Simple Docker-based quickstart for osquery, Fleet, and ELK stack
Check out fleetctl preview
for a one-step solution to try out Fleet and osquery. It uses the configuration files in this repository to run Fleet and the necessary dependencies in Docker.
IMPORTANT:
master
branch is used by fleetctl
before version 4.5.0 and should not change anymore except for critical fixes.develop
.production
.To make changes to this repository:
develop
.fleetctl preview --preview-config <branch>
with that branch, make sure everything works.develop
branch.If there are no changes on the develop
branch since last release, simply use: fleetctl preview
.
If there are changes on the develop
branch since last release:
fleetctl preview --preview-config develop
.develop
to the production
branch at which point every fleetctl preview
(version 4.5+) user will retrieve it.