-
Notifications
You must be signed in to change notification settings - Fork 208
[DOCS] 8.4 release notes #2314
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[DOCS] 8.4 release notes #2314
Changes from 50 commits
56ff23e
89ae22b
88cd71f
a5e0b63
7a5f85d
3aca26d
fbb1bbe
ac01d7c
c26ec37
50e05ca
0ea082f
9925a8c
f67bced
b5691cf
88040a3
3230f03
c717710
3165e5f
44017f2
357f273
3e09ac0
8686ecf
a4ebc85
7026398
29e4976
cd6937f
319fd01
1c3d531
f8b922b
3c04876
4302e85
55599dd
aad41ae
5aec400
6ec539c
393dd74
995dc0a
6aa40e1
6743a61
4064f3c
1238916
31844d9
d463311
aed6328
57ccd20
814f5dc
fbf8b06
29fd5fd
afcc8dd
e51ac23
0675ebe
1f377e0
dff443f
b840fd8
70e699d
16699bf
0e11986
c2b6724
6d9148b
a6f44a3
eee7c18
bcd1058
8cac0e1
d3d9b38
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,79 @@ | ||
| [[release-notes-header-8.4.0]] | ||
| == 8.4 | ||
|
|
||
| [discrete] | ||
| [[release-notes-8.4.0]] | ||
| === 8.4.0 | ||
|
|
||
| [discrete] | ||
| [[known-issue-8.4.0]] | ||
| ==== Known issue | ||
nastasha-solomon marked this conversation as resolved.
Outdated
Show resolved
Hide resolved
|
||
| * If additional look-back time is set for the advanced query rule preview, alerts from source documents that are outside the preview time frame may not appear in the preview ({pull}137422[#137422]). | ||
| * A new Lucene 9 validation change causes errors when creating an event correlation rule for users who upgrade from {stack} version 7.x to 8.x. To fix this, use triple quotes `""" """` for regular expressions within an event correlation rule. | ||
nastasha-solomon marked this conversation as resolved.
Outdated
Show resolved
Hide resolved
|
||
|
|
||
| [discrete] | ||
| [[breaking-changes-8.4.0]] | ||
| ==== Breaking changes | ||
| // tag::breaking-changes[] | ||
| // NOTE: The breaking-changes tagged regions are reused in the Elastic Installation and Upgrade Guide. The pull attribute is defined within this snippet so it properly resolves in the output. | ||
| :pull: {pull} | ||
| There are no breaking changes in 8.4.0. | ||
| // end::breaking-changes[] | ||
|
|
||
| [discrete] | ||
| [[features-8.4.0]] | ||
| ==== Features | ||
nastasha-solomon marked this conversation as resolved.
Show resolved
Hide resolved
|
||
| * Creates a new rule type, New Terms, that creates an alert when a value appears for the first time in a particular field ({pull}134526[#134526]). | ||
| * Adds the Insights section to the Alert details flyout to show related cases and alerts ({pull}136009[#136009], {pull}138419[#138419]) | ||
| * Shows process alerts in the event process analyzer ({pull}135340[#135340]). | ||
| * Adds support for wildcard exceptions for detection rules. New operators are `matches` and `does not match` ({pull}136147[#136147]). | ||
| * Adds a new search query parameter, `dry_run`, to the bulk actions API that allows you to simulate a bulk action without permanently updating rules ({pull}134664[#134664]). | ||
| * Creates the response console, an interface that enables you to take actions on specific hosts ({pull}135360[#135360], {pull}134520[#134520]). | ||
| * Enables a new method for the Task Manager API: `bulkUpdateSchedules`, which enables you to update the execution timing of `idle` tasks ({pull}132637[#132637]). | ||
nastasha-solomon marked this conversation as resolved.
Outdated
Show resolved
Hide resolved
|
||
| * Includes integration policy errors and statuses in both {fleet} and {elastic-sec} to help troubleshoot when an {agent} has an `Unhealthy` status. | ||
nastasha-solomon marked this conversation as resolved.
Outdated
Show resolved
Hide resolved
|
||
| * Adds Attack surface reduction protections feature to reduce vulnerabilities on Windows endpoints. Credential hardening prevents attackers from stealing credentials stored in Windows system process memory. | ||
| * Adds an endpoint self-healing feature to roll back file changes and processes on Windows endpoints when a prevention alert is generated by enabled protection features. | ||
| * Adds the ability to run query packs as live queries ({pull}132198[#132198]). | ||
| * Provides support for process, file, and network events in Kubernetes. You must enable the session view data setting on your {endpoint-cloud-sec} integration policy to enrich these events with session data and Kubernetes metadata fields. | ||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. @lrishi @qcorporation @norrietaylor @ferullo @nick-alayil @m-sample please take a look at this and the other Endpoint features/fixes when you have a moment. Thanks! |
||
|
|
||
| [discrete] | ||
| [[bug-fixes-8.4.0]] | ||
| ==== Bug fixes and enhancements | ||
| * Updates the Network page's UI to match the Hosts and Users pages ({pull}137541[#137541], {pull}136913[#136913]). | ||
| * Fixes an error that could occur when you tried to apply an index pattern to rules using the bulk action option ({pull}134664[#134664]). | ||
nastasha-solomon marked this conversation as resolved.
Outdated
Show resolved
Hide resolved
|
||
| * Enhances rule previews with configurable rule intervals and look-back times ({pull}137102[#137102]). | ||
| * Enhances the `status pending` badge for endpoint actions with a detailed status when you hover on it ({pull}136966[#136966]). | ||
| * Turns grouped navigation on by default ({pull}136819[#136819]). | ||
| * Adds a confirmation dialog to bulk rule export ({pull}136418[#136418]). | ||
| * Adds index pattern information to the Inspect panel ({pull}136407[#136407]). | ||
| * Adds a custom dashboards table to the Dashboards page ({pull}136221[#136221], {pull}136671[#136671]). | ||
| * Fixes a performance issue with creating alerts from source documents that contain a large number of fields ({pull}135956[#135956]). | ||
| * Updates the rule exceptions UI ({pull}135255[#135255]). | ||
| * Fixes performance issues with rules management ({pull}135311[#135311]). | ||
| * Allows you to define a fallback `@timestamp` when you've defined a timestamp override ({pull}135116[#135116]). | ||
|
||
| * Enhances the host risk score modal UI ({pull}133708[#133708]). | ||
nastasha-solomon marked this conversation as resolved.
Outdated
Show resolved
Hide resolved
|
||
| * Updates the lists index template to use new logic ({pull}133067[#133067]). | ||
| * Adds event filters to event correlation rules ({pull}132507[#132507]). | ||
| * Allows you to define a data view as the rule's data source, making runtime fields available for rule configuration ({pull}130929[#130929]). | ||
| * Creates a single visualization pane on the Alerts page, and adds a treemap visualization that shows the distribution of alerts as nested, proportionally-sized tiles ({pull}126896[#126896]). | ||
| * Fixes an incorrect counter for exported rules ({pull}138598[#138598]). | ||
| * Fixes event filters based on OS version ({pull}138517[#138517]). | ||
| * Fixes a bug that could change the batch size for event search in indicator rules ({pull}138356[#138356]). | ||
| * Fixes a bug that could crash the Alert details flyout ({pull}138331[#138331]). | ||
nastasha-solomon marked this conversation as resolved.
Outdated
Show resolved
Hide resolved
|
||
| * Fixes the preview button for {ml} rules ({pull}137878[#137878]). | ||
| * Fixes a bug that could crash the Endpoints list when a policy ID was missing ({pull}137788[#137788]). | ||
| * Fixes a bug that could interfere with opening host or user details pages ({pull}137719[#137719]). | ||
| * Fixes several bugs related to refreshing the Alerts page ({pull}137620[#137620]). | ||
| * Fixes a bug that prevented threshold rules' Timeline templates from being respected during investigations ({pull}137233[#137233]). | ||
| * Fixes a permissions bug related to the **Save Timeline** button ({pull}136724[#136724]). | ||
| * Fixes a bug with selecting Timeline templates with the same name ({pull}135694[#135694]). | ||
| * Fixes field aliases to `signal-threshold_result.*` ({pull}135565[#135565]). | ||
| * Fixes a bug that lost track of which rules you had selected after refreshing the Rules page ({pull}135533[#135533]). | ||
| * Fixes a bug that lost track of which rules you had selected after applying a bulk action on the Rules page ({pull}135291[#135291]). | ||
| * Fixes a bug that prevented the Rules table from pausing auto-refresh while bulk actions are being applied ({pull}135208[135208]). | ||
nastasha-solomon marked this conversation as resolved.
Outdated
Show resolved
Hide resolved
|
||
| * Fixes a bug that could cause queries with nested fields to fail open ({pull}134866[#134866]). | ||
nastasha-solomon marked this conversation as resolved.
Outdated
Show resolved
Hide resolved
|
||
| * Fixes a bug that slowed down the display of network details ({pull}133539[#133539]). | ||
| * Various minor bug fixes and enhancements ({pull}133079[#133079], {pull}138135[#138135], {pull}137588[#137588], {pull}137511[#137511], {pull}137492[#137492], {pull}135907[#135907], {pull}135426[#135426]). | ||
| * Fixes an {endpoint-cloud-sec} bug on macOS and Linux that could cause CPU spikes if malware protection is enabled on an {endpoint-cloud-sec} integration policy (https://github.com/elastic/endpoint/issues/22[#22]). | ||
| * Fixes a bug that could cause {endpoint-cloud-sec} to crash when outputting log data to {ls}. | ||
| * Allows {endpoint-cloud-sec} to be added to agents running on Ubuntu 22.04 and Debian 11. | ||
Uh oh!
There was an error while loading. Please reload this page.