Ibra
06/08/2022, 1:19 PMKeith Swagler
06/08/2022, 4:08 PMIbra
06/08/2022, 7:12 PMKeith Swagler
06/08/2022, 7:39 PMIbra
06/08/2022, 8:05 PMunzip fleet.zip 'linux/*' -d fleet
sudo cp fleet/linux/fleet* /usr/bin/
Keith Swagler
06/09/2022, 4:05 AMtar xvf fleet_v4.15.0.tar.gz
Ibra
06/09/2022, 12:22 PM/usr/bin/fleet serve \
--mysql_address=127.0.0.1:3306 \
--mysql_database=fleet \
--mysql_username=root \
--mysql_password=toor \
--redis_address=127.0.0.1:6379 \
--server_cert=/tmp/server.cert \
--server_key=/tmp/server.key \
--logging_json
Keith Swagler
06/09/2022, 12:57 PMIbra
06/09/2022, 2:45 PMKeith Swagler
06/09/2022, 3:22 PMIbra
06/09/2022, 3:26 PMKeith Swagler
06/09/2022, 3:34 PMIbra
06/09/2022, 3:44 PMKeith Swagler
06/09/2022, 3:47 PMIbra
06/09/2022, 8:39 PMsystemctl status orbit -l
● orbit.service - Orbit osquery
Loaded: loaded (/usr/lib/systemd/system/orbit.service; enabled; vendor preset: disabled)
Active: active (running) since Thu 2022-06-09 16:26:37 EDT; 3min 33s ago
Main PID: 8640 (orbit)
Tasks: 20 (limit: 11268)
Memory: 19.9M
CGroup: /system.slice/orbit.service
├─8640 /opt/orbit/bin/orbit/orbit
├─8645 /opt/orbit/bin/osqueryd/linux/stable/osqueryd --pidfile=/opt/orbit/osquery.pid --database_path=/opt/orbit/osquery.db --extensions_socket=/opt/orbit/orbit-osquery.em --logger_path=/opt/orbit/osquery_log --enroll_secret_>
└─8649 /opt/orbit/bin/osqueryd/linux/stable/osqueryd
giu 09 16:26:52 test-fleet-01.ibratech.local orbit[8640]: 2022-06-09T16:26:52-04:00 INF start osqueryd cmd="/opt/orbit/bin/osqueryd/linux/stable/osqueryd --pidfile=/opt/orbit/osquery.pid --database_path=/opt/orbit/osquery.db --extension>
giu 09 16:26:52 test-fleet-01.ibratech.local osqueryd[8645]: osqueryd started [version=5.2.2]
giu 09 16:26:57 test-fleet-01.ibratech.local orbit[8640]: W0609 16:26:57.937232 8649 tls_enroll.cpp:101] Failed enrollment request to <https://10.0.63.135/api/v1/osquery/enroll> (Request error: Failed to connect to 10.0.63.135:443: Connection refused>
giu 09 16:26:58 test-fleet-01.ibratech.local orbit[8640]: W0609 16:26:58.988256 8649 tls_enroll.cpp:101] Failed enrollment request to <https://10.0.63.135/api/v1/osquery/enroll> (Request error: Failed to connect to 10.0.63.135:443: Connection refused>
giu 09 16:27:03 test-fleet-01.ibratech.local orbit[8640]: W0609 16:27:03.044104 8649 tls_enroll.cpp:101] Failed enrollment request to <https://10.0.63.135/api/v1/osquery/enroll> (Request error: Failed to connect to 10.0.63.135:443: Connection refused>
giu 09 16:27:12 test-fleet-01.ibratech.local orbit[8640]: W0609 16:27:12.095988 8649 tls_enroll.cpp:101] Failed enrollment request to <https://10.0.63.135/api/v1/osquery/enroll> (Request error: Failed to connect to 10.0.63.135:443: Connection refused>
giu 09 16:27:28 test-fleet-01.ibratech.local orbit[8640]: W0609 16:27:28.154523 8649 tls_enroll.cpp:101] Failed enrollment request to <https://10.0.63.135/api/v1/osquery/enroll> (Request error: Failed to connect to 10.0.63.135:443: Connection refused>
giu 09 16:27:53 test-fleet-01.ibratech.local orbit[8640]: W0609 16:27:53.206271 8649 tls_enroll.cpp:101] Failed enrollment request to <https://10.0.63.135/api/v1/osquery/enroll> (Request error: Failed to connect to 10.0.63.135:443: Connection refused>
giu 09 16:28:29 test-fleet-01.ibratech.local orbit[8640]: W0609 16:28:29.254662 8649 tls_enroll.cpp:101] Failed enrollment request to <https://10.0.63.135/api/v1/osquery/enroll> (Request error: Failed to connect to 10.0.63.135:443: Connection refused>
giu 09 16:29:18 test-fleet-01.ibratech.local orbit[8640]: W0609 16:29:18.307225 8649 tls_enroll.cpp:101] Failed enrollment request to <https://10.0.63.135/api/v1/osquery/enroll> (Request error: Failed to connect to 10.0.63.135:443: Connection refused>
firewall-cmd --list-all
public (active)
target: default
icmp-block-inversion: no
interfaces: ens192
sources:
services: cockpit dhcpv6-client ssh
ports: 8080/tcp 443/tcp
protocols:
forward: no
masquerade: yes
forward-ports:
source-ports:
icmp-blocks:
rich rules:
Keith Swagler
06/10/2022, 12:10 PMfirewall-cmd --add-forward-port=port=443:proto=tcp:toport=8080
Ibra
06/10/2022, 1:55 PMKeith Swagler
06/10/2022, 6:22 PMIbra
06/10/2022, 7:00 PMKeith Swagler
06/10/2022, 7:57 PMIbra
06/11/2022, 12:36 PM