Julian Scala
10/09/2020, 3:28 PMZach Zeid
10/09/2020, 3:38 PMfilesystem
in this case would be whatever you configured your ECS containers to log to (Cloudwatch Logs, most typically).Julian Scala
10/09/2020, 3:48 PM--osquery_result_log_plugin
like by using fleetctl
or something?Zach Zeid
10/09/2020, 3:48 PMJulian Scala
10/09/2020, 3:49 PMKOLIDE_OSQUERY_RESULT_LOG_PLUGIN
. Changing that env var would be enough?sundsta
10/09/2020, 8:25 PMJulian Scala
10/09/2020, 8:27 PM