https://github.com/osquery/osquery logo
Title
s

stefanmaerz

02/12/2019, 5:02 PM
@Johan Edholm ^^^ These are at least 3 benefits
j

Johan Edholm

02/12/2019, 6:35 PM
Thank you @stefanmaerz! That's some great input, much appreciated! Regarding
2)
. Does that mean all logs first goes to Fleet and are then forwarded to Splunk? That seems like a nice thing since that would mean only that one machine would need to be able to reach Splunk.
s

stefanmaerz

02/12/2019, 6:37 PM
Correct. Logs get collected on the fleet server. Fleet server ships them to Splunk. In my envioronment if I just used osquery, the alternative would have been either install a Splunk forwarder on every endpoint or log locally and ship to syslog.
j

Johan Edholm

02/12/2019, 6:54 PM
Thank you again @stefanmaerz, that's very helpful!
👍 1