nyanshak03/09/2021, 9:14 PM
is set to
, is there any benefit to also setting
to anything other than the default (
nyanshak03/09/2021, 9:21 PM
is used rarely if ever now. I'm tempted to remove it entirely but it could be a good escape valve if someone ends up in that bad scenario.
nyanshak03/09/2021, 9:47 PM
nyanshak03/09/2021, 9:49 PM
nyanshak03/09/2021, 9:50 PM
nyanshak03/09/2021, 9:52 PM
, so even though fleet will have unique values for each osquery host, osquery will still send logs with
set to whatever osquery specifies. So there could still be a bit of confusion when trying to correlate logs to fleet hosts, right? And would the situation be any better if the log destination was set to fleet? I'm assuming not, because it would be processing-intensive operation to parse & rewrite all the logs.
to identify the osquery logs (rather than some decorator value) you'll want to configure it appropriately on the clients regardless of Fleet's value.
nyanshak03/09/2021, 10:08 PM
/ why is this the recommended approach? presumably you would never have duplicates for
(except maybe if you copy the osquery DB?)
nyanshak03/09/2021, 10:12 PM