Fleet uses osquery tables to query operating system, hardware, and software data. Each table provides specific data for analysis and filtering.
puppet_logs
Outputs Puppet logs from the last run.
Column | Type | Description |
---|---|---|
file | text | The file from which osquery read this log. |
level | text | The level of the log item (info, error, etc). |
line | text | The line from which this log item was read. |
message | text | The log message content. |
source | text | The source of the log item. |
time | text | The time at which this item was logged. |
List Puppet logs that are of a level of anything but informational.
SELECT * FROM puppet_logs WHERE level!='info';
This table is from the Mac Admins osquery extension.