Well, I should have read the output more carefully
We have about 5 Spaces. OsQuery was used in only one space. Looking into the saved object gives me a headache somehow. I'll try to summarize it a bit.
- In all Spaces were some OsQuery objects
- Some objects were pretty new (somehow tried to reinstall the integration on its own)
- Some objects were really old and might never been managed correctly i guess (?)
some impressions:
As we were not able to use the feature I've removed all the objects related to osquery. Afterwards, I was able to upgrade!
Running the command again seemed to finally upgrade the integration correctly.
input
POST kbn:/api/fleet/epm/packages/osquery_manager/1.6.0
{"force":true}
output
{
"items": [
{
"id": "osquery_manager-69f5ae20-eb02-11e7-8f04-51231daa5b05",
"type": "dashboard"
},
{
"id": "osquery_manager-c0a7ce90-f4aa-11e7-8647-534bb4c21040",
"type": "dashboard"
},
{
"id": "osquery_manager-1da1ed30-eb03-11e7-8f04-51231daa5b05",
"type": "visualization"
},
{
"id": "osquery_manager-240f3630-eb05-11e7-8f04-51231daa5b05",
"type": "visualization"
},
{
"id": "osquery_manager-2d6e0760-f4ab-11e7-8647-534bb4c21040",
"type": "visualization"
},
{
"id": "osquery_manager-6ec10290-f4aa-11e7-8647-534bb4c21040",
"type": "visualization"
},
{
"id": "osquery_manager-a9fd8bb0-eb01-11e7-8f04-51231daa5b05",
"type": "visualization"
},
{
"id": "osquery_manager-ab587180-f4a9-11e7-8647-534bb4c21040",
"type": "visualization"
},
{
"id": "osquery_manager-ffdbba50-f4a9-11e7-8647-534bb4c21040",
"type": "visualization"
},
{
"id": "osquery_manager-0fe5dc00-f49b-11e7-8647-534bb4c21040",
"type": "search"
},
{
"id": "osquery_manager-3824b080-eb02-11e7-8f04-51231daa5b05",
"type": "search"
},
{
"id": "osquery_manager-7a9482d0-eb00-11e7-8f04-51231daa5b05",
"type": "search"
},
{
"id": "osquery_manager-b5d6baa0-eb02-11e7-8f04-51231daa5b05",
"type": "search"
},
{
"id": "osquery_manager-f59e21e0-eb03-11e7-8f04-51231daa5b05",
"type": "search"
},
{
"id": "osquery_manager-03e88290-a6df-11ec-b2f9-c732a3845c54",
"type": "osquery-pack-asset"
},
{
"id": "osquery_manager-07fe8000-a6df-11ec-b2f9-c732a3845c54",
"type": "osquery-pack-asset"
},
{
"id": "osquery_manager-0c09a800-a6df-11ec-b2f9-c732a3845c54",
"type": "osquery-pack-asset"
},
{
"id": "osquery_manager-0f652f10-a6df-11ec-b2f9-c732a3845c54",
"type": "osquery-pack-asset"
},
{
"id": "osquery_manager-135ccf10-a6df-11ec-b2f9-c732a3845c54",
"type": "osquery-pack-asset"
},
{
"id": "osquery_manager-190860a0-a6df-11ec-b2f9-c732a3845c54",
"type": "osquery-pack-asset"
},
{
"id": "osquery_manager-1fc03210-a6df-11ec-b2f9-c732a3845c54",
"type": "osquery-pack-asset"
},
{
"id": "osquery_manager-35f10af0-a6df-11ec-b2f9-c732a3845c54",
"type": "osquery-pack-asset"
},
{
"id": "osquery_manager-3b28cc10-a6df-11ec-b2f9-c732a3845c54",
"type": "osquery-pack-asset"
},
{
"id": "osquery_manager-3f96fba0-a6df-11ec-b2f9-c732a3845c54",
"type": "osquery-pack-asset"
},
{
"id": "osquery_manager-0796f890-b4a9-11ec-8f39-bf9c07530bbb",
"type": "osquery-saved-query"
},
{
"id": "osquery_manager-0f61edf0-17e1-11ed-89c6-331eb0db6d01",
"type": "osquery-saved-query"
},
{
"id": "osquery_manager-128b90b0-b4a6-11ec-8f39-bf9c07530bbb",
"type": "osquery-saved-query"
},
{
"id": "osquery_manager-157d5550-fd27-11ec-8645-83a23bc513b5",
"type": "osquery-saved-query"
},
{
"id": "osquery_manager-239dce60-b4a9-11ec-8f39-bf9c07530bbb",
"type": "osquery-saved-query"
},
{
"id": "osquery_manager-23af51c0-d75f-11ec-879b-83915b27217e",
"type": "osquery-saved-query"
},
{
"id": "osquery_manager-2de24900-b4a9-11ec-8f39-bf9c07530bbb",
"type": "osquery-saved-query"
},
{
"id": "osquery_manager-315bfda0-d75f-11ec-879b-83915b27217e",
"type": "osquery-saved-query"
},
{
"id": "osquery_manager-363d6a30-b4a9-11ec-8f39-bf9c07530bbb",
"type": "osquery-saved-query"
},
{
"id": "osquery_manager-3e553650-17fd-11ed-89c6-331eb0db6d01",
"type": "osquery-saved-query"
},
{
"id": "osquery_manager-3e7155d0-0db5-11ed-a49c-6b13b058b135",
"type": "osquery-saved-query"
},
{
"id": "osquery_manager-47d96fe0-d75f-11ec-879b-83915b27217e",
"type": "osquery-saved-query"
},
{
"id": "osquery_manager-55955db0-0c07-11ed-a49c-6b13b058b135",
"type": "osquery-saved-query"
},
{
"id": "osquery_manager-5c144ac0-b4a5-11ec-8f39-bf9c07530bbb",
"type": "osquery-saved-query"
},
{
"id": "osquery_manager-63c1fe20-176f-11ed-89c6-331eb0db6d01",
"type": "osquery-saved-query"
},
{
"id": "osquery_manager-6fc00190-b4b4-11ec-8f39-bf9c07530bbb",
"type": "osquery-saved-query"
},
{
"id": "osquery_manager-7ee71870-b4b4-11ec-8f39-bf9c07530bbb",
"type": "osquery-saved-query"
},
{
"id": "osquery_manager-83869f40-0dab-11ed-a49c-6b13b058b135",
"type": "osquery-saved-query"
},
{
"id": "osquery_manager-a08d7320-1823-11ed-89c6-331eb0db6d01",
"type": "osquery-saved-query"
},
{
"id": "osquery_manager-a8870ff0-b4a5-11ec-8f39-bf9c07530bbb",
"type": "osquery-saved-query"
},
{
"id": "osquery_manager-b0683c20-0dbb-11ed-a49c-6b13b058b135",
"type": "osquery-saved-query"
},
{
"id": "osquery_manager-ccd3f850-b4a5-11ec-8f39-bf9c07530bbb",
"type": "osquery-saved-query"
},
{
"id": "osquery_manager-cebd7b00-b4b4-11ec-8f39-bf9c07530bbb",
"type": "osquery-saved-query"
},
{
"id": "osquery_manager-e640e200-b4a8-11ec-8f39-bf9c07530bbb",
"type": "osquery-saved-query"
},
{
"id": "osquery_manager-ee586dc0-1801-11ed-89c6-331eb0db6d01",
"type": "osquery-saved-query"
},
{
"id": "osquery_manager-f8649710-b4a8-11ec-8f39-bf9c07530bbb",
"type": "osquery-saved-query"
},
{
"id": "osquery_manager-fc4e34b0-b4a5-11ec-8f39-bf9c07530bbb",
"type": "osquery-saved-query"
},
{
"id": "logs-osquery_manager.result-1.6.0",
"type": "ingest_pipeline"
},
{
"id": "logs-osquery_manager.result",
"type": "index_template"
},
{
"id": "logs-osquery_manager.result@package",
"type": "component_template"
},
{
"id": "logs-osquery_manager.result@custom",
"type": "component_template"
}
],
"_meta": {
"install_source": "registry"
}
}
The integration is there again
However still not tracked as installed
To summarize it from the user perspective
- Some Integrations, in our case Windows, System, some Cisco Integrations, OsQuery Manager are not actively tracked in the Integrations pace under "All Installed". We are able to select the agent integration policies and upgrade them but this is tedious and it would be better having them tracked correctly. They would have been displayed under the "Updates available"
- Upgrading OsQuery Integration from the previous version to 1.6.0 wasn't possible due to some saved objects issues. Removing some saved objects related to osquery seems to resolve the issue.
- There are many saved objects that look like unmanaged or stale. This somehow creates confusion if the objects are still needed or can be deleted. Not sure if they are not tracked correctly.