Shane Sanborn
01/28/2022, 7:45 PM2022-01-28_15.38.41 INFO plgx_win_extension.ext.cpp:601: ##### EclecticIQ Osquery Extension v3.0.0.0 #####
2022-01-28_15.38.44 INFO plgx_win_extension.ext.cpp:699: distributed_tls_plugin is tls
2022-01-28_15.38.44 ERROR plgx_win_extension.ext.cpp:739: Failed retrieving Kernel state from osqueryd config. Error: 2 (The system cannot find the file specified.
)
2022-01-28_15.38.44 INFO plgx_extension_watcher.cpp:41: Watcher Thread starting..
2022-01-28_15.38.44 ERROR plgx_load_unload_vast_driver.cpp:34: Driver-Init Failed: 1056
2022-01-28_15.38.44 ERROR plgx_load_unload_vast_driver.cpp:34: Driver-Init Failed: 1056
2022-01-28_15.38.44 ERROR plgx_win_extension.ext.cpp:761: Driver Load Failed Again
2022-01-28_15.38.44 INFO plgx_win_extension.ext.cpp:780: Polylogyx plugin not found. Creating Config thread to refresh config
2022-01-28_15.38.44 INFO plgx_win_extension.ext.cpp:784: config_tls_plugin is filesystem
Any help would be appreciated thanks!himanshu
01/29/2022, 6:42 AMsc stop vast
2. sc stop vastnw
then load your extension again. Please let us know if that worked for you.
also i see you are running version 3.0.0.0 which is outdated. If possible, it would be great if you could try the latest extension 3.0.1 available here with new features and bug fixes:
https://github.com/eclecticiq/osq-ext-binOpenPlgx
01/29/2022, 8:53 AMShane Sanborn
01/31/2022, 6:50 PM2022-01-31_20.25.53 INFO plgx_win_extension.ext.cpp:632: ##### EclecticIQ Osquery Extension v3.0.1.0 #####
2022-01-31_20.25.57 INFO plgx_win_extension.ext.cpp:730: distributed_tls_plugin is tls
2022-01-31_20.25.57 INFO plgx_win_extension.ext.cpp:771: Kernel services state from config not found. Error: 2 (The system cannot find the file specified.
). State will be set to ENABLED.
2022-01-31_20.25.57 INFO plgx_extension_watcher.cpp:41: Watcher Thread starting..
2022-01-31_20.25.57 INFO plgx_win_extension.ext.cpp:816: Polylogyx plugin not found. Creating Config thread to refresh config
2022-01-31_20.25.57 INFO plgx_win_extension.ext.cpp:820: config_tls_plugin is filesystem
2022-01-31_20.25.57 WARNING plgx_win_utils.cpp:1007: No event_filter found.
2022-01-31_20.25.57 INFO plgx_config_parser.cpp:170: Event controls (remove) stage crossed.
2022-01-31_20.25.57 INFO plgx_win_utils.cpp:1458: No event control (blocking) filter found in config.
2022-01-31_20.25.57 INFO plgx_config_parser.cpp:172: Event controls (apply) stage crossed.
2022-01-31_20.25.57 INFO plgx_config_parser.cpp:923: Config: key:: [utc] value:: [true]
2022-01-31_20.25.57 INFO plgx_config_parser.cpp:923: Config: key:: [custom_plgx_EnableSSL] value:: [true]
2022-01-31_20.25.57 INFO plgx_config_parser.cpp:923: Config: key:: [custom_plgx_EnableBlocking] value:: [true]
2022-01-31_20.25.57 INFO plgx_config_parser.cpp:923: Config: key:: [custom_plgx_EnableHttp] value:: [true]
2022-01-31_20.25.57 INFO plgx_config_parser.cpp:923: Config: key:: [custom_plgx_EnableDns] value:: [true]
2022-01-31_20.25.57 INFO plgx_config_parser.cpp:923: Config: key:: [custom_plgx_EnableShallowSSL] value:: [true]
OpenPlgx
02/01/2022, 3:52 AMhimanshu
02/07/2022, 4:51 AMicacls plgx_win_extension.ext.exe /grant "NT AUTHORITY\LocalService":R /Q
should resolve the issue.