Title
#general
d

DG

04/01/2020, 4:47 PM
When I compiled OSquery from source, i noticed it kept the /tmp/osquery_status in windows - can I specify an alternate location in the FLAG file (I am only using tls plugin as far as i know) , and it also appears to be logging into osquery.db folder. When i get this sorted will osquery.db folder continue to grow? Currently im just debating "--disable_logger=true" to stop the cannot write errors flooding kolide
4:49 PM
Windows (on fleet server) says cannot write /tmp/osquery_status
4:52 PM
My goal is limit growth on clients - and later if i do packs to also run from kolide, and have it receive the results.
sundsta

sundsta

04/01/2020, 5:35 PM
The logging location is configurable both on the osquery end and the Fleet end. If you’re using the TLS logger to send the logs to Fleet, the osqueryd on the endpoint will not log to disk (outside of the cache)
d

DG

04/01/2020, 5:36 PM
it is though.. on the fleet side its logging an error, Do you mind i paste my flag file here?
sundsta

sundsta

04/01/2020, 5:36 PM
Sure
d

DG

04/01/2020, 5:38 PM
--enroll_secret_path=C:\ProgramData\osquery\osquery.key --tls_server_certs=C:\ProgramData\osquery\REMOVED_Reversed.cer --tls_hostname=REMOVED:8080 --host_identifier=uuid --enroll_tls_endpoint=/api/v1/osquery/enroll --config_plugin=tls --config_tls_endpoint=/api/v1/osquery/config --config_tls_refresh=10 --disable_distributed=false --config_tls_max_attempts=3 --distributed_plugin=tls --distributed_interval=10 --distributed_tls_max_attempts=3 --distributed_tls_read_endpoint=/api/v1/osquery/distributed/read --distributed_tls_write_endpoint=/api/v1/osquery/distributed/write --logger_plugin=tls --logger_tls_endpoint=/api/v1/osquery/log --logger_tls_period=10 --log_result_events=false --pack_delimiter=/ --utc
5:39 PM
I get ~7Gb a day from EVERY client (200) thats cannot write /tmp/osquery_status (from my windows hosts)
5:40 PM
I also get cannot lock osquery.db but it still writes to it
5:40 PM
The clients i believe are acting since i left items in the packs folder
5:41 PM
When in doubt, assume im wrong - if you havent heard me yet - I am very new to this software
sundsta

sundsta

04/01/2020, 5:43 PM
Looks fine, except
log_result_events
isn’t a valid flag.
5:44 PM
Turn on verbose logging and then you will see more details (and probably why this is happening) in daemon’s output
d

DG

04/01/2020, 5:45 PM
Oh its in the read doc under debugging
5:45 PM
it reduced the flow of incoming to kolide i was getting - so packs run but i dont get results
5:45 PM
I just get they ran and the query they ran
5:47 PM
Actually maybe it was a bad google on a previous release, removing, thank you
5:48 PM
Verbose is the original issue, when i originally deployed the flag file it had verbose
5:48 PM
now that i removed verbose I still am getting for each windows client cannot write /tmp/osquery_status
5:49 PM
at idle its burning 550mb/hour
5:49 PM
every event, triggers a status, cannot write status, tls logs cannot write to kolide
6:06 PM
Do you know the switch to over write the status file location?
sundsta

sundsta

04/01/2020, 7:13 PM
If its writing the status to file, something is wrong. With TLS logger enabled, it shouldn’t write that to file. Enable verbose logging and look at the logs when the daemon starts, it will describe it attempting to connect to the TLS logging endpoint and describe why it can’t
7:14 PM
d

DG

04/01/2020, 7:14 PM
True but i havent found one for result, maybe I mised it, but ill review again
7:15 PM
Thank you again
sundsta

sundsta

04/01/2020, 7:52 PM
The flag is
logger_path
, which is documented on the page
d

DG

04/01/2020, 11:09 PM
I tried that with C:\Program Files\osquery\log in the past and didnt work. However, let me try again - Thank you again
11:30 PM
You know I think you're right on that, and the error was i didn't encapsulate the string in "'s since there is a space in "program files"
11:32 PM
Thank you very much for helping solve that prblem : ) My last question if you're up for it - is basically how does osquery.db work on the clients, as in do i have to worry of it growing indefinitely or have to do any maintaince. My local test machine is up to about ~60mb for the month
5:34 AM
I think i understand now that its a cache for diffing against, and that you can set max results to save and expiration