Skip to content

Commit ac5fa7e

Browse files
Osquery from alerts
1 parent e8e1e78 commit ac5fa7e

File tree

2 files changed

+4
-72
lines changed

2 files changed

+4
-72
lines changed

raw-migrated-files/docs-content/serverless/security-alerts-run-osquery.md

Lines changed: 0 additions & 62 deletions
This file was deleted.

solutions/security/investigate/run-osquery-from-alerts.md

Lines changed: 4 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -4,21 +4,15 @@ mapped_urls:
44
- https://www.elastic.co/guide/en/serverless/current/security-alerts-run-osquery.html
55
---
66

7-
# Run Osquery from alerts
8-
9-
% What needs to be done: Align serverless/stateful
10-
11-
% Use migrated content from existing pages that map to this page:
12-
13-
% - [x] ./raw-migrated-files/security-docs/security/alerts-run-osquery.md
14-
% - [ ] ./raw-migrated-files/docs-content/serverless/security-alerts-run-osquery.md
7+
# Run Osquery from alerts [security-alerts-run-osquery]
158

169
Run live queries on hosts associated with alerts to learn more about your infrastructure and operating systems. For example, with Osquery, you can search your system for indicators of compromise that might have contributed to the alert. You can then use this data to inform your investigation and alert triage efforts.
1710

1811
::::{admonition} Requirements
1912
* The [Osquery manager integration](/solutions/security/investigate/manage-integration.md) must be installed.
2013
* {{agent}}'s [status](asciidocalypse://docs/docs-content/docs/reference/ingestion-tools/fleet/monitor-elastic-agent.md) must be `Healthy`. Refer to [{{fleet}} Troubleshooting](/troubleshoot/ingest/fleet/common-problems.md) if it isn’t.
21-
* Your role must have [Osquery feature privileges](/solutions/security/investigate/osquery.md).
14+
* In {{stack}}, your role must have [Osquery feature privileges](/solutions/security/investigate/osquery.md).
15+
* In {{serverless-short}}, you must have the appropriate user role to use this feature.
2216

2317
::::
2418

@@ -58,7 +52,7 @@ To run Osquery from an alert:
5852

5953

6054
:::{image} ../../../images/security-setup-query.png
61-
:alt: setup query
55+
:alt: Shows how to set up a single queryy
6256
:class: screenshot
6357
:::
6458

0 commit comments

Comments
 (0)