[Osquery] Add default saved queries#2998
Conversation
james-elastic
left a comment
There was a problem hiding this comment.
If we were to update this with the ECS fields all we'd have to do is put in another PR right?
|
@james-elastic I think it would be better to do it in this PR |
patrykkopycinski
left a comment
There was a problem hiding this comment.
Let's wait with merging for ECS mapping
|
I think there is no rush - 8.3 is still quite away. Who should we contact to get the mappings? Because the previous list didn't mention them. |
|
/test |
🌐 Coverage report
|
|
/test |
|
/test |
1 similar comment
|
/test |
|
@jsoriano it looks like we need to release a new revision of elastic-package with updated package-spec. Do you know if there are any blockers or if we can proceed with a release? |
Yes, we have to merge #3316 or similar first. We will also have to check some other new validations as the ones for the changelog links. |
|
@Mergifyio rebase |
❌ Base branch update has failedDetailsGit reported the following error: err-code: 83BC3 |
|
@tomsonpl As mergify failed rebasing, can you try rebasing it manually? Package Spec changes are merged now. |
|
@mtojek yes, I will try rebasing manually. Thank you :) |
|
@P1llus thank you :) |
Added default Saved Object (Saved Query) to Osquery Manager integration.
Screenshots