Title
#general
teoseller

teoseller

04/03/2019, 9:41 AM
--logger_plugin=tls --logger_tls_endpoint=/api/v1/osquery/log --logger_tls_period=10 --database_path=/usr/share/osquery/DataBase2
packetzero

packetzero

04/03/2019, 11:08 AM
Osquery maintains a rocksdb database. That database_path is actually a directory. The database contains cached events and scheduled query results so differential results can be calculated . In the case of tls logger, which uses buffered_logger, all results get staged in the database before sending to server.
teoseller

teoseller

04/03/2019, 2:33 PM
thank you a lot !!!