Title
#kolide
b

benbass

06/25/2019, 3:49 PM
@zwass Hey Zach. Last week I had some issues on boarding windows machines, where they were not picking up the correct override. By re-applying the config things seemed to work, but only for the devices already enrolled. We added a new one today and are running into the same issue, meanwhile the two existing windows clients are humming along nicely.
zwass

zwass

06/25/2019, 3:50 PM
Is this immediately after enrolling? Does it still get the wrong config after the details update and Fleet knows the correct platform?
b

benbass

06/25/2019, 3:52 PM
This is immediately after enrolling. The new PC is showing up just as a stub in fleet, and we are getting an error on the host (with verbose and tls_dump) that it can’t activate the file system logger plugin at /var/log/osquery/osqueryd.results.log
3:52 PM
The logger is set as a default for when we ramp up for various linux flavors.
zwass

zwass

06/25/2019, 3:53 PM
Does this cause osquery to shut down?
b

benbass

06/25/2019, 3:54 PM
I believe so.
3:55 PM
@Ali Hanson
zwass

zwass

06/25/2019, 3:55 PM
Ah yeah that makes sense. Fleet doesn't figure out that the host is Windows until it is able to run a distributed query to get the details. So the override doesn't apply.
b

benbass

06/25/2019, 3:56 PM
Interesting. So fleet sends the default options, the windows one goes, well I can’t do that, and then stops.
3:57 PM
So fleet never gets to know that that device is windows.
zwass

zwass

06/25/2019, 3:57 PM
Likely
3:57 PM
A workaround might be to only send options in the default config that will work on all platforms, then put overrides for each.
b

benbass

06/25/2019, 3:57 PM
Yeah, my issue is I don’t know what flavor of linux I will be managing down the road.
zwass

zwass

06/25/2019, 3:57 PM
IIRC there is also a way to get some details during enrollment... I'm going to see what else I can find.
b

benbass

06/25/2019, 3:59 PM
I’ll see what I can do as a work around for now - I might have to adjust the default logger.
zwass

zwass

06/25/2019, 4:04 PM
Ah yeah actually osquery already sends details including platform by default... We could save this during the enrollment.
4:17 PM
I filed https://github.com/kolide/fleet/issues/2065 and I think I can get this implemented shortly.
b

benbass

06/25/2019, 4:30 PM
That would be awesome.