-
Notifications
You must be signed in to change notification settings - Fork 360
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Possible issue with ATC tables in osquery 5.12.1? #18490
Comments
ATC tables fixed, |
@xpkoala did you test this with fleetd or plain osquery? Per discussion in osquery slack (https://osquery.slack.com/archives/C6PNW4528/p1714580512141179?thread_ts=1713984325.377259&cid=C6PNW4528) this may only be triggered if there's a table extension also registered (which would be the case with fleetd but not plain osquery). |
FWIW osquery/osquery#8323 |
@xpkoala can you please re-test with the information discussed in the osquery Slack to try to reproduce? |
@zwass ahh, sorry for missing this yesterday, I'll jump on it in a moment. FWIW I did test with fleetd originally. |
@zwass Given 5.12.2 draft release is out (which just reverts the related change - osquery/osquery@5.12.1...5.12.2), do we still need to reproduce? |
I think it's worthwhile to test still as we would want to see whether 5.12.1 actually has issues in our deployments and if 5.12.2 fixes those. |
The following was tested with @lucasmrod and no complications were seen getting results from tables created with ATC:
|
(Another way to try to reproduce: vanilla osquery + fleetd_tables extension.) |
Closing the bug per this thread. https://fleetdm.slack.com/archives/C019WG4GH0A/p1715278510072879 |
ATC tables fixed, |
Osquery 5.12.1
💥 Actual behavior
(Reported from @directionless at Kolide)
Apparently Kolide has found that their ATC tables are no longer registering with osquery 5.12.1. They do some special things with config plugins, so the issue may be isolated to their setup.
🧑💻 Steps to reproduce
Not sure exactly, but let's try to reproduce this using the standard way that we configure ATC tables (through agent options). If that works fine, let's close out this issue and let Kolide continue investigating their special case. If we do reproduce the issue let's work with osquery to get things fixed.
🕯️ More info (optional)
N/A
The text was updated successfully, but these errors were encountered: