Phuc Duong
04/14/2020, 4:19 AMC:\Program Files\osquery\osqueryd>osqueryd.exe --config_plugin=tls --config_tls_endpoint=/api/v1/osquery/config --config_tls_max_attempts=10 --config_tls_refresh=10 --enroll_tls_endpoint=/api/v1/osquery/enroll --enroll_always=true --watchdog_memory_limit=350 --enroll_secret_path="C:\Program Files\osquery\secret" --tls_hostname=<http://fleet-demo.com:8080|fleet-demo.com:8080> --tls_server_certs "C:\Program Files\osquery\certs\<http://fleet-demo.com|fleet-demo.com>_8080.pem" --disable_distributed=false --distributed_plugin=tls --distributed_interval=10 --distributed_tls_max_attempts=3 --distributed_tls_read_endpoint=/api/v1/osquery/distributed/read --distributed_tls_write_endpoint=/api/v1/osquery/distributed/write --logger_plugin=tls --logger_tls_endpoint=/api/v1/osquery/log --logger_tls_period=10 --host_identifier=hexcode
But when I copy these to the osquery.flags file to run the osquery as a service, it returns the error "Windows could not start the osqueryd service on Local Computer" after I start the osqueryd service.
Below is my osquery.flags configuration. Could someone help me on this? thanks so much
--config_plugin=tls
--config_tls_endpoint=/api/v1/osquery/config
--config_tls_max_attempts=10
--config_tls_refresh=10
--enroll_tls_endpoint=/api/v1/osquery/enroll
--enroll_always=true
--watchdog_memory_limit=350
--enroll_secret_path="C:\Program Files\osquery\secret"
--tls_hostname=<http://fleet-demo.com:8080|fleet-demo.com:8080>
--tls_server_certs "C:\Program Files\osquery\certs\<http://fleet-demo.com|fleet-demo.com>_8080.pem"
--disable_distributed=false
--distributed_plugin=tls
--distributed_interval=10
--distributed_tls_max_attempts=3
--distributed_tls_read_endpoint=/api/v1/osquery/distributed/read
--distributed_tls_write_endpoint=/api/v1/osquery/distributed/write
--logger_plugin=tls
--logger_tls_endpoint=/api/v1/osquery/log
--logger_tls_period=10
--host_identifier=hexcode
DG
04/14/2020, 5:51 PM