Title
#general
s

sonal k

10/08/2021, 4:35 AM
@Stefano Bonicatti I am a bit confused as in I am not using this log_result_events flag in my osquery.flags file...so why am I still getting this...
Stefano Bonicatti

Stefano Bonicatti

10/08/2021, 10:26 AM
In the screenshot showing your .conf file, you have the
"options"
element; in there I can see
"log_result_events":"true"
10:28 AM
Some flags are CLI only and should be set only via CLI when launching osquery, or via flagfile, but other flags/configurations can be set via the .conf file. There’s still a bug where we don’t properly enforce that, but the idea is that CLI only flags can be set at startup only, while configuration options can be changed and applied at runtime.
10:29 AM
Again the
osqueryd --help
separates those two categories.
s

sonal k

10/08/2021, 11:43 AM
okay I understood.👍 also when I run "osqueryd --help" I get no such command message...why is so..?
Stefano Bonicatti

Stefano Bonicatti

10/08/2021, 11:50 AM
Probably osqueryd is not in your
PATH
env var (I guess it's osquery 5.0.1). You can also use
osqueryi --help
since that should be reachable, or simply provide the full path to the binary.
s

sonal k

10/08/2021, 12:56 PM
yes its osquery 5.0.1. and osqueryi --helps work