-
Notifications
You must be signed in to change notification settings - Fork 156
Closed
Labels
Team:ExperienceIssues owned by the Experience Docs TeamIssues owned by the Experience Docs Team
Description
Description
With Osquery privileges changes, roles won't need the broad logs-osquery_manager.result*
read index permissions.
These docs section should be updated according to it: https://www.elastic.co/docs/solutions/security/investigate/osquery#required_osquery-privileges
Background & resources
- Point of contact: @szwarckonrad
Which documentation set does this change impact?
ESS and serverless
ESS release
Feature will be included in v9.2.0
Serverless release
Week of September 15 2025
Feature differences
Feature is identical in both ESS and Serverless
Metadata
Metadata
Assignees
Labels
Team:ExperienceIssues owned by the Experience Docs TeamIssues owned by the Experience Docs Team