Beats version 8.18.2
edit
IMPORTANT: This documentation is no longer updated. Refer to Elastic's version policy and the latest documentation.
Beats version 8.18.2
editKnown Issues
editAffecting all Beats
-
Disk queue filled metrics can underflow after blocked publishes. When a disk queue reaches its configured capacity, inputs can block until the output acknowledges events. The queue then accepts the blocked event without updating its metrics. When the event is later removed, the
queue.filled.events,queue.filled.bytes, andqueue.filled.pctmetrics might report incorrect values. Event delivery is unaffected. Upgrade to 8.19.21 or later to apply the fix.
Filebeat
-
The Filestream input does not enforce the restrictions documented for the
clean_inactiveoption, thus allowing configurations that can lead to data re-ingestion issues. -
When
clean_inactive: 0, Filestream cleans the state of all files on start up, effectively re-ingesting all files on restart. Setclean_inactive: -1to disable this behavior.
Bugfixes
editAffecting all Beats
- Fix the add_cloud_metadata processor to better support custom certificate bundles by improving how the AWS provider HTTP client is overridden. 44189
Auditbeat
Filebeat
Osquerybeat
- Disable the allow_unsafe osquery configuration. 40130
Added
editAffecting all Beats
- Update Go version to v1.24.3. 44270
Metricbeat
- Add checks for the Resty response object in all Meraki module API calls to ensure proper handling of nil responses. 44193
-
Add
enable_batch_apioption in the Azure monitor module to allow metrics collection of multiple resources using Azure batch API. 41790 -
Add support for
_nodes/statsURIs compatible with legacy Elasticsearch versions. 44307 - Add a latency configuration option to the Azure Monitor module. 44366
Osquerybeat
- Update osquery version to v5.15.0. 43426