diff --git a/nixos/modules/services/monitoring/osquery.nix b/nixos/modules/services/monitoring/osquery.nix index 2b14c2dd89fb..003407626c8a 100644 --- a/nixos/modules/services/monitoring/osquery.nix +++ b/nixos/modules/services/monitoring/osquery.nix @@ -63,16 +63,30 @@ in freeformType = attrsOf str; options = { database_path = lib.mkOption { - default = "osquery/osquery.db"; + default = "/var/lib/osquery/osquery.db"; readOnly = true; - description = "Path used for the database file, relative to /var/lib/."; - type = nonEmptyStr; + description = '' + Path used for the database file. + + ::: {.note} + If left as the default value, this directory will be automatically created before the + service starts, otherwise you are responsible for ensuring the directory exists with + the appropriate ownership and permissions. + ''; + type = path; }; logger_path = lib.mkOption { - default = "osquery"; + default = "/var/log/osquery"; readOnly = true; - description = "Base directory used for logging, relative to /var/log/."; - type = nonEmptyStr; + description = '' + Base directory used for logging. + + ::: {.note} + If left as the default value, this directory will be automatically created before the + service starts, otherwise you are responsible for ensuring the directory exists with + the appropriate ownership and permissions. + ''; + type = path; }; pidfile = lib.mkOption { default = "/run/osquery/osqueryd.pid"; @@ -96,8 +110,8 @@ in serviceConfig = { ExecStart = "${pkgs.osquery}/bin/osqueryd --flagfile ${flagfile}"; PIDFile = cfg.flags.pidfile; - LogsDirectory = cfg.flags.logger_path; - StateDirectory = dirname cfg.flags.database_path; + LogsDirectory = lib.mkIf (cfg.flags.logger_path == "/var/log/osquery") [ "osquery" ]; + StateDirectory = lib.mkIf (cfg.flags.database_path == "/var/lib/osquery/osquery.db") [ "osquery" ]; Restart = "always"; }; wantedBy = [ "multi-user.target" ];