- Installation and Upgrade Guide: other versions:
- Overview
- Installing the Elastic Stack
- Installing in an air-gapped environment
- Serverless changelog
- Breaking changes
- Release notes
- Upgrade to Elastic 9.0.0-beta1
Elastic Security release notes
editElastic Security release notes
editElastic Security version 9.0.0-rc1
editComing in 9.0.0-rc1.
All features introduced in 8.18.0 are also available in 9.0.0.
Breaking changes
editDeprecations
editKnown issues
editDuplicate alerts can be produced from manually running threshold rules
Details
On November 12, 2024, it was discovered that manually running threshold rules could produce duplicate alerts if the date range was already covered by a scheduled rule execution.
Manually running custom query rules with suppression could suppress more alerts than expected
Details
On November 12, 2024, it was discovered that manually running a custom query rule with suppression could incorrectly inflate the number of suppressed alerts.
New features
edit- Enables Automatic Import to accept CEL log samples (#206491).
- Applies the latest Elastic UI framework (EUI) to Elastic Security features (#204007, #204908).
- Adds the option to view Elasticsearch queries that run during rule execution for threshold, custom query, and machine learning rules (#203320).
Enhancements
edit- Enhances Automatic Import by including setup and troubleshooting documentation for each input type that’s selected in the readme (#206477).
-
Allows users to include
closed
alerts in risk score calculations (#201909). - Adds the ability to continue to the Entity Analytics dashboard when there is no data (#201363).
- Modifies the privilege-checking behavior during rule execution. Now, only read privileges of extant indices are checked during rule execution (#177658).
Bug fixes
editElastic Security version 9.0.0-beta1
editBreaking changes
editDeprecations
editKnown issues
editDuplicate alerts can be produced from manually running threshold rules
Details
On November 12, 2024, it was discovered that manually running threshold rules could produce duplicate alerts if the date range was already covered by a scheduled rule execution.
Manually running custom query rules with suppression could suppress more alerts than expected
Details
On November 12, 2024, it was discovered that manually running a custom query rule with suppression could incorrectly inflate the number of suppressed alerts.
New features
edit- Enables Automatic Import to accept CEL log samples (#206491).
- Applies the latest Elastic UI framework (EUI) to Elastic Security features (#204007, #204908).
- Adds the option to view Elasticsearch queries that run during rule execution for threshold, custom query, and machine learning rules (#203320).
Enhancements
edit- Enhances Automatic Import by including setup and troubleshooting documentation for each input type that’s selected in the readme (#206477).
-
Allows users to include
closed
alerts in risk score calculations (#201909). - Adds the ability to continue to the Entity Analytics dashboard when there is no data (#201363).
- Modifies the privilege-checking behavior during rule execution. Now, only read privileges of extant indices are checked during rule execution (#177658).
Bug fixes
edit- Ensures that table actions use standard colors (#207743).
On this page