-
Notifications
You must be signed in to change notification settings - Fork 206
Closed
Labels
Feature: OsqueryTeam: DocsdocumentationImprovements or additions to documentationImprovements or additions to documentationv8.4.0
Description
Description
When running osquery from an Alert, users now have an option to either run a single query or to run a pack of queries. This impacts all instances of the Live Query UI, including when running osquery from an Alert in the Security app.
Related PR
Contacts
For any questions about this feature, reach out to @patrykkopycinski or @james-elastic
Acceptance Test Criteria
- The Run Osquery page is updated as needed. This likely includes:
- Update screenshots in steps 3 and 7
- Revise steps to indicate this new choice. Users first need to choose whether they want to run a single query or a pack of queries.
- If they choose to run a single query, they would then do step 3 as written "Enter a new query or select a new saved query."
- If they choose to run a pack of queries, they would then select which pack to run. When you select a pack, all queries that will be run are shown. When you hit Submit, a status is shown for each query in the pack.
Screenshots
Running a single query
Running a query pack
Metadata
Metadata
Assignees
Labels
Feature: OsqueryTeam: DocsdocumentationImprovements or additions to documentationImprovements or additions to documentationv8.4.0

