zwass
12/18/2018, 12:19 AMKonstantin
12/18/2018, 4:17 AMroot@hq-o:/etc/osquery# cat osquery-local.conf
{
"schedule": {
"process_events": {
"query": "SELECT * FROM process_events;",
"interval": 10,
"snapshot" : false
}
},
"decorators": {
"load": [
"SELECT uuid AS host_uuid FROM system_info;",
"SELECT user AS username FROM logged_in_users ORDER BY time DESC LIMIT 1;"
]
}
}
zwass
12/18/2018, 4:29 AM--logger_plugin='syslog,filesystem'
2) Does osquery with the Fleet config work if you set logger_plugin
to just syslog
?