unfortunately, I managed to break my OSQuery integrations again.
A simple query like
SELECT * FROM os_version; yields the error message
matching app is not found for action input: osquery for most of my hosts.
Edit: The error message shows up in the "error" column of the query results in Kibana.
I did some trial and error, and it seems that the error shows up as soon as the endpoint integration is added to the host:
I have two policies that are identical except for the endpoint integration. When I assign the one with endpoint integration to the host, I get the error message. As soon as I remove the endpoint integration, osquery results work again for this host.
This is the case across 7.15 and 7.16.
The cluster is on 7.16.1 (incl. fleet server). Integration versions involved:
- Endpoint 1.2.2
- OSquery manager 0.8.0
The logs in
C:\Program Files\Elastic\Agent\data\elastic-agent-4bcd95\logs\default\osquerybeat-json.log don't show anything related to queries, just start/stop of the service and connecting to Elasticsearch.
Any tips on where to search further?