06/25/2020, 7:24 AM
hey folks, is there any way the fleet binary can be configured to show /tmp/osquery_result instead of the combined log when running from a container / kubernetes?
1:14 PM
I ended up using a azureFile mount in k8s to export the result logs to a storage account. From there I use filebeat’s osquery module to import it to Elastic!