"name":"migration/81","path":"","pid":"415"},{"name":"sh","path":"/usr/bin/dash","pid":"4152890"},{"name":"timeout","path":"/usr/bin/timeout","pid":"4152894"},{"name":"top","path":"/usr/bin/top","pid":"4152895"},{"name":"sh","path":"/usr/bin/dash","pid":"415448"},{"name":"timeout","path":"/usr/bin/timeout","pid":"415450"},{"name":"top","path":"/usr/bin/top","pid":"415453"},{"name":"atopacctd","path":"/usr/sbin/atopacctd","pid":"4159918"},{"name":"kworker/22:2-cgroup_destroy","path":"","pid":"4159944"},{"name":"ksoftirqd/81","path":"","pid":"416"},{"name":"kworker/81:0H-kblockd","path":"","pid":"418"},{"name":"sh","path":"/usr/bin/dash","pid":"4182497"},{"name":"timeout","path":"/usr/bin/timeout","pid":"4182501"},{"name":"top","path":"/usr/bin/top","pid":"4182502"},{"name":"cpuhp/82","path":"","pid":"419"},{"name":"migration/82","path":"","pid":"420"},{"name":"ksoftirqd/82","path":"","pid":"421"},{"name":"kworker/82:0H-kblockd","path":"","pid":"423"},{"name":"cpuhp/83","path":"","pid":"424"},{"name":"migration/83","path":"","pid":"425"},{"name":"ksoftirqd/83","path":"","pid":"426"},{"name":"kworker/83:0H-kblockd","path":"","pid":"428"},{"name":"cpuhp/84","path":"","pid":"429"},{"name":"kworker/6:0H-kblockd","path":"","pid":"43"},{"name":"migration/84","path":"","pid":"430"},{"name":"ksoftirqd/84","path":"","pid":"431"},{"name":"kworker/26:1H-kblockd","path":"","pid":"4317"},{"name":"kworker/27:1H-kblockd","path":"","pid":"4318"},{"name":"kworker/28:1H-kblockd","path":"","pid":"4319"},{"name":"kworker/29:1H-kblockd","path":"","pid":"4320"},{"name":"kworker/30:1H-kblockd","path":"","pid":"4321"},{"name":"kworker/31:1H-kblockd","path":"","pid":"4322"},{"name":"kworker/32:1H-kblockd","path":"","pid":"4323"},{"name":"kworker/33:1H-kblockd","path":"","pid":"4324"},{"name":"kworker/34:1H-kblockd","path":"","pid":"4325"},{"name":"kworker/37:1H-kblockd","path":"","pid":"4326"},{"name":"kworker/84:0H-kblockd","path":"","pid":"433"},{"name":"cpuhp/85","path":"","pid":"434"},{"name":"migration/85","path":"","pid":"435"},{"name":"ksoftirqd/85","path":"","pid":"436"},{"name":"kworker/85:0H-kblockd","path":"","pid":"438"},{"name":"cpuhp/86","path":"","pid":"439"},{"name":"cpuhp/7","path":"","pid":"44"},{"name":"migration/86","path":"","pid":"440"},{"name":"ksoftirqd/86","path":"","pid":"441"},{"name":"kworker/86:0H-kblockd","path":"","pid":"443"},{"name":"cpuhp/87","path":"","pid":"444"},{"name":"real_run","path":"/usr/bin/bash","pid":"4443"},{"name":"consul","path":"/data00/tiger/consul_deploy/sbin/consul","pid":"4446"},{"name":"migration/87","path":"","pid":"445"},{"name":"ksoftirqd/87","path":"","pid":"446"},{"name":"kworker/87:0H-kblockd","path":"","pid":"448"},{"name":"cpuhp/88","path":"","pid":"449"},{"name":"migration/7","path":"","pid":"45"},{"name":"migration/88","path":"","pid":"450"},{"name":"ksoftirqd/88","path":"","pid":"451"},{"name":"kworker/12:1H-kblockd","path":"","pid":"4528"},{"name":"kworker/88:0H-kblockd","path":"","pid":"453"},{"name":"cpuhp/89","path":"","pid":"454"},{"name":"migration/89","path":"","pid":"455"},{"name":"ksoftirqd/89","path":"","pid":"456"},{"name":"kworker/61:2-mm_percpu_wq","path":"","pid":"457654"},{"name":"kworker/89:0H-kblockd","path":"","pid":"458"},{"name":"sh","path":"/usr/bin/dash","pid":"458298"},{"name":"timeout","path":"/usr/bin/timeout","pid":"458299"},{"name":"top","path":"/usr/bin/top","pid":"458300"},{"name":"cpuhp/90","path":"","pid":"459"},{"name":"kworker/13:1H-kblockd","path":"","pid":"4595"},{"name":"kworker/14:1H-kblockd","path":"","pid":"4596"},{"name":"kworker/15:1H-kblockd","path":"","pid":"4597"},{"name":"kworker/16:1H-kblockd","path":"","pid":"4598"},{"name":"ksoftirqd/7","path":"","pid":"46"},{"name":"migration/90","path":"","pid":"460"},{"name":"ksoftirqd/90","path":"","pid":"461"},{"name":"kworker/11:0-cgroup_destroy","path":"","pid":"462070"},{"name":"toutiao.infra.t","path":"/data00/tiger/ttlogagent_deploy/bin/toutiao.infra.ttlogagent","pid":"4625"},{"name":"kworker/90:0H-kblockd","path":"","pid":"463"},{"name":"cpuhp/91","path":"","pid":"464"},{"name":"migration/91","path":"","pid":"465"},{"name":"kworker/17:1H-kblockd","path":"","pid":"4652"},{"name":"kworker/19:1H-kblockd","path":"","pid":"4653"},{"name":"kworker/21:1H-kblockd","path":"","pid":"4654"},{"name":"kworker/23:1H-kblockd","path":"","pid":"4655"},{"name":"kworker/38:1H-kblockd","path":"","pid":"4656"},{"name":"kworker/40:1H-kblockd","path":"","pid":"4657"},{"name":"kworker/41:1H-kblockd","path":"","pid":"4658"},{"name":"kworker/42:1H-kblockd","path":"","pid":"4659"},{"name":"ksoftirqd/91","path":"","pid":"466"},{"name":"kworker/43:1H-kblockd","path":"","pid":"4660"},{"name":"kworker/45:1H-kblockd","path":"","pid":"4661"},{"name":"kworker/44:1H-kblockd","path":"","pid":"4662"},{"name":"kworker/46:1H-kblockd","path":"","pid":"4663"},{"name":"kworker/47:1H-kblockd","path":"","pid":"4664"},{"name":"kworker/91:0H-kblockd","path":"","pid":"468"},{"name":"kworker/28:2-events","path":"","pid":"468670"},
5:37 PM
":"89"},{"name":"ksoftirqd/0","path":"","pid":"9"},{"name":"migration/16","path":"","pid":"90"},{"name":"kworker/38:0","path":"","pid":"905103"},{"name":"ksoftirqd/16","path":"","pid":"91"},{"name":"kworker/16:0H-kblockd","path":"","pid":"93"},{"name":"cpuhp/17","path":"","pid":"94"},{"name":"migration/17","path":"","pid":"95"},{"name":"kworker/75:0-mm_percpu_wq","path":"","pid":"956889"},{"name":"healthd2","path":"/etc/sysop/healthd2/healthd2","pid":"9598"},{"name":"ksoftirqd/17","path":"","pid":"96"},{"name":"kworker/91:0-cgroup_destroy","path":"","pid":"964821"},{"name":"kworker/12:1","path":"","pid":"969705"},{"name":"kworker/17:0H-events_highpri","path":"","pid":"98"},{"name":"cpuhp/18","path":"","pid":"99"},{"name":"kworker/23:1-cgroup_destroy","path":"","pid":"992109"}],"action":"snapshot","name":"pack/Global/SELECT pid, name, path FROM processes LIMIT 1;","hostIdentifier":"ce8ace83-708e-489b-a56d-bb7bd868a120","calendarTime":"Mon Sep 12 16:49:58 2022 UTC","unixTime":1663001398,"epoch":0,"counter":0,"numerics":false,"decorations":{"host_uuid":"ce8ace83-708e-489b-a56d-bb7bd868a120","hostname":"n114-063-227.tiktokd.org"}}
5:38 PM
this is caused by a scheduled query we setup long time ago which is already stopped.
5:38 PM
but i dont understand why it is not rotated.
Benjamin Edwards

Benjamin Edwards

09/23/2022, 6:03 PM
w

wennan.he

09/23/2022, 6:32 PM
so you mean the that log file is not enabled for rotated by default?
Benjamin Edwards

Benjamin Edwards

09/23/2022, 6:32 PM
Correct it's not enabled by default
w

wennan.he

09/23/2022, 6:33 PM
so if it is not, and if fleet collects huge size of data for scheduled queries, that might cause disaster, right?
6:34 PM
IO will crash the disk