also i am routing osquery logs to splunk already, but want to run it on fleet as well, should the path in the Global Agent Options'logger_tls_endpoint: /api/v1/osquery/log' be changed to what i have set for osquery config ..
08/04/2021, 2:10 PM
This sounds like a #fleet specific question?
08/04/2021, 2:16 PM
yes.. i am being routed many places with fleet over slack ... so i am here as well
08/04/2021, 2:18 PM
I’m sorry if you’re been bounced around a bunch.
osquery is an tool that runs on the endpoints. It can communicate to a server. Fleet is an OSS server that osquery can connect to.
These question appear to be about fleet configuration. Thus, #fleet