---
sourceDocument: Yokohama IT Operations Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/yokohama/it-operations-management

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama IT Operations Management

ft:clusterId :

    - itom

bundleId :

    - itom

workflow :

    - Technology


---

# Run an Agent Client Collector Security Incident Response OSQuery

# Run an Agent Client Collector
Security Incident Response OSQuery {#ariaid-title1}

* Release version: Yokohama
* 
* Updated January 30, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Run an OSQuery on a machine referenced by an incident to retrieve information on each
incident's CI. For example, if you run a select \* from system_info query
on an incident, the query gathers all information from the OSQuery
system_info table.

## Before you begin

Role required: sn_si.admin or sn_si.basic

## Procedure

1. Navigate to AllSecurity IncidentIncidentsShow All Incidents.
2. Select an incident.
3. In the Related Links section, go to the Configuration Items list and select each incident's CIs that you want to retrieve the information.
4. From the right-click menu, select Run ACC OSQuery  
   The OSQuery to run dialog box opens.
5. Select the name of the query you want to run.  
   The available queries are those configured on the ACC Integration OSQuery page, as described in [Create an Agent Client Collector Security Incident Response OSQuery](https://servicenow-prod.fluidtopics.net/NkI_AhUJqpIQEMulQSctPQ "Define an OSQuery to gather information on a security incident's CI. OSQuery provides an SQL layer on top of OS tables, and is bundled together with the Agent Client Collector as part of the base system."). Options are selectable according to their Name value.
6. Select Submit.  
   The query runs on each of the selected security incident's CIs.
{#acc-run-os-query__steps_cjm_lvs_hsb}

*[\>]: and then


