Channels
android_tests
apple-silicon
arm-architecture
auditing-warroom
aws
carving
code-review
community-feeds
core
darkbytes
doorman
ebpf
eclecticiq-polylogyx-extension
extensions
file-carving
fim
fleet
fleet-dev
fleetosquery
foundation
fuzzing
general
golang
goquery
infrastructure
jobs
kolide
linen-dev
linux
macos
officehours
osctrl
plugins
process-auditing
querycon
queryhub
random
selfgroup
sql
tls
uptycs
vendor-feeds
website
windows
zeek
zentral
zercurity
Powered by
Title
m
Mystery Incorporated
06/24/2021, 1:37 AM
WUT??????? Those paths are obviously false and the agregating logs link just takes you to osquery doco. Where is fleet storing query results?
s
Silvano Ngacha
06/24/2021, 8:09 AM
Please check /tmp/osquery_result /tmp/osquery_status
m
Mystery Incorporated
06/24/2021, 10:04 AM
@Silvano Ngacha
hi, thank you, that file exists but it is empty.
@Silvano Ngacha
oh I see what happened here, randomly executed queries are not logged, only oines that are part of a query pack. Now I am seeing results in that file. Thank you
s
Silvano Ngacha
06/24/2021, 1:51 PM
@Mystery Incorporated
welcome bro!
5 Views
#fleet
Join Slack