Hello, I’m looking to ship the kolide-fleet logs from the filesystem using Fluent and into my ES cluster. Does kolide have that capability to use Fluent to ship logs off?
03/06/2019, 6:55 PM
Fleet doesn't have any log-shipping built in. Typically you would use fluentd to ship logs of the Fleet server filesystem(s).
03/06/2019, 6:56 PM
And I would assume it’s the same with OSQuery if I’d like to use Fluent?
03/06/2019, 6:57 PM
Yup, that sounds about right. If you're logging to filesystem, I think it's assumed that you'll configure something to ship it separately.
There are logging plugins for things like Kinesis, and you could write your own... though I'd recommend just configuring fluent instead of writing a plugin for that specifically
03/06/2019, 6:59 PM
Ahh. Okay! Thank you!
03/06/2019, 7:02 PM
If it's easy enough for you to get fluentd on all your osquery nodes, you might as well log to the filesystems and ship from there. Sometimes it can be easier to just run the log forwarder on the Fleet server and let Fleet aggregate the logs on its own filesystem.