Ted Dorosheff01/15/2022, 4:01 PM
These paths seem to correspond to what we have for
I0115 07:56:12.120774 1844 ntfs_journal_events.cpp:323] Couldn't open C:\Users\teddoro\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\Settings\settings.dat.LOG2 while building FRN set I0115 07:56:12.120774 1844 ntfs_journal_events.cpp:323] Couldn't open C:\Users\teddoro\AppData\Local\Packages\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\Settings\settings.dat while building FRN set I0115 07:56:12.136206 1844 ntfs_journal_events.cpp:323] Couldn't open C:\Users\teddoro\AppData\Local\Packages\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\Settings\settings.dat.LOG1 while building FRN set I0115 07:56:12.136206 1844 ntfs_journal_events.cpp:323] Couldn't open C:\Users\teddoro\AppData\Local\Packages\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\Settings\settings.dat.LOG2 while building FRN set I0115 07:56:12.167567 1844 ntfs_journal_events.cpp:323] Couldn't open C:\Users\teddoro\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\Settings\settings.dat while building FRN set
in yaml config, which leads me to believe that my config is working. However, i'm wondering why osquery isn't able to open these files? I've installed using chocolatey, and verified that osquery is running with the proper permissions and as a service. FWIW, those error logs were observed after running:
ie, it was running from an admin shell, and not as a "service". That being said, when i run osquery in this manner i'm able to see the host i'm running it from in FleetDM and the host appears online. However, after a system reboot and when osquery is running as a service, the host does not appear online.
C:\Program Files\osquery\osqueryd\osqueryd.exe --flagfile=osquery.flags --verbose
table might be better served in the #windows channel. For the host not coming online when run as a service... Is the service running that same command you just pasted? Perhaps it needs an absolute path to the flagfile? If you take the command line from the service and paste it in an admin powershell, does the host come online? Your best bet is to test the exact command line via powershell with absolute paths and then paste it over into the Service.
Ted Dorosheff01/15/2022, 8:41 PM
Ted Dorosheff01/15/2022, 11:12 PM
as a prefix
Ted Dorosheff01/17/2022, 10:56 PM
because in the flags file only the relative path was given. I changed the flags file and now it seems to be one step past that issue, however now the new error reads:
W0117 14:55:22.073629 4404 tls_enroll.cpp:101] Failed enrollment request to <https://fleetdm-ui.ouryahoo.com/api/v1/osquery/enroll> (No node key returned from TLS enroll plugin) retrying...
Ted Dorosheff01/17/2022, 11:04 PM
Ted Dorosheff01/17/2022, 11:05 PM
Ted Dorosheff01/17/2022, 11:20 PM
I0117 15:15:05.984179 3348 rocksdb.cpp:149] Rocksdb open failed (5:0) IO error: Failed to create lock file: \Program Files\osquery\osquery.db/LOCK: The process cannot access the file because it is being used by another process. I0117 15:15:06.202491 3348 rocksdb.cpp:132] Opening RocksDB handle: \Program Files\osquery\osquery.db I0117 15:15:06.202491 3348 rocksdb.cpp:67] RocksDB: [WARN] [db\db_impl\<http://db_impl_open.cc:1846|db_impl_open.cc:1846>] Persisting Option File error: OK
I0117 15:15:06.421223 3348 dispatcher.cpp:149] Thread: 3348 requesting a stop I0117 15:15:06.421223 3348 dispatcher.cpp:156] Service: 00000218214A7950 has been interrupted I0117 15:15:06.421223 3348 dispatcher.cpp:122] Thread: 3348 requesting a join I0117 15:15:06.421223 3348 dispatcher.cpp:140] Service thread: 0000021821579A30 has joined I0117 15:15:06.436787 3348 dispatcher.cpp:144] Services and threads have been cleared E0117 15:15:06.797690 3856 shutdown.cpp:79] Worker returned exit status I0117 15:15:06.797690 1824 dispatcher.cpp:149] Thread: 1824 requesting a stop I0117 15:15:06.797690 1824 dispatcher.cpp:122] Thread: 1824 requesting a join I0117 15:15:06.797690 1824 dispatcher.cpp:140] Service thread: 000001048D7CBAD0 has joined I0117 15:15:06.812259 1824 dispatcher.cpp:144] Services and threads have been cleared
Ted Dorosheff01/17/2022, 11:30 PM
on a windows machine, and then defining my config tls endpoint to be
is the latter config line applicable? I mean for one thing, that path looks like a linux path with those forward slashes....
) is /api/v1/osquery/config."
Ted Dorosheff01/21/2022, 10:57 PM
is a location on the server, where the client should expect to receive config from?
with the node key in the body and the server will respond with the config.
if you want to be able to see the request/response bodies -- might be helpful for understanding.
Ted Dorosheff01/21/2022, 11:00 PM
in flags, and could see everything i defined in yaml config within fleetDM. So, with that being said, is it safe to assume that the client/server config exchange is working correctly?
Ted Dorosheff01/21/2022, 11:01 PM