[Fleet] Expose API that gives insight into status on different Integrations added to Agent #74708
Labels
Feature:Fleet
Fleet team's agent central management project
Team:Defend Workflows
“EDR Workflows” sub-team of Security Solution
Team:Fleet
Team label for Observability Data Collection Fleet team
Team: SecuritySolution
Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.
Describe the feature:
Ingest/Fleet maintains several different Integrations that are added to an Agent. Support for more detailed information regarding each Integration/Package on a particular Agent would be helpful for other plugins using Ingest.
At a minimum:
The latest status will help us understand when the Agent is reporting an Error from the Endpoint so that we can provide more insight in the Security app or prompt a user to look at the Agent logs.
The state updates could help us figure out if an Endpoint is Starting. This would allow us to let users know in the Security app if Endpoints are starting up before we get the first docs. Similarly, we'd be able to know if the Endpoint is running, in general.
Example of "Status" (note Error, Running State, Starting, State):
Describe a specific use case for the feature:
When users want to drill down to see the status of a certain Integration, they want to see an "at a glance" view of that status.
For example, a user view a list of all Agents running Endpoint. They want to see if any Endpoints have reported an Error to the Agent. Then, they can filter down to just the list of Agents with an Error state from Endpoint and drill further into logs.
The text was updated successfully, but these errors were encountered: