Hi There, I have a query, if we have configured firehose as osquery_result_log_plugin, DB as well be used to store the results of the queries?
n
Noah Talerman
07/16/2021, 1:47 PM
Hi @Anoop K V. Fleet does not store query results in its MySQL DB.
If you’ve added this query to a pack, the results will only be sent to firehose.
If you run this query as a live query, the results will not be stored or sent anywhere. Live query results will only be displayed in the Fleet UI.