[DOCS] Osquery features in 8.5#2561
Conversation
|
Documentation previews: |
There was a problem hiding this comment.
Lots of great stuff here, and a massive effort, thank you!
One general, big-picture question: Does this new "Use Osquery" section still belong inside the "Detections and alerts" parent section? With these new features (and more on the way I assume), It seems like Osquery cuts across several functions, not just detections & response but also investigation, threat hunting, etc. Maybe this should be a top-level section of its own?
Co-authored-by: Joe Peeples <joe.peeples@elastic.co>
Co-authored-by: Joe Peeples <joe.peeples@elastic.co>
Co-authored-by: Joe Peeples <joe.peeples@elastic.co>
jmikell821
left a comment
There was a problem hiding this comment.
Lots of good changes here! One tiny tiny nit, then Joe had a question here. Other than that, I won't nit pick at this one further because I know it was a big PR. Thanks for pulling this together. 🌟
Co-authored-by: Janeen Mikell-Straughn <57149392+jmikell821@users.noreply.github.com>
|
This pull request is now in conflicts. Could you fix it @nastasha-solomon? 🙏 |
Co-authored-by: Joe Peeples <joe.peeples@elastic.co>
Co-authored-by: Joe Peeples <joe.peeples@elastic.co>
Co-authored-by: Joe Peeples <joe.peeples@elastic.co> Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com> Co-authored-by: Janeen Mikell-Straughn <57149392+jmikell821@users.noreply.github.com> (cherry picked from commit b04b47f)
Co-authored-by: Joe Peeples <joe.peeples@elastic.co> Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com> Co-authored-by: Janeen Mikell-Straughn <57149392+jmikell821@users.noreply.github.com> Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com>
Addresses #2522, #2513, and #2512.
Previews: