Skip to content

Commit cab4287

Browse files
[Security] [Serverless: Sep 16] Updates required privileges for Osquery Manager (#2890)
Resolves #2874. Adds the appropriate 'applies to' tags to indicate that `Read` privileges for the `logs-osquery_manager.result*` index are no longer required from 9.2. Preview: [Osquery > Required privileges](https://docs-v3-preview.elastic.dev/elastic/docs-content/pull/2890/solutions/security/investigate/osquery#required_osquery-privileges)
1 parent c82ff32 commit cab4287

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

solutions/security/investigate/osquery.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -36,7 +36,7 @@ To use Osquery, you must add the [Osquery manager integration](manage-integratio
3636

3737
To use **Osquery Manager**, you must be assigned to a role with the following privileges:
3838

39-
* `Read` privileges for the `logs-osquery_manager.result*` index.
39+
* {applies_to}`stack: removed 9.2` {applies_to}`serverless: removed` `Read` privileges for the `logs-osquery_manager.result*` index.
4040
* {{kib}} privileges for **Osquery Manager**. The `All` privilege enables you to run, schedule, and save queries. `Read` enables you to view live and scheduled query results, but you cannot run live queries or edit.
4141

4242

0 commit comments

Comments
 (0)