Beats version 7.15.0
editBeats version 7.15.0
editBreaking changes
editAffecting all Beats
Filebeat
- Remove all alias fields pointing to ECS fields from modules. This affects the Suricata and Traefik modules. 10535 26627
-
Fix Crowdstrike ingest pipeline that was creating flattened
process
fields. 27622 27623 -
Rename
log.path
tolog.file.path
in filestream to be consistent withlog
input and ECS. 27761
Heartbeat
- Remove long deprecated watch_poll
functionality. 27166
- Fix inconsistency in event.dataset
values between heartbeat and fleet by always setting this value to the monitor type / fleet dataset. 27535
Metricbeat
Bugfixes
editAffecting all Beats
-
Improve
perfmon
metricset performance. 26886 - Preserve annotations in a kubernetes namespace metadata 27045
- Fix build constraint that caused issues with doc builds. 27381
-
Do not try to load ILM policy if
check_exists
isfalse
. 27508 26322 - Fix bug with cgroups hierarchy override path in cgroups 27620
-
Beat
setup kibana
command may use the elasticsearch API key defined inoutput.elasticsearch.api_key
. 24015 27540 -
Fix
decode_xml
handling of array merging when usingto_lower: true
. 27922 - Separate namespaces for V1 and V2 controller paths 27676
-
Do not try to load ILM policy if
check_exists
isfalse
. 27508 26322 - Kubernetes autodiscover fails in node scope if node name cannot be discovered 26947
Auditbeat
Filebeat
Metricbeat
Winlogbeat
-
Fix an issue with message template caching in the
wineventlog-experimental
API implementation. 26826
Added
editAffecting all Beats
- Add proxy support for AWS functions. 26832
- Added policies to the Elasticsearch output for non indexible events 26952
-
Add
logging.metrics.namespaces
config option to control what metric groups are reported in logs. 25727 - Add sha256 digests to RPM packages. 23670
- Add new offline docker image for Elastic Agent. 27052
- Add cgroups V2 support 27242
- Update ECS field definitions to ECS 1.11.0. 27107
- The disk queue is now GA. 27515
-
Add
daemonset.name
in pods controlled by DaemonSets 26808, 25816
Filebeat
-
Add new template functions and
value_type
parameter tohttpjson
transforms. 26847 - Add support to merge registry updates in the filestream input across multiple ACKed batches in case of backpressure in the registry or disk. 25976
-
Add support to
decode_cef
for MAC addresses that do not contain separator characters. 27050 27109 -
Add new
hmac
template function for httpjson input 27168 -
Update
tags
andthreatintel.indicator.provider
fields inthreatintel.anomali
ingest pipeline 24746 27141 - Move AWS module and filesets to GA. 27428
- Update ecs.version to ECS 1.11.0. 27107
- Add option for S3 input to work without SQS notification 18205 27332
Metricbeat
- Move openmetrics module to oss. 26561
- Fix release state of kubernetes metricsets. 26864
-
Add
gke
metricset collection togcp
module 26824 -
Added
statsd.mappings
configuration for Statsd module 26220 - Added Airflow lightweight module 26220
- Add state_job metricset to Kubernetes modulehttps://github.com/elastic/beats/pull/26479[26479]
- Bump AWS SDK version to v0.24.0 for WebIdentity authentication flow 19393 27126