hi fleet team, our fleet has a /var/log/fleet/resu...
# fleet
w
hi fleet team, our fleet has a /var/log/fleet/result.log file storing lots of logging long time ago, could anyone help to explain what is it about?
r
Could you give us an example or screenshot to help us understand what you're experiencing?
b
Hey, I think this might just be the default logging destination for osquery results (scheduled queries in Fleet). So this would be expected. https://fleetdm.com/docs/deploying/configuration#filesystem More on osquery logs here: https://fleetdm.com/docs/using-fleet/osquery-logs
w
yes sure, we have some issue before and we found this file storing logging 2 weeks ago like:
this is caused by a scheduled query we setup long time ago which is already stopped.
but i dont understand why it is not rotated.
b
w
so you mean the that log file is not enabled for rotated by default?
b
Correct it's not enabled by default
w
so if it is not, and if fleet collects huge size of data for scheduled queries, that might cause disaster, right?
IO will crash the disk