However I am not seeing any entry in result_log table.polylogyx=# select * from result_log
12/23/2019, 7:37 AM
Are you running the server using docker containers?
I meant to say that are you trying to run the server through command line on host machine directly?
We save the incoming scheduled query data using celery worker and that needs to be running
12/23/2019, 1:03 PM
Yes, I am running server as docker container
I have seen celery worker running inside plgx-esp_plgx-esp_1 container . I have schedule a simple query "select * from processes" but no data so Not sure what else could be wrong or missing ?
12/23/2019, 4:45 PM
how are you adding the query?
are the default set of queries workiing?
12/23/2019, 6:04 PM
Yes, Default set of query is working. I can see result in log file
12/24/2019, 6:43 AM
did you connect the newly added query and the target endpoint with a 'tag'?
12/24/2019, 12:27 PM
Yes, I added query and target via tag
Also I updated pack/all-events-pack/ with new query Windows-Native-Logs: SELECT * from windows_events where source = 'Security' or source = 'Microsoft-Windows-Windows Defender/Operational' or source = 'microsoft-windows-powershell/operational'
I am seeing query running in status.log file but no result in result.log file
12/24/2019, 4:11 PM
And there are relevant events in the windows event viewer that you expect? I mean, i am wondering it's not a situation where there are no events.
12/24/2019, 5:18 PM
yes, There is events in event viewer
also I am seeing this logs in /var/log/plgx_srv.log
2019-12-24 18:48:10,216--E--140116265395408--append_node_information_to_result_log--'NoneType' object is not subscriptable
2019-12-24 18:48:10,217--E--140116265395408--append_node_information_to_result_log--'NoneType' object is not subscriptable
12/26/2019, 7:04 AM
I don't see any tags attached to the query from the screenshot you have shared
Add the same tag to a
and the desired
12/26/2019, 12:52 PM
Thank you @moulik. It is working
12/26/2019, 12:55 PM
12/26/2019, 1:10 PM
Can we specify custom tag on endpoint agents using --host_identifier=specified ?[7:54 AM]
Also log coming from rsyslog do not have hostname or machine name so is it possible to append hostname and specific tag in each and every logs coming from endpoint ?
Thank you @moulik log_tee.handle_result(data, host_identifier=node.host_identifier,node=node.to_dict()) is working.
For adding a custom tag ,I am not sure what need to done here as in setting.py it is define as :
I want to add tag like this in endpoint
--specified_identifier=ASHISH123 and append this information in all results coming from that endpoint.
12/27/2019, 6:00 AM
These are osquery specific attributes and tags are something which is server specific. You can create a list of predefined tags in this array(POLYLOGYX_ENROLL_DEFAULT_TAGS) and everytime an endpoint will register these tags will get automatically applied