Skip to content

Commit 75065b0

Browse files
Placeholder fields
1 parent 4475818 commit 75065b0

File tree

3 files changed

+4
-38
lines changed

3 files changed

+4
-38
lines changed

raw-migrated-files/docs-content/serverless/security-osquery-placeholder-fields.md

Lines changed: 0 additions & 28 deletions
This file was deleted.

raw-migrated-files/toc.yml

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -288,7 +288,6 @@ toc:
288288
- file: docs-content/serverless/security-llm-performance-matrix.md
289289
- file: docs-content/serverless/security-machine-learning.md
290290
- file: docs-content/serverless/security-ml-requirements.md
291-
- file: docs-content/serverless/security-osquery-placeholder-fields.md
292291
- file: docs-content/serverless/security-overview-dashboard.md
293292
- file: docs-content/serverless/security-policies-page.md
294293
- file: docs-content/serverless/security-posture-faq.md

solutions/security/investigate/use-placeholder-fields-in-osquery-queries.md

Lines changed: 4 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -4,14 +4,7 @@ mapped_urls:
44
- https://www.elastic.co/guide/en/serverless/current/security-osquery-placeholder-fields.html
55
---
66

7-
# Use placeholder fields in Osquery queries
8-
9-
% What needs to be done: Lift-and-shift
10-
11-
% Use migrated content from existing pages that map to this page:
12-
13-
% - [x] ./raw-migrated-files/security-docs/security/osquery-placeholder-fields.md
14-
% - [ ] ./raw-migrated-files/docs-content/serverless/security-osquery-placeholder-fields.md
7+
# Use placeholder fields in Osquery queries [security-osquery-placeholder-fields]
158

169
Instead of hard-coding alert and event values into Osquery queries, you can use placeholder fields to dynamically pass this data into queries. Placeholder fields function like parameters. You can use placeholder fields to build flexible and reusable queries.
1710

@@ -33,7 +26,9 @@ Queries with placeholder fields can only run against alerts or events. Otherwise
3326

3427
The following query uses the `{{host.name}}` placeholder field:
3528

36-
`SELECT * FROM os_version WHERE name = {{host.os.name}}`
29+
```sql
30+
SELECT * FROM os_version WHERE name = {{host.os.name}}
31+
```
3732

3833
When you run the query, the value that’s stored in the alert or event’s `host.name` field will be transferred to the `{{host.os.name}}` placeholder field.
3934

0 commit comments

Comments
 (0)