Title
#kolide
z

Zach Zeid

07/24/2020, 3:35 PM
or do I have to write some db script to do so?
j

Jason W

07/24/2020, 3:43 PM
Generally people use the logging functionality to export query results (to ELK for example)
zwass

zwass

07/24/2020, 3:44 PM
For live queries? You can redirect stdout from
fleetctl query
to save them to a file or send them wherever you want.
z

Zach Zeid

07/24/2020, 4:17 PM
queries in general, I thought
fleetctl
was a wrapper for the API
4:17 PM
so people use something like syslog to export the queries out, and queries live in
/tmp
?
terracatta

terracatta

07/24/2020, 5:01 PM
this is one key difference between fleet and our saas app K2. In the latter the results of live queries are stored so you can retrieve them later with an API (and multiple people can view the results in the UI at the same time). In addition, K2 allows you to take an adhoc query and run it "continuously" by inserting it in the schedule and will keep the results up to date accordingly.