IMPORTANT: This documentation is no longer updated. Refer to Elastic's version policy and the latest documentation.

Beats version 8.15.4

edit

View commits

Known Issues

edit

Affecting all Beats

  • Disk queue filled metrics can underflow after blocked publishes. When a disk queue reaches its configured capacity, inputs can block until the output acknowledges events. The queue then accepts the blocked event without updating its metrics. When the event is later removed, the queue.filled.events, queue.filled.bytes, and queue.filled.pct metrics might report incorrect values. Event delivery is unaffected. Upgrade to 8.19.21 or later to apply the fix.

Filebeat

  • The Filestream input does not enforce the restrictions documented for the clean_inactive option, thus allowing configurations that can lead to data re-ingestion issues.
  • When clean_inactive: 0, Filestream cleans the state of all files on start up, effectively re-ingesting all files on restart. Set clean_inactive to a very large value. For example, use clean_inactive: 43800h0m0s, which is 5 years.

Breaking changes

edit

Osquerybeat

  • Disable allow_unsafe osquery configuration. 40130

Bugfixes

edit

Affecting all Beats

  • Fix issue where old data could be saved in the memory queue after acknowledgment, increasing memory use. 41356

Filebeat

  • Log bad handshake details when websocket connection fails. 41300
  • Improve modification time handling for entities and entity deletion logic in the Active Directory entityanalytics input. 41179
  • Fix double encoding of client_secret in the Entity Analytics input’s Azure Active Directory provider. 41393
  • The azure-eventhub input now correctly reports its status to the Elastic Agent on fatal errors. 41469

Metricbeat

  • Fix Kubernetes metadata sometimes not being present after startup. 41216

Winlogbeat

  • Fix truncated windows event log message. 41327

Added

edit

Affecting all Beats

  • Replace Ubuntu 20.04 with 24.04 for Docker base images. 40743 40942
  • Reduce memory consumption of k8s autodiscovery and the add_kubernetes_metadata processor when Deployment metadata is enabled.

Heartbeat

  • Add monitor status reporter under managed mode. 41077

Metricbeat

  • Only watch metadata for ReplicaSets in metricbeat k8s module. 41289