IMPORTANT: No additional bug fixes or documentation updates
will be released for this version. For the latest information, see the
current release documentation.
Beats version 7.15.0
editBeats version 7.15.0
editBreaking changes
editAffecting all Beats
Filebeat
- Remove all alias fields pointing to ECS fields from modules. This affects the Suricata and Traefik modules. 10535 26627
-
Fix Crowdstrike ingest pipeline that was creating flattened
process
fields. 27622 27623 -
Rename
log.path
tolog.file.path
in filestream to be consistent withlog
input and ECS. 27761
Heartbeat
- Remove long deprecated watch_poll
functionality. 27166
- Fix inconsistency in event.dataset
values between heartbeat and fleet by always setting this value to the monitor type / fleet dataset. 27535
Metricbeat
Bugfixes
editAffecting all Beats
-
Improve
perfmon
metricset performance. 26886 - Preserve annotations in a kubernetes namespace metadata 27045
- Fix build constraint that caused issues with doc builds. 27381
-
Do not try to load ILM policy if
check_exists
isfalse
. 27508 26322 - Fix bug with cgroups hierarchy override path in cgroups 27620
-
Beat
setup kibana
command may use the elasticsearch API key defined inoutput.elasticsearch.api_key
. 24015 27540 -
Fix
decode_xml
handling of array merging when usingto_lower: true
. 27922 - Separate namespaces for V1 and V2 controller paths 27676
-
Do not try to load ILM policy if
check_exists
isfalse
. 27508 26322 - Kubernetes autodiscover fails in node scope if node name cannot be discovered 26947
Auditbeat
Filebeat
Metricbeat
Winlogbeat
-
Fix an issue with message template caching in the
wineventlog-experimental
API implementation. 26826
Added
editAffecting all Beats
- Add proxy support for AWS functions. 26832
- Added policies to the Elasticsearch output for non indexible events 26952
-
Add
logging.metrics.namespaces
config option to control what metric groups are reported in logs. 25727 - Add sha256 digests to RPM packages. 23670
- Add new offline docker image for Elastic Agent. 27052
- Add cgroups V2 support 27242
- Update ECS field definitions to ECS 1.11.0. 27107
- The disk queue is now GA. 27515
-
Add
daemonset.name
in pods controlled by DaemonSets 26808, 25816
Filebeat
-
Add new template functions and
value_type
parameter tohttpjson
transforms. 26847 - Add support to merge registry updates in the filestream input across multiple ACKed batches in case of backpressure in the registry or disk. 25976
-
Add support to
decode_cef
for MAC addresses that do not contain separator characters. 27050 27109 -
Add new
hmac
template function for httpjson input 27168 -
Update
tags
andthreatintel.indicator.provider
fields inthreatintel.anomali
ingest pipeline 24746 27141 - Move AWS module and filesets to GA. 27428
- Update ecs.version to ECS 1.11.0. 27107
- Add option for S3 input to work without SQS notification 18205 27332
Metricbeat
- Move openmetrics module to oss. 26561
- Fix release state of kubernetes metricsets. 26864
-
Add
gke
metricset collection togcp
module 26824 -
Added
statsd.mappings
configuration for Statsd module 26220 - Added Airflow lightweight module 26220
- Add state_job metricset to Kubernetes modulehttps://github.com/elastic/beats/pull/26479[26479]
- Bump AWS SDK version to v0.24.0 for WebIdentity authentication flow 19393 27126