I have some endpoints (they all appear to be Windo...
# fleet
p
I have some endpoints (they all appear to be Windows 11) where I'm only getting ProcessStop events and not ProcessStart events from the process_etw_events table. Does anyone have any suggestions for troubleshooting?
k
Hi @Paul_B! What version of osquery/fleetd are you running? Are you seeing any errors in the osquery status logs?
p
Hi @Kathy Satterlee thanks: fleet 4.64.1 osquery 5.17.0 orbit: 1.41.0 The only osqueryd.warnings that I'm seeing are like this: services.cpp:124] <redacted HEX>: failed to query service description
@Kathy Satterlee, after enabling verbose logging for orbit on a test machine we are now seeing these errors: W0521 183532.505264 8628 etw_user_session.cpp:201] ControlTrace() failed with error code 234 W0521 183532.524417 8628 etw_kernel_session.cpp:223] ControlTrace() failed with error code 234 W0521 183538.141846 8628
I've done some more testing and with the exact same orbit binary, we get process start and stop on Win 11 23H2. But on Win 11 24H2 we only get Process Stops.
I should have said they are fresh vanilla installs of each OS.
Have heard etw in 24H2 has caused some problems with other EDRs too.. is this a known issue?
Anyone else seeing this?
d
Hi im seeing this too, and dont know how to troubleshoot
u
hey @Duongtt - Looks like we fell off this thread a few months ago! Apologies for that. Can you let us know what Fleet server version you're running? And what version of fleetd/osquery you're running? Do you have fleetd or orbit/osquery logs that you can share (via email or DM) from a host where you're seeing this behavior?
p
Hi @Zay Hanlon, sure. Server: • Fleet 4.64.1 • Go go1.23.4 Agent: • Osquery: 5.18.1 • Agent: 1.46.0 And yes I could get some logs off a test host - just let me know what you'd like me to collect. And thank you for this šŸ™‚
m
Hi @Paul B! First off, if you could please update to the latest version of Fleet that would help us eliminate any possible edge cases. After that, if you could share the fleetd logs for a couple of the hosts that would be great.
šŸ‘ 1
u
HI @Paul B! I wanted to follow up on this. Were you able to grab any logs for us?
p
Hi @Kathy Satterlee, I'm just working on getting a change window approved for updating fleet. Once I've updated to the latest version I'll get some logs to you :)
šŸ™Œ 1