Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

The creation interface for packs is as follows:

...

  • Pack definition, description fields and targets (1): Allows you to assign a name and description to new packs, as well as define the sets of endpoints to configure the pack execution for. Clicking on the Select pack targets button shows the different targetting options available for the pack, which are the same as for individual query executions, as explained in the using queries section of this manual.

  • Information about query packs (2): This section provides some useful information on the operation of the packages.

...

The Editing interface for packs is as follows:

...

  • Pack definition, description fields and targets (1): Like creating packs, this section allows you to assign a name and description to edited packs, as well as the define the sets of endpoints.

...

Use the (plus) icon to add the definition of the target to the list of targets specified for the pack. Targets can be defined based on individual host names or IP addresses, or by creating and applying custom tags. Click on the Save button to apply the changes, or the Cancel button to disregard them.

...

Edit: The above settings can be edited in the window shown by clicking on the Actions button, in addition to Minimum ossuary version, which defines the specific version of the targeted Osquery agent and Shard (percentage), that defines the percentage (1-100) of target endpoints addressed per execution.

...

Remove: It is possible to remove a query from the current pack by clicking on this button. This will not delete the query itself, as it will continue to be available under the Queries section of the application.

...