diff --git a/docs/01-Using-Fleet/standard-query-library/standard-query-library.yml b/docs/01-Using-Fleet/standard-query-library/standard-query-library.yml index eb28736543..ad20335d15 100644 --- a/docs/01-Using-Fleet/standard-query-library/standard-query-library.yml +++ b/docs/01-Using-Fleet/standard-query-library/standard-query-library.yml @@ -2149,9 +2149,15 @@ kind: policy spec: name: CrowdStrike Falcon System Extension enabled and activated (macOS) query: | - SELECT 1 - WHERE (EXISTS (SELECT 1 FROM system_extensions WHERE identifier = 'com.crowdstrike.falcon.Agent')) - AND EXISTS (SELECT 1 FROM system_extensions WHERE state = 'activated_enabled'); + SELECT 1 + WHERE EXISTS ( + SELECT 1 FROM system_extensions + WHERE identifier = 'com.crowdstrike.falcon.Agent' + ) + AND EXISTS ( + SELECT 1 FROM system_extensions + WHERE state = 'activated_enabled' + ); bash: systemextensionsctl list | grep 'falcon' | grep 'activated enabled' description: Checks to make sure that the CrowdStrike System Extension is enabled and activated on macOS devices. resolution: "To activate the CrowdStrike Falcon System Extension, on the failing device, run the following command in the Terminal app: sudo /Applications/Falcon.app/Contents/Resources/falconctl load"