Dan Achin
02/18/2021, 6:27 PMosquery:
node_key_size: 24
status_log_plugin: filesystem
result_log_plugin: filesystem
status_log_file: /var/log/osquery/osquery_status.log
result_log_file: /var/log/osquery/osquery_results.log
filesystem:
status_log_file: /var/log/osquery/osquery_status.log
result_log_file: /var/log/osquery/osquery_results.log
enable_log_rotation: true
enable_log_compression: true
zwass
02/18/2021, 7:47 PMstatus_log_file
is deprecated in the osquery
block as the configuration for the filesystem logging was moved to the filesystem
block when we introduced the concept of logging plugins.Dan Achin
02/18/2021, 7:59 PM