[DOCS] Osquery doc bugs in 8.6 (#148767)

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>
Co-authored-by: gchaps <33642766+gchaps@users.noreply.github.com>
Fixes https://github.com/elastic/kibana/issues/148728
This commit is contained in:
nastasha-solomon 2023-01-18 11:06:11 -05:00 committed by GitHub
parent 74d93211ab
commit bcd4260154
No known key found for this signature in database
GPG key ID: 4AEE18F83AFDEB23
7 changed files with 7 additions and 1 deletions

Binary file not shown.

After

Width:  |  Height:  |  Size: 1.4 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 3.6 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 184 KiB

After

Width:  |  Height:  |  Size: 290 KiB

Before After
Before After

Binary file not shown.

After

Width:  |  Height:  |  Size: 3.6 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 416 KiB

After

Width:  |  Height:  |  Size: 345 KiB

Before After
Before After

Binary file not shown.

After

Width:  |  Height:  |  Size: 674 B

View file

@ -54,7 +54,13 @@ image::images/enter-query.png[Select saved query dropdown name showing query nam
+
TIP: To save a single query for future use, click *Save for later* and define the ID, description, and other <<osquery-manage-query,details>>.
. Review the results. Next, navigate to *Discover* to dive deeper into the response or to *Lens* to create visualizations.
. Review the results and do any of the following:
** Click *View in Discover* (image:images/discover-button-osquery.png[View in Discover icon,20,20]) to explore the results in *Discover*.
** Click *View in Lens* (image:images/lens-button-osquery.png[View in Lens icon,20,20]) to navigate to *Lens*, where you can use the drag-and-drop *Lens* editor to create visualizations.
** Click *Add to Case* (image:images/case-button-osquery.png[Add to Case icon,20,20]) to add the query results to a new or existing case.
** Click the view details icon (image:images/view-osquery-details.png[View details icon,20,20]) to examine the query ID and statement.
. To view more information about the request, such as failures, open the *Status* tab.
[float]