Title
#fleet
w

wennan.he

10/13/2022, 10:07 PM
any update
11:21 PM
i enabled the fim through fleet ui overrides: platforms: all: file_paths: etc: - /etc/osquery/% exclude_paths: tmp: - /tmp/too_many_events/ homes: - /home/not_to_monitor/.ssh/%% but it seems not working, and i cannot find any record in file_events after i create or delete any files under /etc/osquery
11:53 PM
@Kathy Satterlee could u help on this thread?
Kathy Satterlee

Kathy Satterlee

10/13/2022, 11:55 PM
I'll add an update as soon as I'm able, likely tomorrow morning (I'm in Texas).
12:13 AM
I wasn't able to find a way to check that from within Fleet other than to check whether the file events were showing up as expected, so I reached out to the team to verify. There isn't a way to check that from within Fleet since it isn't something that
osquery
stores in a table.
12:14 AM
You could run
osqueryd
with
--tls_dump
enabled to see the response that's coming from the Fleet server when config is checked.
w

wennan.he

10/14/2022, 12:24 AM
ok, but how could we debug this issue?
12:26 AM
@Kathy Satterlee could u advice?
Kathy Satterlee

Kathy Satterlee

10/14/2022, 4:45 PM
It looks like you're using
all
there for the platform. Overrides are applied to hosts based on the platform that comes back from
SELECT platform FROM os_version;
, so that override wouldn't apply to any hosts.
w

wennan.he

10/14/2022, 4:59 PM
sorry i dont get it, why it wouldn't apply for any hosts?
4:59 PM
or how can i let it works out?
Kathy Satterlee

Kathy Satterlee

10/14/2022, 5:28 PM
It won't apply to any hosts because
all
is not a platform. You'll need to provide the actual platform you want the
overrides
to apply to.
5:29 PM
For example,
darwin
for MacOS hosts or
ubuntu
for Ubuntu hosts. If you aren't sure about the platform, you can run the above query against your hosts to see what pops up!
w

wennan.he

10/14/2022, 6:11 PM
what about debian?
Kathy Satterlee

Kathy Satterlee

10/14/2022, 6:27 PM
Does that come back as
platform
if you query your hosts?
6:29 PM
It should be
ubuntu
for Ubuntu hosts for example.
w

wennan.he

10/14/2022, 9:42 PM
the screenshot of query result of SELECT platform FROM os_version; So can i say i need to define options and adding debian as new platform?
9:46 PM
@Kathy Satterlee
Kathy Satterlee

Kathy Satterlee

10/14/2022, 11:31 PM
Exactly!