zen
01/08/2019, 1:21 AMDaveW
01/08/2019, 9:06 PMharveywells
01/08/2019, 9:44 PM86400
(once a day) and just before the query is set to run, the computer goes offline for x number of days...how does the daemon handle rescheduling the query when it’s back up?nyanshak
01/09/2019, 5:04 PMAlan
01/09/2019, 7:55 PMBlake Golliher
01/09/2019, 9:55 PMreed
01/10/2019, 2:27 AM钢铁侠
01/10/2019, 11:10 AMkrisrice
01/10/2019, 3:03 PMsamuel
01/11/2019, 7:08 PMb0l
01/11/2019, 10:52 PMGuillaume
01/15/2019, 1:40 AMpritchardtw
01/16/2019, 1:44 AMJB
01/16/2019, 4:25 PMHostname:osquery root# sudo osqueryctl start --config_path=/var/osquery/osquery.conf
I0116 16:22:03.214370 2890367872 database.cpp:564] Checking database version for migration
Error reading config: Error parsing the config JSON
This is my osquery.conf:
Hostname:osquery root# cat osquery.conf
{
"options": {
"config_plugin": "/var/osquery/osquery.conf",
"logger_plugin": "filesystem",
"logger_path": "/var/log/osquery",
"disable_logging": "false",
"schedule_splay_percent": "10",
"database_path": "/var/osquery/osquery.db",
#"disable_tables": "foo_bar,time",
"utc": "true"
},
"schedule": {
"system_info": {
"query": "SELECT hostname, cpu_brand, physical_memory FROM system_info;",
"interval": 3600
},
"usb_devices": {
"query": "SELECT vendor, model FROM usb_devices;",
"interval": 60
}
},
"decorators": {
"load": [
"SELECT uuid AS host_uuid FROM system_info;",
"SELECT user AS username FROM logged_in_users ORDER BY time DESC LIMIT 1;"
]
},
# Linux: /usr/share/osquery/packs
# OS X: /var/osquery/packs
# Homebrew: /usr/local/share/osquery/packs
# make install: {PREFIX}/share/osquery/packs
"packs": {
# "osquery-monitoring": "/usr/share/osquery/packs/osquery-monitoring.conf",
# "incident-response": "/usr/share/osquery/packs/incident-response.conf",
# "it-compliance": "/usr/share/osquery/packs/it-compliance.conf",
# "osx-attacks": "/usr/share/osquery/packs/osx-attacks.conf",
# "vuln-management": "/usr/share/osquery/packs/vuln-management.conf",
# "hardware-monitoring": "/usr/share/osquery/packs/hardware-monitoring.conf",
# "ossec-rootkit": "/usr/share/osquery/packs/ossec-rootkit.conf",
# "windows-hardening": "C:\\ProgramData\\osquery\\packs\\windows-hardening.conf",
# "windows-attacks": "C:\\ProgramData\\osquery\\packs\\windows-attacks.conf"
},
}
Any ideas?robusto
01/16/2019, 4:56 PMconfig_plugin
should be filesystem
and the config_path
should be the file path ... or added as flags and not set here at all since we're already in the .conf file 🤔Saw Klaus
01/17/2019, 5:41 AMLuf
01/17/2019, 12:43 PMrobusto
01/17/2019, 6:54 PMsudo osqueryi
doesn't seem to be showing actual configuration in .show/.summarycsjp
01/19/2019, 5:51 PMNot using buckd because watchman isn't installed.
Exception in thread "main" java.lang.ClassNotFoundException: com.facebook.buck.cli.Main
at java.net.URLClassLoader.findClass(URLClassLoader.java:382)
at java.lang.ClassLoader.loadClass(ClassLoader.java:424)
at java.lang.ClassLoader.loadClass(ClassLoader.java:357)
at com.facebook.buck.cli.bootstrapper.ClassLoaderBootstrapper.main(ClassLoaderBootstrapper.java:53)
Prakhar
01/21/2019, 7:57 AMsean.cavanaugh
01/21/2019, 7:55 PMPrakhar
01/22/2019, 7:21 AM钢铁侠
01/22/2019, 8:35 AMzwass
groob
groob
yuvalapidot
01/27/2019, 3:09 PMosquery_schedule
table, there I can see the blacklisted
column - which I assume, if it is 1
it means that the watchdog had stopped it the time before, but is this the only indication for the watchdog stoping a query?
Lastly, is the watchdog killing osquery when all queries are using too much resources, or is it stopping a specific query that is using too many resources? in other words - are other queries which are frequently scheduled with a large query in danger being aborted?钢铁侠
01/28/2019, 5:11 AMnick
01/28/2019, 11:44 AMnpamnani
01/29/2019, 5:10 AM