Title
#eclecticiq-polylogyx-extension
d

doteater

05/01/2019, 5:38 PM
Greetings! I'm trying out the extension for the first time. I installed osqueryd and configured it to talk to my fleet server. Then I merged in the configs from the repo, and added the extension. When I start up osqueryd it seems to hang here:
I0430 15:12:02.791899  9080 database.cpp:563] Checking database version for migration
I0430 15:12:04.289724  9592 interface.cpp:105] Registering extension (plgx_win_extension, 31328, version=1.0.28, sdk=3.2.6)
Flags: https://privatebin.net/?5a7f503bc93004a7#gYA5A7VzOO8Glqtmq+x95cIteRz5FA37dpRSPJExwQY= conf (basically just the default conf + the one from the extension repo): https://privatebin.net/?000d34495a4e0377#A12z4f74DsR8Fmq9tg5EZtGVBsaz51dFqnA3XKJ6ZUQ=
5:41 PM
Actually now I realize I'm using fleet instead of the local filesystem for conf - that must be the issue?
6:05 PM
Now I switched to local filesystem conf, at first my config wouldn't parse due to clumsy edits - but new tables were working via direct queries from fleet. Now that I've gotten the config fixed I get this error:
E0501 11:02:56.950307  8236 init.cpp:593] Cannot activate filesystem logger plugin: Could not create file: \ProgramData\osquery\log\osqueryd.results.log
. Guessing this is due to also using Fleet TLS for logging - maybe using fleet along with this extension isn't really going to work? Does the extension depend on using the local filesystem plugins for config and logging?
manu

manu

05/01/2019, 6:08 PM
it does support both local/tls config. looking at ur logs it seems you don't have
log
folder under
c:\programdata\osquery\
6:08 PM
can you please check if not then create the folder manually
6:09 PM
also make sure that you are running osquery
3.2.6
6:11 PM
this is a sample config for local filesystem https://github.com/polylogyx/osq-ext-bin/blob/master/osquery.flags
d

doteater

05/01/2019, 6:15 PM
Thanks for the confirmation @manu - I just realized that error was just because the file already existed, once I removed the existing results log the error went away. Restarting service also doesn't show the error again - maybe there was some kind of permission issue with the existing log file.
manu

manu

05/01/2019, 6:16 PM
great
6:18 PM
infact when u would be running and switch between shell and as a service u would be facing permission for db, that's very common in the beginning too.
6:19 PM
the soln to that prob is to either point to a diff db in ur flagsfile or takeownership of the folder or remove it altogether, if u r just experimenting.