Title
#kolide
Saif Abulkhair

Saif Abulkhair

09/30/2020, 6:32 AM
How do we get live query results via web apis ?
sundsta

sundsta

09/30/2020, 4:24 PM
The
fleetctl
tool implements an example of how to do this. https://github.com/kolide/fleet/blob/master/cmd/fleetctl/query.go
Saif Abulkhair

Saif Abulkhair

09/30/2020, 5:59 PM
thanks. Any idea if i can get these working without using the cli ?
CptOfEvilMinions

CptOfEvilMinions

09/30/2020, 6:42 PM
@Saif Abulkhair the Kolide platform is built with Go Kit so most actions performed via the webgui is an API call. The Kolide “API” has not been officially documented but reading the HTTP handlers file will be helpful. I don’t have access to my homelab Kolide instance because I am at work but here are some starter curl statements and API endpoints First, you need to authenticate yourself:
curl -X POST https://<Kolide>/api/v1/kolide/login -d '{"Username": "<Kolide admin e-mail>", "Password": "<Kolide admin password>"}'
When you successfully login you should receive a JWT token which you will use for all future API requests to Kolide. Here is the Kolide login code. Next, you can use the JWT to perform API operations such as getting a list of queries: /api/v1/kolide/queries. Next, request query results using /api/v1/kolide/results/
Saif Abulkhair

Saif Abulkhair

10/01/2020, 7:12 AM
Awesome. I wll try thhese pointers and hopefully would come back to thank you again.😁
11:47 AM
@CptOfEvilMinions this is what i tried and reached.
11:51 AM
1 Login using /login endpoint 2. Get the lsit of all queires using / queries endpoint 3. Execute one of the query using /queries/run endpoint and passing the body something like this
{"query":"SELECT name[Software Name], bundle_short_version[Software version], bundle_identifier[Software publisher] FROM apps \nwhere bundle_identifier not like '%com.apple%' and \npath like ( '%/Applications/' ||apps.name);","selected":{"hosts":[],"labels":[7]}}
I can see from code that a websocket gets created and its the websocket which returns the queries results. How do i consume the websocket which is generted at runitme ?
sundsta

sundsta

10/04/2020, 7:40 PM
See the
fleetctl
source I linked previously, it shows an example of how to do so in Golang