Thomas Stromberg10/20/2022, 4:06 PM
tables are populated on half of our Linux machines running Kolide, but not the other. It sort of follows Linux distribution boundaries: • Ubuntu: Yes! • Fedora: No • Arch: Mixed • NixOS: Mixed. One machine has data in
, the other doesn't. Both seem to only record
bind calls in
One of the ones where none of the tables are populated is my personal machine, so I'm happy to investigate. Is it possible that the auditd rules installed by osquery could conflict with previously written configurations? I did check the output of
but it didn't seem to give any indications.
sudo journalctl -t launcher