ryan08/03/2021, 2:30 PM
as normal user (expected since it’s a priv port) and then
if I run via sudo
Failed to start: initializing service: initializing osquery logging: create filesystem status logger: create new raw logger: open /tmp/osquery_status: permission denied
Mystery Incorporated08/03/2021, 3:44 PM
zwass08/05/2021, 4:08 PM
when running as root? Can you share the full command and output?
ryan08/05/2021, 7:07 PM
zwass08/05/2021, 10:34 PM
and show the results? We are looking to see if there are unusual permissions on that file.
sudo ls -l /tmp/osquery_status