I'll also add that /var/log/osquery/result.log is world read writable and selinux is disabled (rhel7)
z
zwass
03/02/2018, 4:45 PM
On the Fleet server, right?
🍻 1
s
stefanmaerz
03/02/2018, 4:48 PM
that was my problem. I thought the logs were stored locally on the client
thanks!
z
zwass
03/02/2018, 4:49 PM
Sweet, glad you worked it out! You can of course configure logs to be stored on the local machine, but part of the advantage of Fleet is that it aggregates the logs onto a single machine for you.
👍 1
s
stefanmaerz
03/02/2018, 4:54 PM
I actually much prefer them on the fleet server. Makes my deployment much easier since I don't have to worry about collecting logs from 4000 endpoints