Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[DOCS] 8.5 Release Notes #2519

Merged
merged 55 commits into from
Nov 1, 2022
Merged
Show file tree
Hide file tree
Changes from 7 commits
Commits
Show all changes
55 commits
Select commit Hold shift + click to select a range
123a348
Creates release notes
benironside Sep 30, 2022
16f1bb2
Merge branch 'main' into issue-2460-big
benironside Sep 30, 2022
ff00dc1
Merge branch 'main' into issue-2460-big
nastasha-solomon Oct 4, 2022
82b8434
Adding requested content
nastasha-solomon Oct 10, 2022
ac45ed4
Merge branch 'main' into issue-2460-big
nastasha-solomon Oct 12, 2022
a87fbaa
Edits and new additions
nastasha-solomon Oct 12, 2022
294cbc0
Merge branch 'issue-2460-big' of github.com:elastic/security-docs int…
nastasha-solomon Oct 12, 2022
e983054
Update docs/release-notes/8.5.asciidoc
nastasha-solomon Oct 14, 2022
0a97ade
Update docs/release-notes/8.5.asciidoc
nastasha-solomon Oct 14, 2022
787fcdf
Update docs/release-notes/8.5.asciidoc
nastasha-solomon Oct 14, 2022
4392fef
Update docs/release-notes/8.5.asciidoc
nastasha-solomon Oct 14, 2022
dec505d
Update docs/release-notes/8.5.asciidoc
nastasha-solomon Oct 14, 2022
51a4c35
Update docs/release-notes/8.5.asciidoc
nastasha-solomon Oct 14, 2022
56f5da4
Update docs/release-notes/8.5.asciidoc
nastasha-solomon Oct 14, 2022
b8abb00
Update docs/release-notes/8.5.asciidoc
nastasha-solomon Oct 14, 2022
8e70fce
Update docs/release-notes/8.5.asciidoc
nastasha-solomon Oct 14, 2022
d141e94
Update docs/release-notes/8.5.asciidoc
nastasha-solomon Oct 14, 2022
2c43338
Update docs/release-notes/8.5.asciidoc
nastasha-solomon Oct 14, 2022
ce25044
Merge branch 'main' into issue-2460-big
nastasha-solomon Oct 14, 2022
7d717a0
Joe's suggestion
nastasha-solomon Oct 14, 2022
ec3c9cd
Joe's features and bug fix
nastasha-solomon Oct 14, 2022
3dacfac
add KSPM to release notes
tinnytintin10 Oct 17, 2022
c6da579
Update docs/release-notes/8.5.asciidoc
nastasha-solomon Oct 17, 2022
b925edb
Update docs/release-notes/8.5.asciidoc
nastasha-solomon Oct 17, 2022
0049836
Merge branch 'main' into issue-2460-big
nastasha-solomon Oct 17, 2022
199b8a8
Update docs/release-notes/8.5.asciidoc
nastasha-solomon Oct 17, 2022
d501cfb
Update docs/release-notes/8.5.asciidoc
benironside Oct 17, 2022
cd724b4
Update docs/release-notes/8.5.asciidoc
nastasha-solomon Oct 18, 2022
1854e24
Update docs/release-notes/8.5.asciidoc
nastasha-solomon Oct 18, 2022
d64558e
Update docs/release-notes/8.5.asciidoc
nastasha-solomon Oct 18, 2022
103b710
Update docs/release-notes/8.5.asciidoc
nastasha-solomon Oct 18, 2022
ef9c8a0
Update docs/release-notes/8.5.asciidoc
nastasha-solomon Oct 18, 2022
abd02eb
Update docs/release-notes/8.5.asciidoc
nastasha-solomon Oct 18, 2022
0139424
Merge branch 'main' into issue-2460-big
nastasha-solomon Oct 18, 2022
61e909a
Adding 142805
nastasha-solomon Oct 18, 2022
eaf6b7e
Merge branch 'main' into issue-2460-big
nastasha-solomon Oct 19, 2022
ea5c369
Added 143882, 144011, and 143362.
nastasha-solomon Oct 27, 2022
e8179ee
Update docs/release-notes/8.5.asciidoc
nastasha-solomon Oct 31, 2022
e02952a
Merge branch 'main' into issue-2460-big
nastasha-solomon Oct 31, 2022
4aacf43
Adds 140825
nastasha-solomon Oct 31, 2022
37fd7eb
Adds missing PR numbers and 139379
nastasha-solomon Oct 31, 2022
6583dff
Adds 140378 and 141847
nastasha-solomon Oct 31, 2022
b631578
Update docs/release-notes/8.5.asciidoc
nastasha-solomon Nov 1, 2022
2fd1610
Update docs/release-notes/8.5.asciidoc
nastasha-solomon Nov 1, 2022
5aafad7
Update docs/release-notes/8.5.asciidoc
nastasha-solomon Nov 1, 2022
7bdab5e
Update docs/release-notes/8.5.asciidoc
nastasha-solomon Nov 1, 2022
d26a025
Update docs/release-notes/8.5.asciidoc
nastasha-solomon Nov 1, 2022
e2e493d
Update docs/release-notes/8.5.asciidoc
nastasha-solomon Nov 1, 2022
df73858
Update docs/release-notes/8.5.asciidoc
nastasha-solomon Nov 1, 2022
7fd9f01
Update docs/release-notes/8.5.asciidoc
nastasha-solomon Nov 1, 2022
15aa9cc
Update docs/release-notes/8.5.asciidoc
nastasha-solomon Nov 1, 2022
d9a2beb
Update docs/release-notes/8.5.asciidoc
nastasha-solomon Nov 1, 2022
f1d6948
Update docs/release-notes/8.5.asciidoc
nastasha-solomon Nov 1, 2022
00b9459
Merge branch 'main' into issue-2460-big
nastasha-solomon Nov 1, 2022
8a14940
Update docs/release-notes/8.5.asciidoc
nastasha-solomon Nov 1, 2022
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 2 additions & 0 deletions docs/release-notes.asciidoc
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,7 @@

This section summarizes the changes in each release.

* <<release-notes-8.5.0, {elastic-sec} version 8.5.0>>
* <<release-notes-8.4.3, {elastic-sec} version 8.4.3>>
* <<release-notes-8.4.2, {elastic-sec} version 8.4.2>>
* <<release-notes-8.4.1, {elastic-sec} version 8.4.1>>
Expand All @@ -28,6 +29,7 @@ This section summarizes the changes in each release.
:issue: https://github.com/elastic/kibana/issues/
:pull: https://github.com/elastic/kibana/pull/

include::release-notes/8.5.asciidoc[]
include::release-notes/8.4.asciidoc[]
include::release-notes/8.3.asciidoc[]
include::release-notes/8.2.asciidoc[]
Expand Down
78 changes: 78 additions & 0 deletions docs/release-notes/8.5.asciidoc
Original file line number Diff line number Diff line change
@@ -0,0 +1,78 @@
[[release-notes-header-8.5.0]]
== 8.5

[discrete]
[[release-notes-8.5.0]]
=== 8.5.0

[discrete]
[[known-issue-8.5.0]]
==== Known issues
* Users might experience slightly longer installation and upgrade times for the user and host risk score features ({pull}142434[#142434]).

[discrete]
[[breaking-changes-8.5.0]]
==== Breaking changes
// tag::breaking-changes[]
// NOTE: The breaking-changes tagged regions are reused in the Elastic Installation and Upgrade Guide. The pull attribute is defined within this snippet so it properly resolves in the output.
:pull: {pull}
* Host and user risk score features that were installed in 8.4 or earlier are not ECS-compatible and therefore cannot generate new risk scores in 8.5.0. Before upgrading, users can archive their existing risk indices if they want to keep their "old" host and user risk scores. Otherwise, new risk indices will be generated once users upgrade host and user risk score features.
nastasha-solomon marked this conversation as resolved.
Show resolved Hide resolved
nastasha-solomon marked this conversation as resolved.
Show resolved Hide resolved
// end::breaking-changes[]

[discrete]
[[deprecations-8.5.0]]
==== Deprecations
* Deprecates the risk score index and displays the Upgrade button in host and user risk score cards on the the Entity Analytics dashboard ({pull}140143[#140143]).
nastasha-solomon marked this conversation as resolved.
Show resolved Hide resolved

[discrete]
[[features-8.5.0]]
==== Features
* Introduces the Entity Analytics dashboard, which showcases host and user risk scores and anomalies. Also adds host and user risk data to the user and host detail pages. These features require at least a platinum license ({pull}137688[#137688], {pull}140270[#140270], {pull}139462[#139462]).
nastasha-solomon marked this conversation as resolved.
Show resolved Hide resolved
* Update *Anomalies* tab to display the same quantity of anomalies when navigating from Entity Analytics dashboard ({pull}139910[#139910]).
nastasha-solomon marked this conversation as resolved.
Show resolved Hide resolved
* Enriches alerts with host and user risk scores ({pull}139478[#139478]).
* Enables the Intelligence page by default and makes the functionality generally available ({pull}141117[#141117]).
nastasha-solomon marked this conversation as resolved.
Show resolved Hide resolved
* Allows indicator data to be investigated in Timeline by including the *Add to Timeline* button throughout the Indicators table ({pull}138836[#138836], {pull}140496[#140496]).
* Removes the Host risk score card from the Overview dashboard ({pull}140177[#140177]).
* Adds the option to bulk edit rule schedules to the bulk actions menu in the Rules table ({pull}140166[#140166]).
* Adds the option to bulk edit rule actions to the bulk actions menu in the Rules table ({pull}138900[#138900]).
* Adds an alert count card to the User, Host, and Network detail pages. The card shows alerts per rule and can be filtered by alert status ({pull}140150[#140150]).
* Enables the Alerts related by process ancestry section by default. It appears in the Alert details flyout if you have a https://www.elastic.co/pricing[Platinum or Enterprise subscription]. Also allows users with a https://www.elastic.co/pricing[Platinum or Enterprise subscription] to examine alerts associated with events ({pull}140006[#140006]).
nastasha-solomon marked this conversation as resolved.
Show resolved Hide resolved
* Enables the Alerts related by session ID section by default. It appears in the Alert details flyout if you have a https://www.elastic.co/pricing[Platinum or Enterprise subscription].
* Renames the Elastic Endpoint and Cloud Security integration to the Elastic Defend integration ({pull}139517[#139517]).
* Adds preconfigured use-cases to the setup wizard for the Elastic Defend integration (formerly known as Endpoint and Cloud Security), each with different default settings ({pull}139230[#139230]).
nastasha-solomon marked this conversation as resolved.
Show resolved Hide resolved
* Updates the UI for the rule details flyout's *Exceptions* tab ({pull}138770[138770]).
nastasha-solomon marked this conversation as resolved.
Show resolved Hide resolved
* Enables the Osquery Response Action and adds an *Osquery Results* tab to the Alert details flyout. You can use the Osquery Response Action to immediately query hosts that generate alerts ({pull}133279[#133279]).
nastasha-solomon marked this conversation as resolved.
Show resolved Hide resolved
* Enables rule exceptions to reference value lists, regardless of rule type. One caveat is that text type value lists still do not work for EQL and threshold rules ({pull}133254[#133254]).
* Introduces the new alert renderer, which concisely displays a detailed summary of the `kibana.alert.reason` field. It appears in Timeline, throughout the Alerts page, and on the alert details flyout ({pull}140825[#140825]).
nastasha-solomon marked this conversation as resolved.
Show resolved Hide resolved

[discrete]
[[bug-fixes-8.5.0]]
==== Bug fixes and enhancements
* Fixes a bug that sometimes caused event correlation rule (EQL) errors whenever rule queries contain regular expressions using wildcard fields and predefined character classes (for example, `\w`, `\s`, `\d`) (https://github.com/elastic/elasticsearch/pull/90064[#90064]).
nastasha-solomon marked this conversation as resolved.
Show resolved Hide resolved
* Adds the `has_guide` tag to all prebuilt rules with investigation guides. Users can filter the Rules table by this tag to quickly find prebuilt rules with investigation guides (https://github.com/elastic/detection-rules/pull/2297[2297]).
nastasha-solomon marked this conversation as resolved.
Show resolved Hide resolved
* Informs you when the event analyzer's current time range is too narrow to include event data ({pull}140831[#140831]).
* Lets you inspect bar charts and data grids, as with other data visualizations ({pull}140810[#140810]).
* Makes the Indicators table sortable by any column ({pull}140582[#140582]).
* Provides the ability to add fields to Indicators table ({pull}138882[#138882]).
* Updates the rule preview UI ({pull}140221[#140221]).
nastasha-solomon marked this conversation as resolved.
Show resolved Hide resolved
* Adds an overview tab to the Indicator details flyout ({pull}140073[#140073]).
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
* Adds an overview tab to the Indicator details flyout ({pull}140073[#140073]).
* Adds an Overview tab to the Indicator details flyout ({pull}140073[#140073]).

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@jmikell821 just double-checking that Overview doesn't need to be bolded.

* Improves the UI for saved rule queries ({pull}140064[#140064]).
* Computes `threat.indicator.name` on the {es} server instead of on the client ({pull}139814[#139814]).
* Makes the state of tables throughout {es-sec} persist, for example when you toggle between table view and grid view ({pull}139696[#139696]).
* Lets you enable multiple filters using various plus `+` and minus `-` buttons. Previously, adding a new filter in this way could remove the existing filters ({pull}139616[#139616]).
* Updates rule details page URLs to specify which tab to focus ({pull}139592[#139592]).
* Simplifies the process of adding a rule exception ({pull}138169[#138169]).
* Hides the process ancestry insights interface when data is not available ({pull}141751[#141751]).
nastasha-solomon marked this conversation as resolved.
Show resolved Hide resolved
* Formats the Rules table's `Last Gap` column in a human-readable way ({pull}141363[#141363]).
nastasha-solomon marked this conversation as resolved.
Show resolved Hide resolved
* Introduces fuzzy search for user names in the Actions Log ({pull}141239[#141239]).
* Improves the *Add Field* menu ({pull}141084[#141084]).
nastasha-solomon marked this conversation as resolved.
Show resolved Hide resolved
* Restores your ability to create exceptions with leading or trailing white space ({pull}139617[#139617]).
* Fixes two minor bugs with the *Overwrite existing rules* option for rule import ({pull}138758[#138758],{pull}139470[#139470]).
nastasha-solomon marked this conversation as resolved.
Show resolved Hide resolved
* Fixes a bug that made the `binary` field type seem appear usable in Exception entries despite not being supported ({pull}139370[#139370]).
nastasha-solomon marked this conversation as resolved.
Show resolved Hide resolved
* Fixes a bug that prevented a toast message from appearing after you export a rule from the rule details page ({pull}139209[#139209]).
* Fixes sorting and pagination bugs on the *Import value lists* menu ({pull}138381[#138381]).
* Mimics native link behavior for single page application links ({pull}142304[#142304]).
nastasha-solomon marked this conversation as resolved.
Show resolved Hide resolved
* Fixes validation issues within the rule Actions tab ({pull}141811[#141811]).
* Fixes a bug with visualization types on the Hosts, Network, Users page ({pull}141235[#141235]).
* Updates the documentation link in the Trusted applications page ({pull}142467[#142467]).
nastasha-solomon marked this conversation as resolved.
Show resolved Hide resolved
* Provides the ability to run Osquery from a rule's investigation guide ({pull}95149[#95149]).