Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[BUG]: Information for Prebuilt packs are loaded and activated information needs to be updated. #2611

Closed
amolnater-qasource opened this issue Oct 19, 2022 · 6 comments
Assignees
Labels
bug Something isn't working Feature: Osquery QA:Validated Issue has been Validated by QA Team Team: Docs v8.5.0

Comments

@amolnater-qasource
Copy link

Description:
Information for Prebuilt packs are loaded and activated information needs to be updated.

  • Prebuilt packs are first loaded and not automatically activated.
  • To select from query packs that have been loaded, the pack needs not be activated.

PR Ticket:
#2561

URL link or topic name:
https://security-docs_2561.docs-preview.app.elstc.co/guide/en/security/master/osquery-response-action.html#add-osquery-response-action
https://security-docs_2561.docs-preview.app.elstc.co/guide/en/security/master/alerts-run-osquery.html#alerts-run-osquery

Screenshots/ Recordings:
Expected:

Packs.-.Osquery.-.Elastic.-.Google.Chrome.2022-10-19.12-09-43.mp4
Packs.-.Osquery.-.Elastic.-.Google.Chrome.2022-10-19.12-23-05.mp4

Actual:
10

@amolnater-qasource
Copy link
Author

@manishgupta-qasource Please review.

@manishgupta-qasource
Copy link

Reviewed & assigned to @jmikell821

@nastasha-solomon
Copy link
Contributor

Thanks for filing this, @amolnater-qasource ! I'm following up on this and will get back to you soon.

@nastasha-solomon
Copy link
Contributor

@amolnater-qasource the Security doc updates are ready for your review at #2561. I applied the same corrections to the Kibana Osquery docs at elastic/kibana#143242 (changes are here) and added some extra information about working with active and inactive packs (see the first bullet in the second step here.)

cc: @patrykkopycinski

@nastasha-solomon
Copy link
Contributor

Merged #2561

@arvindersingh-qasource
Copy link

Hi @nastasha-solomon ,

Thanks for looking into the issue.

We have validated this issue on the Kibana Guide [8.5] and found that issue is Fixed.

Guide Link

Please find the below observations

  • Add Osquery Response Actions
    1

  • Run Osquery from Alerts
    2

Thanks

@arvindersingh-qasource arvindersingh-qasource added the QA:Validated Issue has been Validated by QA Team label Nov 2, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working Feature: Osquery QA:Validated Issue has been Validated by QA Team Team: Docs v8.5.0
Projects
None yet
Development

No branches or pull requests

5 participants