Has anyone had a host just not pickup a query pack...
# fleet
Has anyone had a host just not pickup a query pack? So like it's been assigned into the MS Windows label, but it's not being given the query pack for windows hosts...
are you running osqueryd with
--versbose --tls_dump
and you're not seeing the pack?
I fixed it, it seems that some how the host thought it had both osquery 4.9 and 5.0.1 installed at the same time, dunno why
But it caused big problems, it was reporting osquery as a no binary on disk process, wouldn't get assigned a pack etc, anyway I totally scrubbed osquery and reinstalled it and that fixed it
oh and I purged the software, software_cpe and software_cve tables in the db
glad you figured it out!