Skip to content

Commit e968f26

Browse files
Rewords content about feature reqs
1 parent 912b853 commit e968f26

File tree

3 files changed

+4
-6
lines changed

3 files changed

+4
-6
lines changed

solutions/security/investigate/add-osquery-response-actions.md

Lines changed: 1 addition & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -14,8 +14,7 @@ This functionality is in technical preview and may be changed or removed in a fu
1414
Osquery Response Actions allow you to add live queries to custom query rules so you can automatically collect data on systems the rule is monitoring. Use this data to support your alert triage and investigation efforts.
1515

1616
::::{admonition} Requirements
17-
* In {{stack}}, Osquery Response Actions require a [Platinum or Enterprise subscription](https://www.elastic.co/pricing).
18-
* In {{serverless-short}}, Osquery Response Actions require the Endpoint Protection Complete [project feature](../../../deploy-manage/deploy/elastic-cloud/project-settings.md).
17+
* Ensure you have the appropriate [{{stack}}](https://www.elastic.co/pricing) subscription or [{{serverless-short}} project tier](../../../deploy-manage/deploy/elastic-cloud/project-settings.md).
1918
* The [Osquery manager integration](manage-integration.md) must be installed.
2019
* {{agent}}'s [status](asciidocalypse://docs/docs-content/docs/reference/ingestion-tools/fleet/monitor-elastic-agent.md) must be `Healthy`. Refer to [{{fleet}} Troubleshooting](/troubleshoot/ingest/fleet/common-problems.md) if it isn’t.
2120
* Your role must have [Osquery feature privileges](/solutions/security/investigate/osquery.md).

solutions/security/investigate/run-osquery-from-alerts.md

Lines changed: 1 addition & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -11,8 +11,7 @@ Run live queries on hosts associated with alerts to learn more about your infras
1111
::::{admonition} Requirements
1212
* The [Osquery manager integration](/solutions/security/investigate/manage-integration.md) must be installed.
1313
* {{agent}}'s [status](asciidocalypse://docs/docs-content/docs/reference/ingestion-tools/fleet/monitor-elastic-agent.md) must be `Healthy`. Refer to [{{fleet}} Troubleshooting](/troubleshoot/ingest/fleet/common-problems.md) if it isn’t.
14-
* In {{stack}}, your role must have [Osquery feature privileges](/solutions/security/investigate/osquery.md).
15-
* In {{serverless-short}}, you must have the appropriate user role to use this feature.
14+
* Your role must have the appropriate [feature privileges](osquery#required_osquery-privileges) in {{stack}} or [user role](/deploy-manage/users-roles/cloud-organization/user-roles.md) in {{serverless-short}}.
1615

1716
::::
1817

solutions/security/investigate/timeline-templates.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -53,7 +53,7 @@ Regular Timeline filter
5353

5454

5555
Template filter
56-
: :::{image} ../../../images/security-timeline-template-filter.png
56+
:::{image} ../../../images/security-timeline-template-filter.png
5757
:alt: timeline template filter
5858
:class: screenshot
5959
:::
@@ -74,7 +74,7 @@ To enable the filter, either specify a value or change it to a field’s existin
7474
1. Choose one of the following:
7575

7676
* Find **Timelines** in the main menu or by using the [global search field](/explore-analyze/find-and-organize/find-apps-and-objects.md). Next, select the **Templates** tab, then click **Create new Timeline template**.
77-
* Go to the Timeline bar (which is at the bottom of most pages), click the ![Click the add new button](../../../images/security-add-new-timeline-button.png "") button, then click **Create new Timeline template**.
77+
* Go to the Timeline bar (which is at the bottom of most pages), click the ![Click the add new button](../../../images/security-add-new-timeline-button.png "title =20x20") button, then click **Create new Timeline template**.
7878
* From an open Timeline or Timeline template, click **New****New Timeline template**.
7979

8080
2. To add filters, click **Add field**, and then select the required option:

0 commit comments

Comments
 (0)