Skip to content

Instantly share code, notes, and snippets.

View yuvalapidot's full-sized avatar

Yuval Lapidot yuvalapidot

View GitHub Profile
@yuvalapidot
yuvalapidot / osqueryd.log
Created April 10, 2018 07:35
log of the osqueryd process showing the bug in 'services' distributed query
(On End-Point)
C:\ProgramData\osquery\osqueryd\osqueryd.exe --enroll_secret_path C:\ProgramData\osquery\enroll-secret --tls_server_certs C:\ProgramData\osquery\fleet-lnx.pem --pidfile C:\ProgramData\osquery\osqueryd.pidfile --database_path C:\ProgramData\osquery\osquery.db --verbose --tls_dump --flagfile C:\ProgramData\osquery\osquery.flags > osqueryd.log
I0404 05:56:16.944069 7540 init.cpp:380] osquery initialized [version=2.11.2]
I0404 05:56:16.975721 7540 system.cpp:344] Found stale process for osqueryd (7760)
I0404 05:56:16.975721 7540 system.cpp:377] Writing osqueryd pid (5064) to C:\ProgramData\osquery\osqueryd.pidfile
I0404 05:56:16.975721 7540 extensions.cpp:300] Could not autoload extensions: Failed reading: \ProgramData\osquery\extensions.load
I0404 05:56:17.256268 6512 watcher.cpp:549] osqueryd watcher (5064) executing worker (5004)
I0404 05:56:17.271912 824 init.cpp:377] osquery worker initialized [watcher=5064]
I0404 05:56:17.303719 824 rocksdb.cpp:132] Opening RocksDB handle: C:\Progra