Home
Docs
Join the conversation
Join Slack
Channels
# arm-architecture
# code-review
# core
# ebpf
# eclecticiq-polylogyx-extension
# extensions
# file-carving
# fleet
# foundation
# general
# golang
# kolide
# linux
# macos
# officehours
# osctrl
# plugins
# process-auditing
# sql
# website
# windows
# zeek
Powered by Linen
Channels
arm-architecture
code-review
core
ebpf
eclecticiq-polylogyx-extension
extensions
file-carving
fleet
foundation
general
golang
kolide
linux
macos
officehours
osctrl
plugins
process-auditing
sql
website
windows
zeek
Topic
Authors
Views
Replies
Activity
Share
That's what I thought, I was hoping there'd be some sort of ability to track a "heartbeat" with osquery, but realizing the fallacy of using a system to check it's own health is sort of a :lolwut:
s
0
2
2 years ago
Copy to Clipboard
@Phuc Duong
hi! could you check you don’t have a space after each line in the flagfile? If you check the error closely each value seems to have been read with a space in it.
d
0
4
2 years ago
Copy to Clipboard
Anyone use osquery in k8s at all?
z
1
4
2 years ago
Copy to Clipboard
#general
how much time it takes an server to show up in fleet?In my case it keeps on stating adding new host
s
1
2
2 years ago
Copy to Clipboard
This message was deleted.
s
1
4
2 years ago
Copy to Clipboard
Need some noobie help. I0412 14:08:38.742949 11449 tls.cpp:253] TLS/HTTPS POST request to URI:
https://localhost:8080/api/v1/osquery/enroll
W0412 14:08:38.750748 11449 tls_enroll.cpp:76] Failed enrollment request to <...
x
0
4
2 years ago
Copy to Clipboard
@Prateek Kumar Nischal
that event will never be picked up unless osquery is updated to parse it
You can start by updating the following files: osquery/tables/events/linux/process_events.cpp osquery/events/linux/process_events....
a
1
1
2 years ago
Copy to Clipboard
Been wondering for a while - since i know osqpery is meant to be turned to what you ultimately want for it (why waste resources) - but is there a best of breed most people adopt? I am thinking the SwiftOnSecurity Sysmon...
d
0
3
2 years ago
Copy to Clipboard
Hello. I'm trying to collect user based events, specifically failed login attempts. My user_events table is empty and I see this when I query the table: "Table user_events is event-based but events are disabled". How d...
a
4
3
2 years ago
Copy to Clipboard
On my AWS slack pluralsight put up the free april link
http://pluralsight.com/offer/2020/free-april-month
and they got a osquery class - not sure how good, no reviews - but its there : ?
https://app.pluralsight.com/li...
d
1
3
2 years ago
Copy to Clipboard
z
That's what I thought, I was hoping there'd be some sort of ability to track a "heartbeat" with osquery, but realizing the fallacy of using a system to check it's own health is sort of a :lolwut:
2 Replies
2 years ago
@Phuc Duong
hi! could you check you don’t have a space after each line in the flagfile? If you check the error closely each value seems to have been read with a space in it.
4 Replies
2 years ago
z
Anyone use osquery in k8s at all?
4 Replies
2 years ago
t
#general
how much time it takes an server to show up in fleet?In my case it keeps on stating adding new host
2 Replies
2 years ago
s
This message was deleted.
4 Replies
2 years ago
s
Need some noobie help. I0412 14:08:38.742949 11449 tls.cpp:253] TLS/HTTPS POST request to URI:
https://localhost:8080/api/v1/osquery/enroll
W0412 14:08:38.750748 11449 tls_enroll.cpp:76] Failed enrollment request to <...
4 Replies
2 years ago
a
@Prateek Kumar Nischal
that event will never be picked up unless osquery is updated to parse it
You can start by updating the following files: osquery/tables/events/linux/process_events.cpp osquery/events/linux/process_events....
1 Replies
2 years ago
d
Been wondering for a while - since i know osqpery is meant to be turned to what you ultimately want for it (why waste resources) - but is there a best of breed most people adopt? I am thinking the SwiftOnSecurity Sysmon...
3 Replies
2 years ago
Hello. I'm trying to collect user based events, specifically failed login attempts. My user_events table is empty and I see this when I query the table: "Table user_events is event-based but events are disabled". How d...
3 Replies
2 years ago
d
On my AWS slack pluralsight put up the free april link
http://pluralsight.com/offer/2020/free-april-month
and they got a osquery class - not sure how good, no reviews - but its there : ?
https://app.pluralsight.com/li...
3 Replies
2 years ago
Previous
1
2
3
...
70
71
72
...
118
119
120
Next