Title
#kolide
g

groob

11/15/2018, 3:27 PM
--logger_plugin=something_other_than_filesystem
r

Ralph23

11/15/2018, 3:39 PM
for my logger pluggin i have --logger_plugin=filesystem
3:39 PM
nothing shows up in ProgramData\osquery\log
3:40 PM
i also added --osquery_status_log_file:\ProgramData\osquery\log
3:41 PM
nothing works…all this on a windows end point
3:41 PM
yes the daemon connects to kolide very easy.. so it cant be the flag file
g

groob

11/15/2018, 3:41 PM
can you run it with --tls_dump and see that your packs are being schedule?
r

Ralph23

11/15/2018, 3:41 PM
im using kolide
g

groob

11/15/2018, 3:42 PM
i dont care what you’re using on the other end. I’m asking about running osquery in your shell and adding the --tls_dump flag so you can debug it
r

Ralph23

11/15/2018, 4:00 PM
did that already
4:00 PM
not working
g

groob

11/15/2018, 4:04 PM
what is not working
4:04 PM
what are you seeing in tls_dump
r

Ralph23

11/15/2018, 4:22 PM
why is the logger pluggin tls
4:25 PM
Here is the flag file