Bit_by_bit
07/11/2018, 10:48 PMyuvalapidot
07/12/2018, 6:29 AMC:\ProgramData\osquery
as @thor metioned, or under your installation folder (if you didn't install osquery in its default path), please copy & rename the file to osquery.config and use it. Also, afaik, you can use the --config_path flag when your run osqueryd to choose from where you read the config file.Bit_by_bit
07/12/2018, 3:44 PMthor
07/12/2018, 4:09 PMosquery.flags
, which specifies all of these things, there's some more information about deployments on our readthedocs (https://osquery.readthedocs.io/en/stable/deployment/configuration/) but there's not something you can set for the config_path
to be always set, you'll need to setup a flagsfile that works for you and deploy it in some uniform way like with Chef or Puppet