Ojas
Luke Heath
Lucas Rodriguez
logger_plugin
is for osquery result
(scheduled queries results) and osquery status
logs.
If you are interested on osquery logs in general, you can check the following paths:https://github.com/fleetdm/fleet/tree/main/orbit#logs
(Both Orbit and osquery logs should be in those locations.)Ojas
Lucas Rodriguez
filesystem
from logger_plugin
(and just leave tls
or empty until the new release is out).Ojas
Lucas Rodriguez
Ojas
Lucas Rodriguez
Do i need to generate a new installer? No, should auto-update.
Also now i see another older issue, my fleet_osquery service in windows keeps stopping. Could you check
C:\Windows\system32\config\systemprofile\AppData\Local\FleetDM\Orbit\Logs\orbit-osquery.log
? (You may be hitting a known issue we are trying to fix for next release.)Ojas
Lucas Rodriguez
"C:\Program Files\Orbit\bin\orbit\orbit.exe" --version
?
Could not create file: \Program Files\osquery\log\osqueryd.results.log On the latest version we changed the path, that looks like the old default path.
Ojas
Lucas Rodriguez
Ojas
Lucas Rodriguez
C:\Windows\system32\config\systemprofile\AppData\Local\FleetDM\Orbit\Logs\orbit-osquery.log
)?how do i check that? Try visiting the URL from a browser in the host, or using the
curl
or wget
commands (if available).Ojas
Lucas Rodriguez
filesystem
logger configuration from Fleet temporarily? (to give the process a chance to auto-update)Ojas
Lucas Rodriguez
tls
.Ojas
Lucas Rodriguez
filesystem
in its internal rocksdb local storage..., but let's see if this helps.Ojas
Lucas Rodriguez
msi
installer and re-install Orbit.Ojas
Lucas Rodriguez
Ojas
Lucas Rodriguez
filesystem
change is still not working.Ojas
Lucas Rodriguez