Description
In 8.5, users can add Osquery results from an alert to a new or an existing case. From the results table, they would click the Add to case button to do this.
The following example shows the workflow from adding query results from Osquery in Kibana to a case:


Required doc updates
The design of the results table has changed slightly to include an option to add Osquery results to a case. Will need to doc this new functionality and refresh screenshots in the Kibana and Security docs.
Kibana docs

Security docs
Need to make several changes to the Run Osquery from a detection alert topic in.



Notes
- Users cannot do the following:
- Attach Osquery results to a case when creating a new case
- Add Osquery results to an existing case from the case details page
- Need to test/check on what form Osquery results are exported and imported in.
Description
In 8.5, users can add Osquery results from an alert to a new or an existing case. From the results table, they would click the Add to case button to do this.
The following example shows the workflow from adding query results from Osquery in Kibana to a case:
Required doc updates
The design of the results table has changed slightly to include an option to add Osquery results to a case. Will need to doc this new functionality and refresh screenshots in the Kibana and Security docs.
Kibana docs
live-query-check-results.pngimage in section for viewing and re-running live queries. Should be:Security docs
Need to make several changes to the Run Osquery from a detection alert topic in.
single-query-results.png). Should be:Notes