Hi, having an issue with a bunch of new endpoints enrolling, I see them putting query results in the osquery_results.log yet they don't show up on the kolide GUI/API, anyone have an idea what the cause of this could be?
03/20/2020, 3:47 PM
Scheduled queries don’t end up in the UI. They are sent to whatever logger plugin you have configured (filesystem by default)
03/20/2020, 3:52 PM
I mean the actual host doesn't appear at all in Kolide Fleet, even though it does make the connection
03/20/2020, 4:34 PM
Look at the status log, it will tell you
03/20/2020, 9:11 PM
@MM probably not your issue, but I had something similar when using UUID for host identifier. Containers running on the same host all had the same UUID, so whichever enrolled first showed up in Fleet, though all continued to send longs.