Mystery Incorporated
10/08/2021, 3:13 PMosquery:
detail_update_interval: 27m
Tomas Touceda
10/08/2021, 3:16 PMJocelyn Bothe
10/08/2021, 3:18 PMTomas Touceda
10/08/2021, 3:19 PMMystery Incorporated
10/08/2021, 3:22 PMJocelyn Bothe
10/08/2021, 3:29 PMMystery Incorporated
10/08/2021, 3:36 PMTomas Touceda
10/08/2021, 3:42 PMMystery Incorporated
10/08/2021, 3:44 PMTomas Touceda
10/08/2021, 3:45 PMMystery Incorporated
10/08/2021, 3:45 PM{
"component": "crons",
"cron": "vulnerabilities",
"err": "getting cpes for: increase-memory-limit: fts5: syntax error near \".\"",
"level": "error",
"software->cpe": "error translating to CPE, skipping...",
"ts": "2021-10-08T15:37:07.933390548Z"
}
{
"component": "http",
"err": "read auth token: reading from websocket: sockjs: session not in open state",
"msg": "failed to read auth token",
"ts": "2021-10-08T15:34:45.315116969Z"
}
Tomas Touceda
10/08/2021, 3:47 PMMystery Incorporated
10/08/2021, 3:47 PMTomas Touceda
10/08/2021, 3:48 PMerr
or ingest-err
Mystery Incorporated
10/08/2021, 3:51 PMTomas Touceda
10/08/2021, 3:55 PMMystery Incorporated
10/08/2021, 3:56 PMTomas Touceda
10/08/2021, 3:57 PMMystery Incorporated
10/08/2021, 3:58 PMExecStart=/usr/local/bin/fleet serve --config /home/terrance/fleet/config.yml
Tomas Touceda
10/08/2021, 4:00 PMMystery Incorporated
10/08/2021, 4:06 PMStandardOutput=/var/log/fleet_standard.log
StandardError=/var/log/fleet_error.log
Tomas Touceda
10/08/2021, 4:08 PMMystery Incorporated
10/08/2021, 4:09 PM{"component":"crons","cron":"vulnerabilities","databases-path":"/mnt/fleetvuln","level":"info","ts":"2021-10-08T16:10:36.864309515Z"}
{"component":"crons","cron":"vulnerabilities","level":"info","periodicity":"1h0m0s","ts":"2021-10-08T16:10:36.864402755Z"}
{"address":"127.0.0.1:2498","msg":"listening","transport":"https","ts":"2021-10-08T16:10:36.883492137Z"}
Tomas Touceda
10/08/2021, 4:12 PMMystery Incorporated
10/08/2021, 4:15 PM{
"host": "xxxx",
"level": "debug",
"msg": "host reported software with empty name",
"source": "programs",
"ts": "2021-10-08T16:14:26.936622816Z",
"version": "5.5.0.6704"
}
{
"component": "http",
"err": [
"failed to save host software: insert software: Error 1054: Unknown column 'bundle_identifier' in 'field list'"
],
"ip_addr": "127.0.0.1:42184",
"level": "debug",
"method": "POST",
"took": "98.103886ms",
"ts": "2021-10-08T16:14:25.29209961Z",
"uri": "/api/v1/osquery/distributed/write",
"x_for_ip_addr": "x.x.x.x"
}
zwass
10/08/2021, 5:05 PMMystery Incorporated
10/09/2021, 2:08 AM