Osquery Manager
Deploy Osquery with Elastic Agent, then run and schedule queries in Kibana
Version | 1.15.0 (View all) |
Compatible Kibana version(s) | 8.16.0 or higher |
Supported Serverless project types | Security |
Subscription level | Basic |
Level of support | Elastic |
With this integration, you can centrally manage Osquery deployments to Elastic Agents in your Fleet and query host data through distributed SQL.
This integration adds an Osquery UI in Kibana where you can:
- Run live queries for one or more agents
- View a history of past queries and their results
- Schedule queries to capture OS state changes over time
- Save queries and build a library of queries for specific use cases
Osquery results are stored in Elasticsearch, so that you can use the power of the stack to search, analyze, and visualize Osquery data.
Documentation
For information about using Osquery, see the Osquery Kibana documentation. This includes information about required privileges; how to run, schedule, and save queries; how to map osquery fields to ECS; and other useful information about managing Osquery with this integration.
Exported Fields
For a full list of fields that can be returned in osquery results, see the Exported Fields reference in the Kibana documentation.
Changelog
Version | Details | Kibana version(s) |
---|---|---|
1.15.0 | Enhancement View pull request | 8.16.0 or higher |
1.14.0 | Enhancement View pull request | 8.16.0 or higher |
1.13.0 | Enhancement View pull request | 8.16.0 or higher |
1.12.0 | Enhancement View pull request | 8.15.0 or higher |
1.11.0 | Enhancement View pull request | 8.12.0 or higher |
1.10.1 | Bug fix View pull request | 8.10.1 or higher |
1.10.0 | Enhancement View pull request | 8.10.1 or higher |
1.9.0 | Enhancement View pull request | 8.10.0 or higher |
1.8.4 | Enhancement View pull request | 8.7.1 or higher |
1.7.4 | Enhancement View pull request | 8.7.0 or higher |
1.7.3 | Enhancement View pull request | 8.7.0 or higher |
1.7.2 | Enhancement View pull request | 8.7.0 or higher |
1.7.1 | Enhancement View pull request | 8.7.0 or higher |
1.7.0 | Enhancement View pull request | 8.7.0 or higher |
1.6.0 | Enhancement View pull request | 8.6.0 or higher |
1.5.1 | Enhancement View pull request | 8.6.0 or higher |
1.5.0 | Enhancement View pull request | — |
1.4.1 | Enhancement View pull request | 8.4.0 or higher |
1.4.0 | Enhancement View pull request | 8.4.0 or higher |
1.3.2 | Bug fix View pull request | 8.3.0 or higher |
1.3.1 | Enhancement View pull request | 8.3.0 or higher |
1.3.0 | Enhancement View pull request | — |
1.2.1 | Enhancement View pull request | 8.2.0 or higher |
1.2.0 | Enhancement View pull request | 8.2.0 or higher |
1.1.0 | Enhancement View pull request | — |
1.0.0 | Enhancement View pull request | 7.16.0 or higher |
0.8.1 | Enhancement View pull request | — |
0.8.0 | Enhancement View pull request | — |
0.7.4 | Enhancement View pull request | — |
0.7.3 | Enhancement View pull request | — |
0.7.2 | Enhancement View pull request | — |
0.7.1 | Enhancement View pull request | — |
0.7.0 | Enhancement View pull request | — |
0.6.1 | Enhancement View pull request | — |
0.6.0 | Enhancement View pull request | — |
0.5.3 | Enhancement View pull request | — |
0.5.2 | Enhancement View pull request | — |
0.5.1 | Enhancement View pull request | — |
0.5.0 | Enhancement View pull request | — |
0.4.1 | Enhancement View pull request | — |
0.4.0 | Enhancement View pull request | — |
0.3.2 | Enhancement View pull request | — |
0.3.1 | Enhancement View pull request | — |
0.3.0 | Enhancement View pull request | — |
0.2.4 | Enhancement View pull request | — |
0.2.3 | Enhancement View pull request | — |
0.2.2 | Enhancement View pull request | — |
0.2.1 | Enhancement View pull request | — |
0.2.0 | Enhancement View pull request | — |
0.1.0 | Enhancement View pull request | — |