David Payne
01/03/2020, 5:17 PMAndrea
01/03/2020, 5:41 PMfilesystem I usually specify --logger_path flag with the location where to put those logs (on your screenshot that flag is missing btw). I have noticed though that on Windows I never find the logs where specified, but I find them on C:\Windows\Temp (or some sub-directory) , or in C:\Users\username\AppData\Local\Temp\ depending on how I run osquery (debug/release mode). Never had the chance to investigate better though (maybe I am missing something)David Payne
01/03/2020, 7:24 PMzwass
--config_tls_endpoint set and that means some values in your flagfile could be overridden by the config returned by Fleet.David Payne
01/06/2020, 3:05 PMzwass
fleetctl CLI to get and modify configuration: https://github.com/kolide/fleet/tree/master/docs/cli