-
Notifications
You must be signed in to change notification settings - Fork 184
Description
Description
We are retaking the Osquery project and there are some conflicts in the documentation of Osquery Manager integration: https://www.elastic.co/docs/reference/integrations/osquery_manager
The documentation has not been updated since long time and there are features that are redundant and others that are important but not been documented yet.
There are several topics that require review from Elastic docs team:
- Removal of Exported field page, it is redundant as it is something already documented in osquery official docs. https://www.elastic.co/docs/reference/kibana/osquery-exported-fields
- Add Elastic osquery tables, this tables are an additional on top of official native osquery tables: https://github.com/elastic/beats/blob/main/x-pack/osquerybeat/ext/osquery-extension/README.md. These tables are created by Elastic and are not documented in the official osquery site: https://osquery.io/schema/5.20.0/
- Investigate where is the right place to include the Elastic tables, if it is via a link to each table within the integration documentation page or if as a new site or if it is possible to have it within the docs autopopulated from Github readme and not in Kibana integration information.
- Rename of Documentation section to Investigate with Osquery to reflect better the link to the documentation site, also add a better description to the site.
Below a graphical representation of what it was described above:
Resources
There are Elastic osquery tables that exist but are not documented (i.e., host_groups) and we are planning to add more tables in 9.3 like Amcacheand Browser history. In future releases, we will add more tables.
Issue for old not documented Elastic osquery tables: elastic/beats#47593
Which documentation set does this change impact?
Elastic On-Prem and Cloud (all)
Feature differences
Identical
What release is this request related to?
N/A
Serverless release
January 2026
Collaboration model
The documentation team
Point of contact.
Main contact: @raqueltabuyo
Stakeholders: @marc-gr @brian-mckinney