[DOCS] Osquery doc bugs in 8.6 (#148767)
Co-authored-by: Joe Peeples <joe.peeples@elastic.co> Co-authored-by: gchaps <33642766+gchaps@users.noreply.github.com> Fixes https://github.com/elastic/kibana/issues/148728
BIN
docs/osquery/images/case-button-osquery.png
Normal file
After Width: | Height: | Size: 1.4 KiB |
BIN
docs/osquery/images/discover-button-osquery.png
Normal file
After Width: | Height: | Size: 3.6 KiB |
Before Width: | Height: | Size: 184 KiB After Width: | Height: | Size: 290 KiB |
BIN
docs/osquery/images/lens-button-osquery.png
Normal file
After Width: | Height: | Size: 3.6 KiB |
Before Width: | Height: | Size: 416 KiB After Width: | Height: | Size: 345 KiB |
BIN
docs/osquery/images/view-osquery-details.png
Normal file
After Width: | Height: | Size: 674 B |
|
@ -54,7 +54,13 @@ image::images/enter-query.png[Select saved query dropdown name showing query nam
|
|||
+
|
||||
TIP: To save a single query for future use, click *Save for later* and define the ID, description, and other <<osquery-manage-query,details>>.
|
||||
|
||||
. Review the results. Next, navigate to *Discover* to dive deeper into the response or to *Lens* to create visualizations.
|
||||
. Review the results and do any of the following:
|
||||
|
||||
** Click *View in Discover* (image:images/discover-button-osquery.png[View in Discover icon,20,20]) to explore the results in *Discover*.
|
||||
** Click *View in Lens* (image:images/lens-button-osquery.png[View in Lens icon,20,20]) to navigate to *Lens*, where you can use the drag-and-drop *Lens* editor to create visualizations.
|
||||
** Click *Add to Case* (image:images/case-button-osquery.png[Add to Case icon,20,20]) to add the query results to a new or existing case.
|
||||
** Click the view details icon (image:images/view-osquery-details.png[View details icon,20,20]) to examine the query ID and statement.
|
||||
|
||||
. To view more information about the request, such as failures, open the *Status* tab.
|
||||
|
||||
[float]
|
||||
|
|