Join Slack
Channels
general
android_tests
apple-silicon
arm-architecture
auditing-warroom
awallaby
aws
beyond-identity
carving
code-review
community-feeds
core
darkbytes
doorman
ebpf
eclecticiq-polylogyx-extension
extensions
file-carving
fim
fleet
fleet-dev
fleetosquery
foundation
fuzzing
golang
goquery
help-proxy
infrastructure
jobs
kolide
linen-dev
linux
loonsecio
macos
officehours
osctrl
plugins
process-auditing
qingteng
querycon
queryhub
random
selfgroup
sql
tls
uptycs
vendor-feeds
website
windows
zeek
zentral
zercurity
Powered by
its the default
# general
p
packetzero
11/06/2019, 12:57 AM
its the default
n
nyanshak
11/06/2019, 1:19 AM
https://osquery.slack.com/archives/C1XCLA5DZ/p1573002989209400
- posted question to
#C1XCLA5DZ
since it's probably more relevant, but maybe you know the answer anyways. thanks for the help either way 🙂
p
packetzero
11/06/2019, 1:41 AM
I don't know kolide. Look at the logger_plugin and logger_min_status settings. Sometimes there are two loggers such as
logger_plugin=aws_kinesis,filesystem
if logger_min_status=1, only WARN and ERROR logs go to first logger.
Open in Slack
Previous
Next