osqueryd --flagfile=/etc/osquery/osquery.flags
W1109 11
0251.865283 25474 tls_enroll.cpp:66] Failed enrollment request to
https://172.20.17.23:8080 (Cannot parse JSON: Invalid value. Offset: 0) retrying...
W1109 11
0252.873628 25474 tls_enroll.cpp:66] Failed enrollment request to
https://172.20.17.23:8080 (Cannot parse JSON: Invalid value. Offset: 0) retrying...
W1109 11
0256.904080 25474 tls_enroll.cpp:66] Failed enrollment request to
https://172.20.17.23:8080 (Cannot parse JSON: Invalid value. Offset: 0) retrying...
W1109 11
0257.912461 25474 tls_enroll.cpp:66] Failed enrollment request to
https://172.20.17.23:8080 (Cannot parse JSON: Invalid value. Offset: 0) retrying...
I1109 11
0301.933297 25474 events.cpp:825] Event publisher not enabled: syslog: Publisher disabled via configuration
W1109 11
0302.052307 25474 inotify.cpp:80] Failed to do stat on: /etc/init/
W1109 11
0302.101761 25502 tls_enroll.cpp:66] Failed enrollment request to
https://172.20.17.23:8080 (Cannot parse JSON: Invalid value. Offset: 0) retrying...
W1109 11
0303.112587 25502 tls_enroll.cpp:66] Failed enrollment request to
https://172.20.17.23:8080 (Cannot parse JSON: Invalid value. Offset: 0) retrying...
I1109 11
0308.053982 25503 scheduler.cpp:83] Executing scheduled query hardware_events: SELECT * FROM hardware_events;
W1109 11
0308.188552 25502 tls_enroll.cpp:66] Failed enrollment request to
https://172.20.17.23:8080 (Cannot parse JSON: Invalid value. Offset: 0) retrying...
I1109 11
0309.072151 25503 scheduler.cpp:83] Executing scheduled query file_events: SELECT * FROM file_events;
I1109 11
0309.084679 25503 scheduler.cpp:83] Executing scheduled query process_events: SELECT auid, cmdline, ctime, cwd, egid, euid, gid, parent, path, pid, time, uid FROM process_events WHERE path NOT IN ('/bin/sed', '/usr/bin/tr', '/bin/gawk', '/bin/date', '/bin/mktemp', '/usr/bin/dirname', '/usr/bin/head', '/usr/bin/jq', '/bin/cut', '/bin/uname', '/bin/basename') and cmdline NOT LIKE '%_key%' AND cmdline NOT LIKE '%secret%';
I1109 11
0309.099536 25503 scheduler.cpp:83] Executing scheduled query socket_events: SELECT action, auid, family, local_address, local_port, path, pid, remote_address, remote_port, success, time FROM socket_events WHERE success=1 AND path NOT IN ('/usr/bin/hostname') AND remote_address NOT IN ('127.0.0.1', '169.254.169.254', '', '0000
00000000
00000000
00000000:0001', '::1', '0000
00000000
00000000
ffff7f00:0001', 'unknown', '0.0.0.0', '0000
00000000
00000000
00000000:0000');
W1109 11
0309.196720 25502 tls_enroll.cpp:66] Failed enrollment request to
https://172.20.17.23:8080 (Cannot parse JSON: Invalid value. Offset: 0) retrying...
W1109 11
0317.292363 25502 tls_enroll.cpp:66] Failed enrollment request to
https://172.20.17.23:8080 (Cannot parse JSON: Invalid value. Offset: 0) retrying...
I1109 11
0318.114519 25503 scheduler.cpp:83] Executing scheduled query file_events: SELECT * FROM file_events;