Well… What’s in the log?
# kolide
s
Well… What’s in the log?
t
@seph it looks like stuff thats used by kolide to fill in the host info on the card, like host_uuid, time, osquery version and stuff like that. It's just in there repeatedly, looks to save more every time the host checks in
s
I’m not sure I understand. You’re saying this is a results log, and that it has a lot of decorators in it?
Is this ultimately your local configuration?
t
its not the results log. its the osquery-output.log, not sure if thats what the results go on MAC but there are no scheduled queries configured
s
Can you send a snippet? I’m not sure why those things would be logged there
t
and no, it's deployed across my environment and a user reported this to me while cleaning up their workstation
s
Without seeing a log, I’m not really sure what you’re referring to. But this might be fleet specific, and I don’t do much with fleet
For future readers — I’ve been chatting with Tim in DMs. I don’t think this is a Kolide related. The mac package he’s using sets osquery in verbose mode, and does not have log rotation.