# Fleet Deploy OSQuery to Windows

**URL:** <https://discuss.elastic.co/t/fleet-deploy-osquery-to-windows/356301>\
**Category:** SIEM\
**Tags:** osquery-manager\
**Created:** [March 27, 2024, 3:15pm UTC](https://discuss.elastic.co/t/fleet-deploy-osquery-to-windows/356301 "2024-03-27T15:15:31Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![sourcreamnormanbates](https://avatars.discourse-cdn.com/v4/letter/s/f05b48/32.png) [@sourcreamnormanbates](https://discuss.elastic.co/u/sourcreamnormanbates)\
**Post date:** [March 27, 2024, 3:15pm UTC](https://discuss.elastic.co/t/fleet-deploy-osquery-to-windows/356301/1 "2024-03-27T15:15:31Z")

</div>

I have successfully deployed both OSQuery manager and one agent to a Linux machine.  
However; my deployment to a Windows box doesn't seem to be working.  
I believe it's because the log path needs to be modified to something suitable to Windows.

This is the default value: /var/log/osquery/osqueryd.results.log\*

---

<div class="post-metadata">

**Author:** ![wsouza](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wsouza/32/92547_2.png) [@wsouza](https://discuss.elastic.co/u/wsouza)\
**Post date:** [April 2, 2024, 7:49pm UTC](https://discuss.elastic.co/t/fleet-deploy-osquery-to-windows/356301/2 "2024-04-02T19:49:35Z")

</div>

Hi, @sourcreamnormanbates

When installing the Elastic Agent on the Windows host, did you use administrator permissions at the command prompt? I recommend creating an inbound rule in the Windows Firewall for the Elastic Agent. In some situations, Windows Firewall blocks remote communications.

What version of Windows? On this host, is there any endpoint protection solution such as antivirus?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [April 2, 2024, 8:12pm UTC](https://discuss.elastic.co/t/fleet-deploy-osquery-to-windows/356301/3 "2024-04-02T20:12:17Z")

</div>

> [@sourcreamnormanbates](#):
>
> I believe it's because the log path needs to be modified to something suitable to Windows.

Which integration are you using? _Osquery Logs_ or _Osquery Manager_?

The first one requires that you already have osquery installed on the host and will collect the logs for it, the second one will use the osqueryd that is shipped with the agent and allows you to run queries directly from Kibana.

---

<div class="post-metadata">

**Author:** ![sourcreamnormanbates](https://avatars.discourse-cdn.com/v4/letter/s/f05b48/32.png) [@sourcreamnormanbates](https://discuss.elastic.co/u/sourcreamnormanbates)\
**Post date:** [April 17, 2024, 1:24pm UTC](https://discuss.elastic.co/t/fleet-deploy-osquery-to-windows/356301/4 "2024-04-17T13:24:35Z")

</div>

OK that worked now that I understand the difference between the two.  
For some reason I thought "Logs" was a client and "Manager" was the server side.  
I guess I overcomplicated things.  
Thanks for the reply, this will be a great addition to our DFIR capability.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 15, 2024, 1:24pm UTC](https://discuss.elastic.co/t/fleet-deploy-osquery-to-windows/356301/5 "2024-05-15T13:24:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
