elastic / elastic/docs-content

[Internal]: Load custom extensions osquery

Open
#7,930 2 comments 0 reactions 1 assignee Claimed by @natasha-moore-elastic View on GitHub
Team:SKI
Dominant language
No language data
Stars
47
Forks
261
Avg merge
3d 12h
Merged PRs (30d)
116

Description

### Description

We introduce a new advanced configuration for osquery where users can add their own custom extensions. This will enable customers to load their own custom osquery extensions through Elastic Agent (osquerybeat), with explicit acknowledgment that these extensions are customer-managed and unsupported by Elastic. A warning should be shown stating that this could create incompatibilities and it is at customer own risk and the tables will not autocomplete.

The docs for advanced configuration should be updated to include this new capability, in a similar way that what we documented for custom Osquery version: https://www.elastic.co/docs/solutions/security/investigate/manage-integration#osquery-custom-version

Also, the section in the FAQs about extension not be supported should be removed: https://www.elastic.co/docs/solutions/security/investigate/osquery-faq#osquery-extensions

### Resources

PR: https://github.com/elastic/beats/pull/51777
Epic: https://github.com/elastic/security-team/issues/16055

### Which deployment methods does this change impact?

Elastic On-Prem and Cloud (all)

### Feature differences

Identical

### What Elastic Stack release is this request related to?

~~9.5~~
Edit: Confirmed with @marc-gr this will be available from 9.6

### Serverless release

_No response_

### Collaboration model

The documentation team will create the first draft

### Point of contact.

**Main contact:** @raqueltabuyo

**Stakeholders:** @marc-gr

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.