-
Notifications
You must be signed in to change notification settings - Fork 4.9k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
OSQuery results are not viewable in Kibana when upgrading to the 8.6.0 Agent running the OSQuery Manager integration #34250
Comments
Pinging @elastic/elastic-agent (Team:Elastic-Agent) |
This issue doesn't have a |
This is an internally confirmed bug in Agent and OSQuery beat for 8.6.0. I opened this so that it can be tracked externally |
The proposal to support 8.6.0 and fix the issue in 8.6.1 is the following:
|
For the logstash the additional filter needs to be configured in the logstash pipeline only if the used with 8.6.0 version of the agent. This is want I tested so far works:
|
When upgrading to the 8.6.0 Agent, OSQuery results will not be visible in Kibana due to changes in a couple values in documents that are shipped to ES by the OSQuery beat. These differing docs between OSQuery beat in the 8.5.x Agent and the 8.6.0 Agent cause the newer documents to be rejected by the
logs-osquery_manager.result-*
datastream.Steps to Reproduce:
The text was updated successfully, but these errors were encountered: