billcobbler03/16/2021, 12:35 AM
set to 3, but osquery clients continue to send old distributed query results which results in repeated 500s with Fleet logging error messages indicating the hosts are still using old query names. Some example error logs:
As far as I can tell after looking at how Fleet generates host detail queries, this might just be an issue with OSQuery not honoring the max attempts setting? Anyone else run into this, or know for a fact that the max attempts setting actually works?
failed to ingest result: unknown query prefix: kolide_detail_query_osquery_flags failed to ingest result: unknown query prefix: kolide_label_query_9 failed to ingest result: unknown query prefix: kolide_detail_query_uptime
billcobbler03/16/2021, 12:58 AM
(out of ~3k hosts) but that might just be NAT'd IPs or something. This happened on our server fleet environment, but the behavior fell off after a couple days. However our workstation fleet environment continues to experience the issue and I don't see any downward trend in the error rate.