Ari Weinberg
07/12/2022, 8:45 PM{
"component": "http",
"err": "error in query ingestion",
"ingestion-err": "campaign waiting for listener (please retry)",
"ip_addr": "ENDPOINT-IP:41730",
"level": "error",
"method": "POST",
"took": "1.136788ms",
"ts": "2022-07-12T20:38:50.060101107Z",
"uri": "/api/v1/osquery/distributed/write",
"x_for_ip_addr": ""
}
Also getting (although not sure its related):
{
"component": "http",
"err": "read auth token: reading from websocket: sockjs: session not in open state",
"msg": "failed to read auth token",
"ts": "2022-07-12T20:37:57.77330272Z"
}
The problem appears to be the agent talking back to the fleet server, because I can see the query being run on the agent in debug mode. It just seems to fail when posting back the results. Agent is vanilla OSquery 5.1.0
This only started since I updated a few minutes ago from fleet 4.9.1Kathy Satterlee
07/12/2022, 9:27 PMAri Weinberg
07/12/2022, 9:27 PMKathy Satterlee
07/12/2022, 9:52 PMAri Weinberg
07/12/2022, 9:53 PMKathy Satterlee
07/12/2022, 10:05 PMcompose
file?Ari Weinberg
07/12/2022, 10:27 PMJason Cetina
07/12/2022, 10:33 PMKathy Satterlee
07/12/2022, 11:04 PMzwass
07/12/2022, 11:09 PMJason Cetina
07/12/2022, 11:10 PMzwass
07/12/2022, 11:10 PMJason Cetina
07/12/2022, 11:11 PMzwass
07/12/2022, 11:12 PMJason Cetina
07/12/2022, 11:12 PMzwass
07/12/2022, 11:12 PMJason Cetina
07/12/2022, 11:12 PMzwass
07/12/2022, 11:13 PMJason Cetina
07/12/2022, 11:13 PMzwass
07/12/2022, 11:14 PMJason Cetina
07/12/2022, 11:15 PMzwass
07/12/2022, 11:25 PMAri Weinberg
07/12/2022, 11:37 PMzwass
07/12/2022, 11:38 PMAri Weinberg
07/12/2022, 11:38 PMzwass
07/12/2022, 11:39 PMAri Weinberg
07/12/2022, 11:39 PMzwass
07/12/2022, 11:39 PMAri Weinberg
07/12/2022, 11:39 PMzwass
07/12/2022, 11:40 PMAri Weinberg
07/12/2022, 11:40 PMKathy Satterlee
07/12/2022, 11:40 PMAri Weinberg
07/12/2022, 11:42 PMzwass
07/12/2022, 11:43 PMKathy Satterlee
07/12/2022, 11:43 PMJason Cetina
07/12/2022, 11:50 PM/etc/ssl/certs/ca-certificates.crt
. The root CA changed for this endpoint and so everything turfed when it got rotated. Not sure how/why it was setup that way. Anyway, it's fixed now.zwass
07/12/2022, 11:50 PMJason Cetina
07/12/2022, 11:51 PMKathy Satterlee
07/12/2022, 11:51 PMAri Weinberg
07/15/2022, 3:13 PM{
"component": "http",
"err": "error in query ingestion",
"ingestion-err": "campaign stopped",
"ip_addr": "AGENT-IP:50524",
"level": "error",
"method": "POST",
"took": "2.406993ms",
"ts": "2022-07-15T15:11:55.292524773Z",
"uri": "/api/v1/osquery/distributed/write",
"x_for_ip_addr": ""
}
Getting the following in the console: