osqueryd --flagfile=/etc/osquery/osquery.flags
W1109 11:02:51.865283 25474 tls_enroll.cpp:66] Failed enrollment request to
https://172.20.17.23:8080 (Cannot parse JSON: Invalid value. Offset: 0) retrying...
W1109 11:02:52.873628 25474 tls_enroll.cpp:66] Failed enrollment request to
https://172.20.17.23:8080 (Cannot parse JSON: Invalid value. Offset: 0) retrying...
W1109 11:02:56.904080 25474 tls_enroll.cpp:66] Failed enrollment request to
https://172.20.17.23:8080 (Cannot parse JSON: Invalid value. Offset: 0) retrying...
W1109 11:02:57.912461 25474 tls_enroll.cpp:66] Failed enrollment request to
https://172.20.17.23:8080 (Cannot parse JSON: Invalid value. Offset: 0) retrying...
I1109 11:03:01.933297 25474 events.cpp:825] Event publisher not enabled: syslog: Publisher disabled via configuration
W1109 11:03:02.052307 25474 inotify.cpp:80] Failed to do stat on: /etc/init/
W1109 11:03:02.101761 25502 tls_enroll.cpp:66] Failed enrollment request to
https://172.20.17.23:8080 (Cannot parse JSON: Invalid value. Offset: 0) retrying...
W1109 11:03:03.112587 25502 tls_enroll.cpp:66] Failed enrollment request to
https://172.20.17.23:8080 (Cannot parse JSON: Invalid value. Offset: 0) retrying...
I1109 11:03:08.053982 25503 scheduler.cpp:83] Executing scheduled query hardware_events: SELECT * FROM hardware_events;
W1109 11:03:08.188552 25502 tls_enroll.cpp:66] Failed enrollment request to
https://172.20.17.23:8080 (Cannot parse JSON: Invalid value. Offset: 0) retrying...
I1109 11:03:09.072151 25503 scheduler.cpp:83] Executing scheduled query file_events: SELECT * FROM file_events;
I1109 11:03:09.084679 25503 scheduler.cpp:83] Executing scheduled query process_events: SELECT auid, cmdline, ctime, cwd, egid, euid, gid, parent, path, pid, time, uid FROM process_events WHERE path NOT IN ('/bin/sed', '/usr/bin/tr', '/bin/gawk', '/bin/date', '/bin/mktemp', '/usr/bin/dirname', '/usr/bin/head', '/usr/bin/jq', '/bin/cut', '/bin/uname', '/bin/basename') and cmdline NOT LIKE '%_key%' AND cmdline NOT LIKE '%secret%';
I1109 11:03:09.099536 25503 scheduler.cpp:83] Executing scheduled query socket_events: SELECT action, auid, family, local_address, local_port, path, pid, remote_address, remote_port, success, time FROM socket_events WHERE success=1 AND path NOT IN ('/usr/bin/hostname') AND remote_address NOT IN ('127.0.0.1', '169.254.169.254', '', '0000:0000:0000:0000:0000:0000:0000:0001', '::1', '0000:0000:0000:0000:0000:ffff:7f00:0001', 'unknown', '0.0.0.0', '0000:0000:0000:0000:0000:0000:0000:0000');
W1109 11:03:09.196720 25502 tls_enroll.cpp:66] Failed enrollment request to
https://172.20.17.23:8080 (Cannot parse JSON: Invalid value. Offset: 0) retrying...
W1109 11:03:17.292363 25502 tls_enroll.cpp:66] Failed enrollment request to
https://172.20.17.23:8080 (Cannot parse JSON: Invalid value. Offset: 0) retrying...
I1109 11:03:18.114519 25503 scheduler.cpp:83] Executing scheduled query file_events: SELECT * FROM file_events;