wennan.he
12/28/2022, 12:38 AMMikhail
12/29/2022, 1:44 PMnick fury
12/31/2022, 4:35 PMpeanut butter
01/01/2023, 7:20 PMwennan.he
01/02/2023, 11:26 PMOjas
01/03/2023, 9:42 AMtoby1knby
01/03/2023, 1:16 PMMacAdmins osquery extension which comes conveniently bundled with Fleet's osquery installers by default
However - when i try to pull from the unified log table in fleetdm, I get a "No platforms (check your query for invalid tables or tables that are supported on different platforms)"
Any pointers on what I am doing wrong, or am I just completely missing the point?
Thanks in advance for any light you can shed om this.Zapier
01/03/2023, 7:41 PMDherder
01/03/2023, 9:11 PMAdrian Junge
01/04/2023, 10:58 AMRyan Pesek
01/05/2023, 9:23 PMtls_client_cert
and tls_client_key
set in our environment to enforce mTLS on all API calls the agent makes. However the paths to these certificate files need to change depending on if the host in MacOS or Windows. It doesn't appear to be possible to set multiple values for these config options because according to the docs command_line_flags
does not support the overrides
key.peanut butter
01/06/2023, 2:25 PMpeanut butter
01/06/2023, 7:08 PMdefensivedepth
01/06/2023, 9:36 PMZapier
01/06/2023, 11:09 PMroberto
01/09/2023, 11:13 AMReza Kazemy
01/09/2023, 2:39 PMJesus Santos
01/09/2023, 2:44 PMArsenio
01/09/2023, 4:20 PMwennan.he
01/10/2023, 12:28 AMLucas Rodriguez
01/10/2023, 12:14 PMKathy Satterlee
01/10/2023, 5:08 PMpeanut butter
01/10/2023, 7:14 PMwennan.he
01/10/2023, 11:31 PMwennan.he
01/11/2023, 12:39 AMorbit_info
SELECT
on every distributed/read
(we could alternatively add some small interval for this specific query, if need be). We will use the cached_mysql to not perform unnecessary token insertions on every distributed/write
. Also token updating should do a INSERT ON DUPLICATE KEY token=token
, and not update updated_at
.
is this supposed to work out only osquery is hosted in orbit? if we don'r run osquery by orbit, this return info doesn't impact, is my understand correct?Arsenio
01/11/2023, 2:06 PMArsenio
01/11/2023, 3:11 PMShend Saliaga
01/11/2023, 3:59 PMfleet db prepare
more than once should not cause any additional changes other than the first time it runsAlex Loewenthal
01/11/2023, 7:19 PMSELECT EXISTS(SELECT * FROM system_info WHERE board_model not in ('VirtualBox', 'Parallels Virtual Platform') AND (select 1 from disk_encryption WHERE encrypted = '1' AND name like '/dev/dm-1')) as is_desktop_encrypted;
pvirani
01/11/2023, 8:04 PM/var/log/osquery/osqueryd.results.log
on the host. see the example log line from it below
{
"name": "pack/osquery_monitoring/schedule",
"hostIdentifier": "ip-172-31-55-24",
"calendarTime": "Wed Jan 11 19:46:37 2023 UTC",
"unixTime": 1673466397,
"epoch": 0,
"counter": 0,
"numerics": false,
"decorations": {
"host_uuid": "ec2fb435-c38c-9e86-d043-106a4c7ec832",
"hostname": "ip-172-31-55-24.us-west-2.compute.internal"
},
"columns": {
"average_memory": "0",
"avg_system_time": "",
"avg_user_time": "",
"executions": "0",
"interval": "86400",
"last_executed": "0",
"name": "pack/it_compliance/iptables",
"output_size": "0",
"wall_time": "0"
},
"action": "added"
}
• On the Fleet Webserver cat osquery_status -f
shows the last query execution to have happened in August 2022 🙀
{
"hostIdentifier": "ip-172-31-23-127",
"calendarTime": "Fri Aug 26 18:54:26 2022 UTC",
"unixTime": "1661540066",
"severity": "2",
"filename": "scheduler.cpp",
"line": "118",
"message": "Error executing scheduled query pack/osx_attacks/OSX_Mughthesec: no such table: launchd",
"version": "5.2.2",
"decorations": {
"host_uuid": "EC2C455A-F709-B975-ADA7-C33DE9F7EABA",
"hostname": "ip-172-31-23-127.us-west-2.compute.internal"
}
}
Where do I even begin debugging?