Osquery Manager integration
editOsquery Manager integration
editVersion |
1.15.0 (View all) |
Compatible Kibana version(s) |
8.16.0 or higher |
Supported Serverless project types |
Security |
Subscription level |
Basic |
Level of support |
Elastic |
With this integration, you can centrally manage Osquery deployments to Elastic Agents in your Fleet and query host data through distributed SQL.
This integration adds an Osquery UI in Kibana where you can:
- Run live queries for one or more agents
- View a history of past queries and their results
- Schedule queries to capture OS state changes over time
- Save queries and build a library of queries for specific use cases
Osquery results are stored in Elasticsearch, so that you can use the power of the stack to search, analyze, and visualize Osquery data.
Documentation
editFor information about using Osquery, see the Osquery Kibana documentation. This includes information about required privileges; how to run, schedule, and save queries; how to map osquery fields to ECS; and other useful information about managing Osquery with this integration.
Exported Fields
editFor a full list of fields that can be returned in osquery results, see the Exported Fields reference in the Kibana documentation.
Changelog
editChangelog
Version | Details | Kibana version(s) |
---|---|---|
1.15.0 |
Enhancement (View pull request) |
8.16.0 or higher |
1.14.0 |
Enhancement (View pull request) |
8.16.0 or higher |
1.13.0 |
Enhancement (View pull request) |
8.16.0 or higher |
1.12.0 |
Enhancement (View pull request) |
8.15.0 or higher |
1.11.0 |
Enhancement (View pull request) |
8.12.0 or higher |
1.10.1 |
Bug fix (View pull request) |
8.10.1 or higher |
1.10.0 |
Enhancement (View pull request) |
8.10.1 or higher |
1.9.0 |
Enhancement (View pull request) |
8.10.0 or higher |
1.8.4 |
Enhancement (View pull request) |
8.7.1 or higher |
1.7.4 |
Enhancement (View pull request) |
8.7.0 or higher |
1.7.3 |
Enhancement (View pull request) |
8.7.0 or higher |
1.7.2 |
Enhancement (View pull request) |
8.7.0 or higher |
1.7.1 |
Enhancement (View pull request) |
8.7.0 or higher |
1.7.0 |
Enhancement (View pull request) |
8.7.0 or higher |
1.6.0 |
Enhancement (View pull request) |
8.6.0 or higher |
1.5.1 |
Enhancement (View pull request) |
8.6.0 or higher |
1.5.0 |
Enhancement (View pull request) |
— |
1.4.1 |
Enhancement (View pull request) |
8.4.0 or higher |
1.4.0 |
Enhancement (View pull request) |
8.4.0 or higher |
1.3.2 |
Bug fix (View pull request) Enhancement (View pull request) |
8.3.0 or higher |
1.3.1 |
Enhancement (View pull request) |
8.3.0 or higher |
1.3.0 |
Enhancement (View pull request) |
— |
1.2.1 |
Enhancement (View pull request) |
8.2.0 or higher |
1.2.0 |
Enhancement (View pull request) |
8.2.0 or higher |
1.1.0 |
Enhancement (View pull request) |
— |
1.0.0 |
Enhancement (View pull request) |
7.16.0 or higher |
0.8.1 |
Enhancement (View pull request) |
— |
0.8.0 |
Enhancement (View pull request) |
— |
0.7.4 |
Enhancement (View pull request) |
— |
0.7.3 |
Enhancement (View pull request) |
— |
0.7.2 |
Enhancement (View pull request) |
— |
0.7.1 |
Enhancement (View pull request) |
— |
0.7.0 |
Enhancement (View pull request) |
— |
0.6.1 |
Enhancement (View pull request) |
— |
0.6.0 |
Enhancement (View pull request) |
— |
0.5.3 |
Enhancement (View pull request) |
— |
0.5.2 |
Enhancement (View pull request) |
— |
0.5.1 |
Enhancement (View pull request) |
— |
0.5.0 |
Enhancement (View pull request) |
— |
0.4.1 |
Enhancement (View pull request) |
— |
0.4.0 |
Enhancement (View pull request) |
— |
0.3.2 |
Enhancement (View pull request) |
— |
0.3.1 |
Enhancement (View pull request) |
— |
0.3.0 |
Enhancement (View pull request) |
— |
0.2.4 |
Enhancement (View pull request) |
— |
0.2.3 |
Enhancement (View pull request) |
— |
0.2.2 |
Enhancement (View pull request) |
— |
0.2.1 |
Enhancement (View pull request) |
— |
0.2.0 |
Enhancement (View pull request) |
— |
0.1.0 |
Enhancement (View pull request) |
— |