Pete
11/03/2020, 6:15 PMseph
--osquery_flag logger_plugin=filesystem
tells osquery to write to the filesystem, it’s using the default path — \Program Files\osquery\log\osqueryd.results.log
that directory doesn’t exists, so it’s an errorseph
seph
seph
Pete
11/03/2020, 6:48 PMPete
11/03/2020, 6:50 PMPete
11/03/2020, 6:50 PMsundsta
11/03/2020, 6:52 PMPete
11/03/2020, 6:55 PMPete
11/03/2020, 6:56 PMPete
11/03/2020, 6:56 PMseph
seph
Pete
11/03/2020, 6:57 PMPete
11/03/2020, 6:58 PMseph
seph
Pete
11/03/2020, 6:59 PMseph
Pete
11/03/2020, 7:10 PMPete
11/03/2020, 7:11 PMPete
11/03/2020, 7:11 PMPete
11/03/2020, 7:13 PM