elastic / elastic/docs-content
[Internal]: Load custom extensions osquery
- Dominant language
- No language data
- Stars
- 47
- Forks
- 261
- Avg merge
- 3d 12h
- Merged PRs (30d)
- 116
Description
### Description
We introduce a new advanced configuration for osquery where users can add their own custom extensions. This will enable customers to load their own custom osquery extensions through Elastic Agent (osquerybeat), with explicit acknowledgment that these extensions are customer-managed and unsupported by Elastic. A warning should be shown stating that this could create incompatibilities and it is at customer own risk and the tables will not autocomplete.
The docs for advanced configuration should be updated to include this new capability, in a similar way that what we documented for custom Osquery version: https://www.elastic.co/docs/solutions/security/investigate/manage-integration#osquery-custom-version
Also, the section in the FAQs about extension not be supported should be removed: https://www.elastic.co/docs/solutions/security/investigate/osquery-faq#osquery-extensions
### Resources
PR: https://github.com/elastic/beats/pull/51777
Epic: https://github.com/elastic/security-team/issues/16055
### Which deployment methods does this change impact?
Elastic On-Prem and Cloud (all)
### Feature differences
Identical
### What Elastic Stack release is this request related to?
~~9.5~~
Edit: Confirmed with @marc-gr this will be available from 9.6
### Serverless release
_No response_
### Collaboration model
The documentation team will create the first draft
### Point of contact.
**Main contact:** @raqueltabuyo
**Stakeholders:** @marc-gr
Contributor guide
No contributing guide indexed for this repository
Assessment
This issue has not been assessed yet.