[DOCS] Add the 7.16 Osquery docs #116969
Labels
enhancement
New value added to drive a business result
Feature:Osquery
Security Solution Osquery feature
Team:Asset Management
Security Asset Management Team
Team:Docs
v7.16.0
Summary
Osquery has several changes in 7.16 that require a doc update, including:
default
was supported). This impacts the data stream name.dates
can have different types (e.g. integer, text, bigint), which may lead to issues with mapping. One way to handle this is with use of SQL operators in the query in some cases. Ideally the docs can include instructions about how (and when) to adjust sql statements to get a proper ES compatible timestamp.The text was updated successfully, but these errors were encountered: