Replies: 2 comments 3 replies
-
What Security Onion version are you running? |
Beta Was this translation helpful? Give feedback.
2 replies
-
Live Queries only show up in the FleetDM Web interface. Scheduled query results will be stored in Elasticsearch & available to view via Hunt or Kibana. With the upcoming 2.4 release, both Live Query results & scheduled query results will be viewable in Hunt. |
Beta Was this translation helpful? Give feedback.
1 reply
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
Hello,
I'm starting to work on using Osquery for automating hunts and then having the logs it produces inspected via rules somehow. Initially looking at using Elastalert.
When I run a query via Fleet I get results in that web Gui but I cannot see the logs in Kibana. I've looked at how logs flow from Osquery to Kibana but coming up empty. I do see some Osquery logs in Kibana but no logs generated by my queries. Not seeing any of my queries' logs in
/nsm/osquery/fleet/result.log
.I feel like I'm missing something simple, and I apologize if I am. This is the first time I've worked with Osquery in quite some time.
thanks for any help
Beta Was this translation helpful? Give feedback.
All reactions