https://github.com/osquery/osquery logo
Title
s

stefanmaerz

03/02/2018, 4:35 PM
I'll also add that /var/log/osquery/result.log is world read writable and selinux is disabled (rhel7)
z

zwass

03/02/2018, 4:45 PM
On the Fleet server, right?
🍻 1
s

stefanmaerz

03/02/2018, 4:48 PM
that was my problem. I thought the logs were stored locally on the client
thanks!
z

zwass

03/02/2018, 4:49 PM
Sweet, glad you worked it out! You can of course configure logs to be stored on the local machine, but part of the advantage of Fleet is that it aggregates the logs onto a single machine for you.
👍 1
s

stefanmaerz

03/02/2018, 4:54 PM
I actually much prefer them on the fleet server. Makes my deployment much easier since I don't have to worry about collecting logs from 4000 endpoints
z

zwass

03/02/2018, 5:06 PM
We totally agree 🙂