• b

    Beckel

    2 years ago
    We're seeing OSQuery us a lot of bandwidth up for our home users which we have narrowed down to a configuration issue with one of the intervals. Do you have a recommendation for configuring
    distributed_interval
    and
    logger_tls_period
    if our main focus is to only us Fleet as a TLS Aggregrator and not ask questions?
  • zwass

    zwass

    2 years ago
    More than likely your bandwidth is going to the logging. Changing that interval is only going to have a very modest effect on throughput, because it will only effect how often the logs are sent, not how many logs are sent. You will get some additional savings from increasing
    distributed_interval
    and
    config_refresh
    .
  • s

    seph

    2 years ago
    What Zach said. If you want to see that differently, If you can tell which direction, that will tell you more. Bandwidth from the server to the client, is likely configuration refresh. Bandwidth from the client to the server, is likely to be logs.