Skip to content

OSQUERY Schedule in 2.4 #13714

Answered by reyesj2
Hammy-72 asked this question in 2.4
Discussion options

You must be logged in to vote

In OSQUERY under packs click on "Add pack" and then "Add Query". Then under "Scheduled agent policies" You can add for example "endpoint-initial" policy if you're using the default endpoint policy for your elastic agents.

I created a test pack and I can see the data coming in every 30 seconds (I set my queries to 30s for testing). I am looking at SOC -> Hunt -> OSQUERY - Live Query. It is a default dashboard included in Security Onion for Hunt.

You could then create a new Sigma Detection to monitor the incoming OSQUERY data and generate an alert when it meets your criteria

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by defensivedepth
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
2.4
Labels
None yet
2 participants