Mystery Incorporated

08/07/2021, 6:33 AM
Hello, when osqueryd is set to log over TLS to fleet, where do the info, warning and error logs go? I do not see any of these messages in result or status logs?????

Sarah Gillespie

08/09/2021, 8:38 PM
They should go to the status logs. If you're still not seeing them there, could you share some more info about your configuration, etc. so folks can try to help troubleshoot?

Mystery Incorporated

08/10/2021, 12:53 PM
interesting, I think the issue was that osquery itself wasn't generating logs, it was connecting to fleet, enrolling and then freezing/doing nothing. When I changed the logging from TLS to filesystem, no logs were being wrote to disk so from that I conclude that most likely osquery was not generating logs, thus I was not seeing them in status
