Jocelyn Bothe
04/20/2021, 7:32 PMzwass
--buffered_log_max=1
to osquery, which would cause it to drop all but the newest log after the next logging attempt.Jocelyn Bothe
04/20/2021, 8:53 PM[root@osquery-service-vab183 ouser]# /usr/bin/fleet version
fleet version 3.10.0
zwass
filesystem
or stdout
and waiting until osquery is done dumping the logs. Then switch back to Kinesis.Jocelyn Bothe
04/21/2021, 2:07 PM