https://github.com/osquery/osquery logo
#kolide
Title
h

hilt

06/25/2020, 7:24 AM
hey folks, is there any way the fleet binary can be configured to show /tmp/osquery_result instead of the combined log when running from a container / kubernetes?
I ended up using a azureFile mount in k8s to export the result logs to a storage account. From there I use filebeat’s osquery module to import it to Elastic!
4 Views