Title
#kolide
b

Beckel

07/07/2020, 2:21 PM
We're seeing OSQuery us a lot of bandwidth up for our home users which we have narrowed down to a configuration issue with one of the intervals. Do you have a recommendation for configuring
distributed_interval
and
logger_tls_period
if our main focus is to only us Fleet as a TLS Aggregrator and not ask questions?
zwass

zwass

07/07/2020, 4:13 PM
More than likely your bandwidth is going to the logging. Changing that interval is only going to have a very modest effect on throughput, because it will only effect how often the logs are sent, not how many logs are sent. You will get some additional savings from increasing
distributed_interval
and
config_refresh
.
s

seph

07/08/2020, 7:58 PM
What Zach said. If you want to see that differently, If you can tell which direction, that will tell you more. Bandwidth from the server to the client, is likely configuration refresh. Bandwidth from the client to the server, is likely to be logs.