Mike S.
03/10/2025, 8:46 PMRebecca Cowart
03/11/2025, 3:53 PMSELECT * FROM osquery_flags;
and show us the results?
Can you also send us the fleetd logs?Mike S.
03/11/2025, 7:31 PMRebecca Cowart
03/17/2025, 6:23 PMRebecca Cowart
03/17/2025, 6:24 PMMike S.
03/17/2025, 6:29 PMRebecca Cowart
03/17/2025, 6:30 PMMike S.
03/17/2025, 6:31 PMRebecca Cowart
03/17/2025, 6:35 PMMike S.
03/17/2025, 6:36 PMRebecca Cowart
03/17/2025, 7:06 PMRebecca Cowart
03/17/2025, 7:09 PMMike S.
03/17/2025, 7:09 PMRebecca Cowart
03/17/2025, 7:12 PMRebecca Cowart
03/17/2025, 7:13 PMMike S.
03/17/2025, 7:14 PMMike S.
03/17/2025, 7:16 PMMike S.
03/17/2025, 7:17 PMMike S.
03/17/2025, 7:19 PMRebecca Cowart
03/17/2025, 8:39 PMMike S.
03/17/2025, 8:45 PMRebecca Cowart
03/17/2025, 8:47 PMMike S.
03/17/2025, 8:50 PMRebecca Cowart
03/17/2025, 8:55 PMBenjamin Edwards
03/17/2025, 8:59 PMserve --config config.yml
(sub name of your config file) it should work fine.
Make sure you aren't confusing the fleet server yaml configuration with agent configuration. The firehose settings are only relevant for the server configuration.
If you are still seeing filesystem as the backend (its the default value) then your configuration isn't being supplied correctly or the server needs to be restarted to pick up the new changes.Mike S.
03/17/2025, 9:01 PMBenjamin Edwards
03/17/2025, 9:08 PMserver:
tls: false
logging:
debug: true
osquery:
result_log_plugin: firehose
firehose:
region: ca-central-1
result_stream: osquery_result
(omitted some of the other keys for brevity)Mike S.
03/17/2025, 9:12 PMBenjamin Edwards
03/17/2025, 9:13 PMBenjamin Edwards
03/17/2025, 9:13 PMRebecca Cowart
03/18/2025, 12:56 PMMike S.
03/18/2025, 3:24 PM