https://github.com/osquery/osquery logo
Title
m

Mystery Incorporated

06/24/2021, 1:37 AM
WUT??????? Those paths are obviously false and the agregating logs link just takes you to osquery doco. Where is fleet storing query results?
s

Silvano Ngacha

06/24/2021, 8:09 AM
Please check /tmp/osquery_result /tmp/osquery_status
m

Mystery Incorporated

06/24/2021, 10:04 AM
@Silvano Ngacha hi, thank you, that file exists but it is empty.
@Silvano Ngacha oh I see what happened here, randomly executed queries are not logged, only oines that are part of a query pack. Now I am seeing results in that file. Thank you
s

Silvano Ngacha

06/24/2021, 1:51 PM
@Mystery Incorporated welcome bro!