Skip to content

[Security] [Serverless: June 16] Document Osquery results export#6823

Open
natasha-moore-elastic wants to merge 1 commit into
mainfrom
issue-6735
Open

[Security] [Serverless: June 16] Document Osquery results export#6823
natasha-moore-elastic wants to merge 1 commit into
mainfrom
issue-6735

Conversation

@natasha-moore-elastic

@natasha-moore-elastic natasha-moore-elastic commented Jun 3, 2026

Copy link
Copy Markdown
Contributor

Summary

Resolves #6735.

  • Adds an Export results action to the Results table actions list on the Examine Osquery results page
  • Consolidates the duplicated Results table actions into a single list on the Examine Osquery results page, and trims the overlapping list on the Osquery page to point to it instead of repeating the actions.

Generative AI disclosure

  1. Did you use a generative AI (GenAI) tool to assist in creating this contribution?
  • Yes
  • No

@github-actions

github-actions Bot commented Jun 3, 2026

Copy link
Copy Markdown
Contributor

Elastic Docs AI PR menu

Check the box to run an AI review for this pull request.

  • Review docs changes (docs-review). Status: not started.

Powered by GitHub Agentic Workflows and docs-actions. For more information, reach out to the docs team.

@github-actions

github-actions Bot commented Jun 3, 2026

Copy link
Copy Markdown
Contributor

@github-actions

github-actions Bot commented Jun 3, 2026

Copy link
Copy Markdown
Contributor

✅ Elastic Docs Style Checker (Vale)

No issues found on modified lines!


The Vale linter checks documentation changes against the Elastic Docs style guide. To use Vale locally or report issues, refer to Elastic style guide for Vale.

@natasha-moore-elastic natasha-moore-elastic changed the title [Security] Document Osquery results export [Security] [Serverless: June 16] Document Osquery results export Jun 3, 2026
@natasha-moore-elastic natasha-moore-elastic marked this pull request as ready for review June 3, 2026 11:33
@natasha-moore-elastic natasha-moore-elastic requested a review from a team as a code owner June 3, 2026 11:33

@benironside benironside left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nice. I like the cross-linking :)


* Click the view details icon (![View details icon](/solutions/images/security-view-osquery-details.png "title =20x20")) to examine the query ID and statement.
* {applies_to}`stack: ga 9.4+` {applies_to}`serverless: ga` Add or remove tags to organize and label the queries for future use.
* Click the view details icon {icon}`expand` to examine the query ID and statement.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
* Click the view details icon {icon}`expand` to examine the query ID and statement.
* Click the **View Details** icon {icon}`expand` to examine the query ID and statement.

Standardizing, unless there's a UI reason not to :)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Internal]: Document Osquery results export (NDJSON / JSON / CSV) — new in 9.5 (experimental)

2 participants