IMPORTANT: This documentation is no longer updated. Refer to Elastic's version policy and the latest documentation.

Beats version 8.18.1

edit

View commits

Known Issues

edit

Affecting all Beats

  • Disk queue filled metrics can underflow after blocked publishes. When a disk queue reaches its configured capacity, inputs can block until the output acknowledges events. The queue then accepts the blocked event without updating its metrics. When the event is later removed, the queue.filled.events, queue.filled.bytes, and queue.filled.pct metrics might report incorrect values. Event delivery is unaffected. Upgrade to 8.19.21 or later to apply the fix.

Filebeat

  • The Filestream input does not enforce the restrictions documented for the clean_inactive option, thus allowing configurations that can lead to data re-ingestion issues.
  • When clean_inactive: 0, Filestream cleans the state of all files on start up, effectively re-ingesting all files on restart. Set clean_inactive: -1 to disable this behavior.

Bugfixes

edit

Filebeat

  • Journald input now works on Docker containers (only ubi variant). 41278 44040 44056
  • Fixed websocket input panic on sudden network error or server crash. 44063 44068
  • [Filestream] Log the "reader closed" message on the debug level to avoid log spam. 44051
  • Fix links to CEL mito extension functions in input documentation. 44098

Added

edit

Filebeat

  • Add pagination batch size support to Entity Analytics input’s Okta provider. 43655
  • Update CEL mito extensions to v1.19.0. 44098