dear all,
is it possible to split up the output of osqueryd.results.log into several logs, like osqueryd.apache.access.log and osqueryd.apache.error.log?
Any hints? 🙂
g
groob
08/23/2017, 10:01 AM
@sonja you have to do some post-processing on your own. logstash or your own code for that.
s
sonja
08/23/2017, 10:14 AM
Ok thank you!
g
groob
08/23/2017, 10:33 AM
I do this with the help of a TLS server that receives everything from the result log then sends the data to various workers depending on the log type/source
s
sonja
08/23/2017, 12:17 PM
thanks!
i plan to use fluentd to send the logs to kafka-topics, but osquery writes everything to the one file, so i finally have to configure fluentd to send some data to one topic and the other logs to other topics.
Hope that works 🙏