Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[DOCS] Osquery results can be added to case #2512

Closed
4 of 5 tasks
nastasha-solomon opened this issue Sep 27, 2022 · 0 comments · Fixed by #2561 or elastic/kibana#143242
Closed
4 of 5 tasks

[DOCS] Osquery results can be added to case #2512

nastasha-solomon opened this issue Sep 27, 2022 · 0 comments · Fixed by #2561 or elastic/kibana#143242

Comments

@nastasha-solomon
Copy link
Contributor

nastasha-solomon commented Sep 27, 2022

Description

In 8.5, users can add Osquery results from an alert to a new or an existing case. From the results table, they would click the Add to case button to do this.

The following example shows the workflow from adding query results from Osquery in Kibana to a case:

Required doc updates

The design of the results table has changed slightly to include an option to add Osquery results to a case. Will need to doc this new functionality and refresh screenshots in the Kibana and Security docs.

Kibana docs

Security docs

Need to make several changes to the Run Osquery from a detection alert topic in.

  • Refresh screenshot in the Review single query results section (single-query-results.png). Should be:

  • Will likely need to add a bullet to the list of exportable case items in the Export a case docs.
  • Add a list item to the Investigate query results section for attaching Osquery results to a case. Note that if a user choose to add results to a new case, they'll also be prompted to choose the solution they want to create the case in (Security, Observability, and Stack).

Notes

  • Users cannot do the following:
    • Attach Osquery results to a case when creating a new case
    • Add Osquery results to an existing case from the case details page
  • Need to test/check on what form Osquery results are exported and imported in.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
2 participants