Jean M
09/10/2021, 5:16 PM{
"component": "service",
"err": null,
"method": "NewQuery",
"name": "hvhgvghvgh",
"sql": "SELECT * FROM osquery_info",
"took": "4.327208ms",
"ts": "2020-02-05T15:19:07.729088806Z",
"user": "jean"
}
However, I cannot see them anymore, did something changed in more recent versions? 🙄 or maybe I’m missing some configuration…Tomas Touceda
09/10/2021, 5:19 PMJean M
09/10/2021, 5:26 PMTomas Touceda
09/10/2021, 5:37 PMJean M
09/10/2021, 6:31 PM{
"hostIdentifier": "xxx",
"calendarTime": "Mon Sep 6 16:29:23 2021 UTC",
"unixTime": "1630945763",
"severity": "0",
"filename": "distributed.cpp",
"line": "121",
"message": "Executing distributed query: fleet_distributed_query_1990: SELECT * FROM socket_events WHERE remote_address = \"1.1.1.1\";",
"version": "4.7.0",
decorators...
Tomas Touceda
09/10/2021, 6:33 PMJean M
09/10/2021, 6:40 PM{
"component": "http",
"level": "info",
"method": "POST",
"numHosts": 1,
"query_id": null,
"sql": "SELECT * FROM osquery_info",
"took": "43.706372ms",
"ts": "2021-09-10T18:35:42.909882382Z",
"uri": "/api/v1/fleet/queries/run",
"user": "jean"
}