David Payne
01/03/2020, 5:17 PMAndrea
01/03/2020, 5:41 PMfilesystem
I usually specify --logger_path
flag with the location where to put those logs (on your screenshot that flag is missing btw). I have noticed though that on Windows I never find the logs where specified, but I find them on C:\Windows\Temp
(or some sub-directory) , or in C:\Users\username\AppData\Local\Temp\
depending on how I run osquery (debug/release mode). Never had the chance to investigate better though (maybe I am missing something)David Payne
01/03/2020, 7:24 PMzwass
01/03/2020, 10:18 PM--config_tls_endpoint
set and that means some values in your flagfile could be overridden by the config returned by Fleet.David Payne
01/06/2020, 3:05 PMzwass
01/08/2020, 6:55 PMfleetctl
CLI to get and modify configuration: https://github.com/kolide/fleet/tree/master/docs/cli