Speaking of #osquery-go-distributed-read-plugin-implementation-questions 🙄, I am deploying osquery with Kolide on my team's endpoints (mostly windows machines). I am trying to perform distributed queries (from Kolide) - but can't receive any answer. Looking at the status logs - I see that for a long while the queried computers did not post to distributed/read, it is as if the distributed plugin crashed. Did anyone ever noticed such a problem? Yesterday it also happened, and only after few hours the osquery agent started posting to distributed/read again.
03/20/2018, 7:59 PM
I had this same problem when using the latest version of osquery (2.11) with Kolide. I ended up compiling their binary dist which included it's own version of osquery for launcher (2.9) and this resolved my problem. I did clear out the state directories as well.