Title
#general
w

wennan.he

10/12/2022, 9:17 PM
Hi osquery team, if /etc/osquery/osquery.conf is not offered, will osuqery read conf from config_tls_endpoint?
s

seph

10/12/2022, 9:25 PM
Depends on the flags. You’d need to configure that
w

wennan.he

10/12/2022, 9:31 PM
like this?

Configuration

--config_plugin=tls --config_tls_endpoint=/api/osquery/config --config_refresh=10
9:32 PM
is there any way to check the response of this api?
9:33 PM
@seph
s

seph

10/12/2022, 9:35 PM
Might be right. The docs have some examples of this
9:36 PM
As for responses… you can examine osquery settings for things that should have been set by the config. You can look at verbose logs. Pretty sure something is logged.
w

wennan.he

10/12/2022, 9:37 PM
for my case, i don't offer the config file. that is why i would like to check the response from this api.
9:38 PM
and could u tell me where is the verbose log file?
s

seph

10/12/2022, 9:38 PM
Osquery logs to stdout and stderr. Everything else depends on how you have it configured.
w

wennan.he

10/12/2022, 9:42 PM

Logging

--logger_plugin=tls --logger_tls_endpoint=/api/osquery/log --logger_tls_period=60
9:42 PM
this is our logging cfg
9:42 PM
and it means it returns the all the stdout and stderr to fleet?