Title
#kolide
p

poisonous97

04/07/2020, 8:49 AM
hello every, i am using kolide fleet to manage the osquery agents. I want to deloy multi-sites fleet but only using a dashboard. How to deloy it? Same is:
d

DG

04/07/2020, 2:58 PM
In my head, and im a newbie at this - the dashboard would be your SIEM or event correlator (like Splunk) - assuming the dashboard is just info gathered from each fleet. The fleet runs query packs, or the clients run local packs and send to fleets, whom then aggregate up to a central "something" that can take the data
sundsta

sundsta

04/07/2020, 4:58 PM
^ that is correct. Fleet just receives the logs and forwards them to a destination you specify. It does not have log search, dashboarding, etc.
p

poisonous97

04/08/2020, 2:04 AM
how about management osquery when using fleet to config the all osquery? one by one ?
sundsta

sundsta

04/08/2020, 3:27 PM
Yes, Fleet also controls the queries run on the endpoints connected to it. You would have to apply the same queries/packs to each site in your case, but that’s trivial with
fleetctl