I'm using a 7.13 stack with 7.13 Elastic Agents on multiple machines. I have the OSQuery Manager Integration installed (v. 0.2.3) and applied a respective policy to three Agents (2x Ubuntu 20.04, 1x Windows Server 2019).
When I run live queries, they either don't reach the targets or don't come back to Kibana (stuck on pending) - I'm not sure what's happening and would need some assistance as to where to start debugging.
On one Linux host, queries sometimes work, on the other two hosts they have never come back successfully, ever. I'm using the simple query "SELECT * FROM os_version;".
I have confirmed that osqueryd and osquerybeat are running on the hosts. The hosts also appear "green" in the live query host selector.
Some log files from the host that does work occasionally:
I0527 17:27:18.444630 702059 eventfactory.cpp:156] Event publisher not enabled: BPFEventPublisher: Publisher disabled via configuration I0527 17:27:18.444713 702059 eventfactory.cpp:156] Event publisher not enabled: auditeventpublisher: Publisher disabled via configuration I0527 17:27:18.444742 702059 eventfactory.cpp:156] Event publisher not enabled: inotify: Publisher disabled via configuration I0527 17:27:18.444759 702059 eventfactory.cpp:156] Event publisher not enabled: syslog: Publisher disabled via configuration
there's nothing else in this logfile.
<install_path>/data/elastic-agent-054e22/install/osquerybeat-7.13.0-linux-x86_64/osquery/osqueryd.results.log is empty on every host.