You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This functionality is in technical preview and may be changed or removed in a future release. Elastic will work to fix any issues, but features in technical preview are not subject to the support SLA of official GA features.
@@ -21,8 +14,9 @@ This functionality is in technical preview and may be changed or removed in a fu
21
14
Osquery Response Actions allow you to add live queries to custom query rules so you can automatically collect data on systems the rule is monitoring. Use this data to support your alert triage and investigation efforts.
22
15
23
16
::::{admonition} Requirements
24
-
* Osquery Response Actions require a [Platinum or Enterprise subscription](https://www.elastic.co/pricing).
25
-
* The [Osquery manager integration](/solutions/security/investigate/manage-integration.md) must be installed.
17
+
* In {{stack}}, Osquery Response Actions require a [Platinum or Enterprise subscription](https://www.elastic.co/pricing).
18
+
* In {{serverless-short}}, Osquery Response Actions require the Endpoint Protection Complete [project feature](../../../deploy-manage/deploy/elastic-cloud/project-settings.md).
19
+
* The [Osquery manager integration](manage-integration.md) must be installed.
26
20
* {{agent}}'s [status](asciidocalypse://docs/docs-content/docs/reference/ingestion-tools/fleet/monitor-elastic-agent.md) must be `Healthy`. Refer to [{{fleet}} Troubleshooting](/troubleshoot/ingest/fleet/common-problems.md) if it isn’t.
27
21
* Your role must have [Osquery feature privileges](/solutions/security/investigate/osquery.md).
28
22
* You can only add Osquery Response Actions to custom query rules.
@@ -102,6 +96,6 @@ Refer to [Examine Osquery results](/solutions/security/investigate/examine-osque
0 commit comments