Let's start with something very basic. How did you install the osquery agent? Msi? Choco? Something else?
z
Zafar
07/01/2019, 3:55 PM
installed it via .ms package
*.msi
Downloaded this .msi package and installed it manually on my windows 10 laptop.
Wazuh agent is also running on the same machine that is configured to pick and forward osquery alerts to wazuh-manager
g
Guy
07/02/2019, 10:03 AM
what's in your config.flag file?
z
Zafar
07/04/2019, 3:40 PM
Nothing, it's empty with 0 byte data
osquery.flags --> 0 KB
g
Guy
07/09/2019, 2:53 PM
Oops, forgot about this. Well you need to populate that file with your server details