You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
- Loading Kibana assets (dashboards, index templates) rely on Saved Object API. So to provide a reliable service, Beats can only import and export dashboards using at least Kibana 7.15. {issue}20672[20672] {pull}27220[27220]
24
+
25
+
*Filebeat*
26
+
27
+
- Remove all alias fields pointing to ECS fields from modules. This affects the Suricata and Traefik modules. {issue}10535[10535] {pull}26627[26627]
28
+
- Fix Crowdstrike ingest pipeline that was creating flattened `process` fields. {issue}27622[27622] {pull}27623[27623]
29
+
- Rename `log.path` to `log.file.path` in filestream to be consistent with `log` input and ECS. {pull}27761[27761]
30
+
31
+
*Heartbeat*
32
+
- Remove long deprecated `watch_poll` functionality. {pull}27166[27166]
33
+
- Fix inconsistency in `event.dataset` values between heartbeat and fleet by always setting this value to the monitor type / fleet dataset. {pull}27535[27535]
34
+
35
+
*Metricbeat*
36
+
37
+
- Fix Elasticsearch jvm.gc.collectors.old being exposed as young {issue}19636[19636] {pull}26616[26616]
- Update Filebeat compatibility function to remove processor description field on ES < 7.9.0 {pull}27774[27774]
61
+
- Make filestream events ECS compliant. {issue}27776[27776]
62
+
63
+
*Metricbeat*
64
+
65
+
- Allow metric prefix override per service in gcp module. {pull}26960[26960]
66
+
- Update metrics configuration and dashboards after changes in the Azure Monitor {pull}27520[27520]
67
+
68
+
*Winlogbeat*
69
+
70
+
- Fix an issue with message template caching in the `wineventlog-experimental` API implementation. {pull}26826[26826]
71
+
72
+
==== Added
73
+
74
+
*Affecting all Beats*
75
+
76
+
- Add proxy support for AWS functions. {pull}26832[26832]
77
+
- Added policies to the Elasticsearch output for non indexible events {pull}26952[26952]
78
+
- Add `logging.metrics.namespaces` config option to control what metric groups are reported in logs. {pull}25727[25727]
79
+
- Add sha256 digests to RPM packages. {issue}23670[23670]
80
+
- Add new 'offline' docker image for Elastic Agent. {pull}27052[27052]
81
+
- Add cgroups V2 support {pull}27242[27242]
82
+
- Update ECS field definitions to ECS 1.11.0. {pull}27107[27107]
83
+
- The disk queue is now GA. {pull}27515[27515]
84
+
- Add `daemonset.name` in pods controlled by DaemonSets {pull}26808[26808], {issue}25816[25816]
85
+
86
+
*Filebeat*
87
+
88
+
- Add new template functions and `value_type` parameter to `httpjson` transforms. {pull}26847[26847]
89
+
- Add support to merge registry updates in the filestream input across multiple ACKed batches in case of backpressure in the registry or disk. {pull}25976[25976]
90
+
- Add support to `decode_cef` for MAC addresses that do not contain separator characters. {issue}27050[27050] {pull}27109[27109]
91
+
- Add new `hmac` template function for httpjson input {pull}27168[27168]
92
+
- Update `tags` and `threatintel.indicator.provider` fields in `threatintel.anomali` ingest pipeline {issue}24746[24746] {pull}27141[27141]
93
+
- Move AWS module and filesets to GA. {pull}27428[27428]
94
+
- Update ecs.version to ECS 1.11.0. {pull}27107[27107]
95
+
- Add option for S3 input to work without SQS notification {issue}18205[18205] {pull}27332[27332]
96
+
97
+
*Metricbeat*
98
+
99
+
- Move openmetrics module to oss. {pull}26561[26561]
100
+
- Fix release state of kubernetes metricsets. {pull}26864[26864]
101
+
- Add `gke` metricset collection to `gcp` module {pull}26824[26824]
102
+
- Added `statsd.mappings` configuration for Statsd module {pull}26220[26220]
Copy file name to clipboardExpand all lines: CHANGELOG.next.asciidoc
-40Lines changed: 0 additions & 40 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -19,9 +19,6 @@ https://github.com/elastic/beats/compare/v7.0.0-alpha2...master[Check the HEAD d
19
19
- Remove the non-ECS `agent.hostname` field. Use the `agent.name` or `agent.id` fields for an identifier. {issue}16377[16377] {pull}18328[18328]
20
20
- Make error message about locked data path actionable. {pull}18667[18667]
21
21
- Remove the deprecated `xpack.monitoring.*` settings. Going forward only `monitoring.*` settings may be used. {issue}9424[9424] {pull}18608[18608]
22
-
- Add daemonset.name in pods controlled by DaemonSets {pull}26808[26808], {issue}25816[25816]
23
-
- Kubernetes autodiscover fails in node scope if node name cannot be discovered {pull}26947[26947]
24
-
- Loading Kibana assets (dashboards, index templates) rely on Saved Object API. So to provide a reliable service, Beats can only import and export dasbhboards using at least Kibana 7.15. {issue}20672[20672] {pull}27220[27220]
25
22
- Skip add_kubernetes_metadata processor when kubernetes metadata are already present {pull}27689[27689]
- Remove deprecated fields from kubernetes module {pull}28046[28046]
@@ -94,8 +91,6 @@ https://github.com/elastic/beats/compare/v7.0.0-alpha2...master[Check the HEAD d
94
91
- Remove deprecated fields in Kafka module. {pull}27938[27938]
95
92
96
93
*Heartbeat*
97
-
- Remove long deprecated `watch_poll` functionality. {pull}27166[27166]
98
-
- Fix inconsistency in `event.dataset` values between heartbeat and fleet by always setting this value to the monitor type / fleet dataset. {pull}27535[27535]
99
94
100
95
*Journalbeat*
101
96
@@ -109,10 +104,6 @@ https://github.com/elastic/beats/compare/v7.0.0-alpha2...master[Check the HEAD d
109
104
- Move service config under metrics and simplify metric types. {pull}18691[18691]
110
105
- Fix ECS compliance of user.id field in system/users metricset {pull}19019[19019]
111
106
- Remove "invalid zero" metrics on Windows and Darwin, don't report linux-only memory and diskio metrics when running under agent. {pull}21457[21457]
112
-
- Added `statsd.mappings` configuration for Statsd module {pull}26220[26220]
- Preserve annotations in a kubernetes namespace metadata {pull}27045[27045]
217
-
- Fix build constraint that caused issues with doc builds. {pull}27381[27381]
218
-
- Do not try to load ILM policy if `check_exists` is `false`. {pull}27508[27508] {issue}26322[26322]
219
-
- Fix bug with cgroups hierarchy override path in cgroups {pull}27620[27620]
220
-
- Beat `setup kibana` command may use the elasticsearch API key defined in `output.elasticsearch.api_key`. {issue}24015[24015] {pull}27540[27540]
221
-
- Fix `decode_xml` handling of array merging when using `to_lower: true`. {pull}27922[27922]
222
-
- Seperate namespaces for V1 and V2 controller paths {pull}27676[27676]
223
206
- Beats dashboards use custom index when `setup.dashboards.index` is set. {issue}21232[21232] {pull}27901[27901]
224
207
225
208
*Auditbeat*
@@ -230,7 +213,6 @@ https://github.com/elastic/beats/compare/v7.0.0-alpha2...master[Check the HEAD d
230
213
- system/package: Fix an error that can occur while trying to persist package metadata. {issue}18536[18536] {pull}18887[18887]
231
214
- system/socket: Fix dataset using 100% CPU and becoming unresponsive in some scenarios. {pull}19033[19033] {pull}19764[19764]
232
215
- system/socket: Fixed tracking of long-running connections. {pull}19033[19033]
233
-
- file_integrity: honor include_files when doing initial scan. {issue}27273[27273] {pull}27722[27722]
234
216
235
217
*Filebeat*
236
218
@@ -316,11 +298,7 @@ https://github.com/elastic/beats/compare/v7.0.0-alpha2...master[Check the HEAD d
316
298
- Fix Zeek dashboard reference to `zeek.ssl.server.name` field. {pull}21696[21696]
317
299
- Fix for `field [source] not present as part of path [source.ip]` error in azure pipelines. {pull}22377[22377]
318
300
- Drop aws.vpcflow.pkt_srcaddr and aws.vpcflow.pkt_dstaddr when equal to "-". {pull}22721[22721] {issue}22716[22716]
319
-
- Fixes the Snyk module to work with the new API changes. {pull}27358[27358]
320
-
- Fixes a bug in `http_endpoint` that caused numbers encoded as strings. {issue}27382[27382] {pull}27480[27480]
321
301
- Update indentation for azure filebeat configuration. {pull}26604[26604]
322
-
- Update Filebeat compatibility function to remove processor description field on ES < 7.9.0 {pull}27774[27774]
323
-
- Make filestream events ECS compliant. {issue}27776[27776]
324
302
- Update Sophos xg module pipeline to deal with missing `date` and `time` fields. {pull}27834[27834]
325
303
326
304
*Heartbeat*
@@ -426,8 +404,6 @@ https://github.com/elastic/beats/compare/v7.0.0-alpha2...master[Check the HEAD d
426
404
- Fix remote_write flaky test. {pull}21173[21173]
427
405
- Remove io.time from windows {pull}22237[22237]
428
406
- Change vsphere.datastore.capacity.used.pct value to betweeen 0 and 1. {pull}23148[23148]
429
-
- Allow metric prefix override per service in gcp module. {pull}26960[26960]
430
-
- Update metrics configuration and dashboards after changes in the Azure Monitor {pull}27520[27520]
431
407
432
408
*Packetbeat*
433
409
@@ -439,7 +415,6 @@ https://github.com/elastic/beats/compare/v7.0.0-alpha2...master[Check the HEAD d
439
415
- Add source.ip validation for event ID 4778 in the Security module. {issue}19627[19627]
440
416
- Protect against accessing undefined variables in Sysmon module. {issue}22219[22219] {pull}22236[22236]
441
417
- Protect against accessing an undefined variable in Security module. {pull}22937[22937]
442
-
- Fix an issue with message template caching in the `wineventlog-experimental` API implementation. {pull}26826[26826]
443
418
444
419
*Functionbeat*
445
420
@@ -522,14 +497,6 @@ https://github.com/elastic/beats/compare/v7.0.0-alpha2...master[Check the HEAD d
522
497
- Added "add_network_direction" processor for determining perimeter-based network direction. {pull}23076[23076]
523
498
- Added new `rate_limit` processor for enforcing rate limits on event throughput. {pull}22883[22883]
524
499
- Allow node/namespace metadata to be disabled on kubernetes metagen and ensure add_kubernetes_metadata honors host {pull}23012[23012]
525
-
- Add proxy support for AWS functions. {pull}26832[26832]
526
-
- Added policies to the elasticsearch output for non indexible events {pull}26952[26952]
527
-
- Add `logging.metrics.namespaces` config option to control what metric groups are reported in logs. {pull}25727[25727]
528
-
- Add sha256 digests to RPM packages. {issue}23670[23670]
529
-
- Add new 'offline' docker image for Elastic Agent. {pull}27052[27052]
530
-
- Add cgroups V2 support {pull}27242[27242]
531
-
- update ECS field definitions to ECS 1.11.0. {pull}27107[27107]
532
-
- The disk queue is now GA. {pull}27515[27515]
533
500
- Allow non-padded base64 data to be decoded by decode_base64_field {pull}27311[27311], {issue}27021[27021]
534
501
- The Kafka support library Sarama has been updated to 1.29.1. {pull}27717[27717]
535
502
- Kafka is now supported up to version 2.8.0. {pull}27720[27720]
@@ -747,15 +714,8 @@ https://github.com/elastic/beats/compare/v7.0.0-alpha2...master[Check the HEAD d
747
714
- Add Google Workspace module and mark Gsuite module as deprecated {pull}22950[22950]
748
715
- Mark m365 defender, defender atp, okta and google workspace modules as GA {pull}23113[23113]
749
716
- Added `alternative_host` option to google pubsub input {pull}23215[23215]
750
-
- Add new template functions and `value_type` parameter to `httpjson` transforms. {pull}26847[26847]
751
-
- Add support to merge registry updates in the filestream input across multiple ACKed batches in case of backpressure in the registry or disk. {pull}25976[25976]
752
-
- Add support to `decode_cef` for MAC addresses that do not contain separator characters. {issue}27050[27050] {pull}27109[27109]
753
-
- Add new `hmac` template function for httpjson input {pull}27168[27168]
754
717
- Add `timezone` config option to the `decode_cef` processor. {issue}27232[27232] {pull}27727[27727]
755
718
- Add `timezone` config option to the `syslog` input. {pull}27727[27727]
756
-
- Update `tags` and `threatintel.indicator.provider` fields in `threatintel.anomali` ingest pipeline {issue}24746[24746] {pull}27141[27141]
757
-
- Move AWS module and filesets to GA. {pull}27428[27428]
758
-
- update ecs.version to ECS 1.11.0. {pull}27107[27107]
759
719
- Added support for parsing syslog dates containing a leading 0 (e.g. `Sep 01`) rather than a space. {pull}27775[27775]
760
720
- Add base64 Encode functionality to httpjson input. {pull}27681[27681]
761
721
- Add `join` and `sprintf` functions to `httpjson` input. {pull}27735[27735]
0 commit comments