-
-
Notifications
You must be signed in to change notification settings - Fork 2.4k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Set packs using the Remote Settings API #3381
Comments
Hey @thedrow, want to clarify a bit, do you mean you cannot affect the schedule or configured packs via the 'distributed' query endpoints? |
It seems that the distributed API does not allow to set the packs configured for an osqueryd process. The API only affects the schedule. |
If you use remote configuration you can do this though correct? Remote configuration can also be set to update periodically. |
I am using remote configuration. Packs are not being set. |
I'd like to bump this issue. I've been trying to configure packs using the TLS configuration, and the client logs these requests as:
While if you'd use the exact same osquery.conf from filesystem it functions fine. |
Bumping this issue since I am experimenting the same issue. Running osquery Configuration used:
While using the local configuration and provided with
While using TLS plugin to deliver the same configuration, the error is the same as mentioned above:
Note that using the content of those files, and just pasting it as a JSON object, to be delivered as configuration, it works as expected so it must be a problem with reading the external file. |
The Remote Settings API only allows to either schedule queries to be executed immediately or using the schedule.
You cannot activate or deactivate query packs using the Remote Settings API AFAICT.
This feature should be supported.
The text was updated successfully, but these errors were encountered: