https://github.com/osquery/osquery logo
p

packetzero

11/06/2019, 12:57 AM
its the default
n

nyanshak

11/06/2019, 1:19 AM
https://osquery.slack.com/archives/C1XCLA5DZ/p1573002989209400 - posted question to #kolide since it's probably more relevant, but maybe you know the answer anyways. thanks for the help either way 🙂
p

packetzero

11/06/2019, 1:41 AM
I don't know kolide. Look at the logger_plugin and logger_min_status settings. Sometimes there are two loggers such as
logger_plugin=aws_kinesis,filesystem
if logger_min_status=1, only WARN and ERROR logs go to first logger.