Skip to content

[DOCS] Markdown insights/actions from investigation guide ("playbook actions") #2696

@joepeeples

Description

@joepeeples

Description

Related:

Ongoing work to explore adding "playbook actions" to rule/alert investigation guides, similar to running Osquery from investigation guides (added in 8.5 - docs PR #2561).

Unclear what functionality, if any, will make it into 8.6.0 release, but we're creating this issue to monitor the feature as it's being finalized.

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions