Commit graph

21 commits

Author SHA1 Message Date
amyjtechwriter
2376129c78
[DOCS] Screenshot updated - Osquery (#160774)
## Summary

Updates a screenshot on the
[Osquery](https://www.elastic.co/guide/en/kibana/current/osquery.html)
page.

Closes: #154231
2023-06-29 11:05:07 +01:00
Aleksandr Maus
85b481bd38
Osquery: Update exported fields reference for osquery 5.7.0 (#150216)
## Summary

Update exported fields reference for osquery 5.7.0.

## Related PR

- Requires https://github.com/elastic/beats/pull/34468
- Requires https://github.com/elastic/integrations/pull/5175

Co-authored-by: Patryk Kopyciński <contact@patrykkopycinski.com>
2023-02-06 13:23:21 -05:00
Aleksandr Maus
ff39dca4a8
Osquery: Update exported fields reference for osquery 5.5.1 (#143754) 2023-02-02 11:17:17 -05:00
nastasha-solomon
bcd4260154
[DOCS] Osquery doc bugs in 8.6 (#148767)
Co-authored-by: Joe Peeples <joe.peeples@elastic.co>
Co-authored-by: gchaps <33642766+gchaps@users.noreply.github.com>
Fixes https://github.com/elastic/kibana/issues/148728
2023-01-18 11:06:11 -05:00
nastasha-solomon
d92e2f90bf
[DOCS] Option to schedule Osquery packs for individual policies or globally (#146482)
Addresses https://github.com/elastic/kibana/issues/146468.

Preview
[here](https://kibana_146482.docs-preview.app.elstc.co/guide/en/kibana/master/osquery.html#osquery-schedule-query)
(updated step 4).

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>
Co-authored-by: Kibana Machine <42973632+kibanamachine@users.noreply.github.com>
2022-12-16 14:39:58 -06:00
nastasha-solomon
61505e5edd
[8.5][DOCS] Add support for differential logs (#143242)
Co-authored-by: gchaps <33642766+gchaps@users.noreply.github.com>
2022-10-27 13:32:11 -04:00
nastasha-solomon
36abd986dd
[BUG] Osquery doc updates (#139583)
Co-authored-by: Joe Peeples <joe.peeples@elastic.co>
2022-09-30 14:52:36 -04:00
nastasha-solomon
201820d718
[DOCS] New option for users to run a query pack (#138853)
Co-authored-by: gchaps <33642766+gchaps@users.noreply.github.com>
2022-08-23 11:12:29 -04:00
Aleksandr Maus
a6c1b0f26d
Osquery: Update exported fields reference for osquery 5.4.0 (#137757)
Co-authored-by: Kibana Machine <42973632+kibanamachine@users.noreply.github.com>
2022-08-08 13:50:38 -04:00
Melissa Burpo
6f3c03abab
Osquery doc fixes (#135848)
* add fim link

* resolve doc issues
2022-07-06 16:42:21 -05:00
Melissa Burpo
b57ee29b66
Osquery 8.3 updates (#134965)
* note that query history list shows past 30 days

* revise query timeout note

* describe new saved queries available out of the box

* update images for UI changes in 8.3

* add osquery FAQ

* revise per team feedback

* simplify version check query

* add clarification about version updates

* describe how to enable the curl table

* fix link

* fix code block

* Apply suggestions from code review

Co-authored-by: gchaps <33642766+gchaps@users.noreply.github.com>

* address pr feedback

Co-authored-by: gchaps <33642766+gchaps@users.noreply.github.com>
2022-06-24 14:02:54 -05:00
Melissa Burpo
fb453aca45
Osquery pack attribution (#131462)
* add new reference page for prebuilt packs

* add link to new prebuilt pack ref page

* convert list to table

* add table close

* Apply suggestions from code review

Co-authored-by: gchaps <33642766+gchaps@users.noreply.github.com>

Co-authored-by: gchaps <33642766+gchaps@users.noreply.github.com>
2022-05-04 16:13:54 -05:00
Melissa Burpo
4ade036958
Osquery 8.2 updates (#130195)
* add exported fields reference docs

* move advanced content to main osquery page

* add info about prebuilt packs

* fix number formatting

* test table formatting fix

* simplify table styling

* edit column widths

* update column options

* Update fields formatting

* add steps for copying prebuilt pack

* add a section header for fields list

* Add redirect for removed advanced-osquery page

Co-authored-by: Kibana Machine <42973632+kibanamachine@users.noreply.github.com>
Co-authored-by: Aleksandr Maus <aleksandr.maus@elastic.co>
2022-04-27 17:02:01 -05:00
gchaps
72a5178179
[DOCS] Reorganizes Osquery docs (#128107)
* [DOCS] Reorganizes Osquery docs

* [DOCS] Adds coming tag to osquery docs

Co-authored-by: Kibana Machine <42973632+kibanamachine@users.noreply.github.com>
2022-04-13 12:21:28 -07:00
Melissa Burpo
15b6f8ec11
Update osquery.asciidoc (#126712)
* Update osquery.asciidoc

Add a note about the requirement that the Osquery Manager integration does not work for Elastic Agents in standalone mode.

* Update docs/osquery/osquery.asciidoc

Co-authored-by: gchaps <33642766+gchaps@users.noreply.github.com>

Co-authored-by: gchaps <33642766+gchaps@users.noreply.github.com>
2022-03-03 12:56:11 -06:00
Melissa Burpo
1751cb2774
Update osquery.asciidoc to address doc issue (#125425)
This update fixes the issue raised in #125355

Co-authored-by: Kibana Machine <42973632+kibanamachine@users.noreply.github.com>
2022-02-14 13:59:31 -06:00
Melissa Burpo
b5d2d75e6f
Osquery revisions (#122727)
* update image to latest

* clarify the saved queries section

* add one more clarification to saved queries section

* remove note about ECS mapping that no longer applies

* copy edit

* address review comments

* small copy edit

* add a link and info to help users find the log file location

* address review comment
2022-01-13 11:46:16 -06:00
Melissa Burpo
6a311d03ac
add osquery notes for 7.16 (#120407)
* add osquery notes for 7.16

* address PR feedback

* revise packs note per team input

* Apply suggestions from code review

Co-authored-by: gchaps <33642766+gchaps@users.noreply.github.com>

Co-authored-by: gchaps <33642766+gchaps@users.noreply.github.com>
2021-12-06 16:10:36 -06:00
Melissa Burpo
90fdbf473d
[DOCS] Update osquery page for changes in 7.16 (#117031)
* update usage section for changes to live queries, saved queries, packs, and ECS mapping

* add info about custom configuration, ECS mapping for date fields, custom tables, and other copy edits

* address pr comment, add info about static values for ecs mapping, make other minor copy edits

* add more info about the new k8s tables

* Apply suggestions from code review

Co-authored-by: gchaps <33642766+gchaps@users.noreply.github.com>

* update per code review comments

* Update docs/osquery/osquery.asciidoc

Co-authored-by: gchaps <33642766+gchaps@users.noreply.github.com>

* address review comments

Co-authored-by: Kibana Machine <42973632+kibanamachine@users.noreply.github.com>
Co-authored-by: gchaps <33642766+gchaps@users.noreply.github.com>
2021-11-22 15:41:01 -06:00
DeDe Morton
70c57bca08
Update doc links to Fleet/Agent docs (#115289) 2021-10-18 13:58:07 -07:00
gchaps
4cda49f5ca
[DOCS] Adds docs for Osquery Manager integration (#109885)
* [DOCS] Adds docs for Osquery Manager integration

* [DOCS] Fixes headings

* [DOCS] Updates osquery doc with info from walkthrough

* [DOCS] Add images and updates text

* Update docs/osquery/osquery.asciidoc

Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com>

* [DOCS] Incorporates review comments

* [DOCS] Incorporates review comments

* address review comments

* Page turn edit

* made minor final tweaks

Co-authored-by: lcawl <lcawley@elastic.co>
Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com>
Co-authored-by: Melissa Burpo <melissa.burpo@elastic.co>
Co-authored-by: KOTungseth <kaarina.tungseth@elastic.co>
2021-09-20 10:58:09 -05:00