Title
#kolide
p

Prash

11/07/2018, 7:47 AM
Hi , I know that Kolide server can log the results osquery agents in a central log file. May I know where I can I see those logs? My osquery_result is empty
joncrain

joncrain

11/07/2018, 2:18 PM
Check this out! https://github.com/kolide/fleet/blob/master/docs/infrastructure/working-with-osquery-logs.md Basically, default is
/tmp/osquery_result
or you can set it to log whereever you want. if you don't see results there you have something wrong with the config
p

Prash

11/07/2018, 2:36 PM
Thank you .. Will check
joncrain

joncrain

11/07/2018, 2:42 PM
Also, check to see if you have anything scheduled to run 🙂
2:43 PM
I think I've loaded packs in the past, but not enabled them and that's why I was not getting results...
p

Prash

11/07/2018, 2:48 PM
Hey Joncrain.. No luck ..
2:48 PM
can you kindly let me know which config file I should check ?
joncrain

joncrain

11/07/2018, 2:52 PM
the config file may or may not be used. it's just the config that's used to startup fleet. https://github.com/kolide/fleet/blob/master/docs/infrastructure/configuring-the-fleet-binary.md
2:53 PM
can you verify that its running? run something like
ps aux | grep fleet
p

Prash

11/07/2018, 2:53 PM
yes it is
joncrain

joncrain

11/07/2018, 2:54 PM
do you have any packs installed?
p

Prash

11/07/2018, 2:55 PM
I did the same way .. I passed --osquery_result_log_file flag while staring fleet
2:55 PM
no I did not install any flag
2:56 PM
I am just running query from GUI
joncrain

joncrain

11/07/2018, 2:58 PM
someone from kolide may have to verify this, but I don't think adhoc queries get logged to the results file
2:59 PM
you could save a query, create a new pack, enable it and add a host to check this
p

Prash

11/07/2018, 3:00 PM
ohh is it .. will try running packs
3:05 PM
I just created a sample pack and it is in enabled state
3:06 PM
How should I run the packs now
p

Prash

11/07/2018, 3:13 PM
It is very helpfull
3:13 PM
Will check all the docs
3:13 PM
before that I see some results in osquery_status
3:14 PM
I guess its coming from the default osqueryd query which I have removed