Beats version 8.19.13
edit
IMPORTANT: This documentation is no longer updated. Refer to Elastic's version policy and the latest documentation.
Beats version 8.19.13
editKnown issues
editAll
-
Disk queue filled metrics can underflow after blocked publishes. When a disk queue reaches its configured capacity, inputs can block until the output acknowledges events. The queue then accepts the blocked event without updating its metrics. When the event is later removed, the
queue.filled.events,queue.filled.bytes, andqueue.filled.pctmetrics might report incorrect values. Event delivery is unaffected. Upgrade to 8.19.21 or later to apply the fix.
Filebeat
- Filestream "take over" mode does not work in versions 8.19.0-8.19.20. A fix will ship in the 8.19.21 release.
Security updates
editAll
Osquerybeat
-
Update
osquery-godependency to v0.0.0-20260226222546-0cc22f415e57. #49280
New features
editElastic Agent
- Fix a bug that could report stopped inputs as still running. #49285
Metricbeat
Enhancements
editFilebeat
Metricbeat
Packetbeat
Bug fixes
editAll
Filebeat
- Fix Kubernetes secret variable resolution in Filebeat autodiscover hints. #48787
- Fix Active Directory entity analytics to resolve nested group membership and escape DN filter values. #48815
- Fix handling of Crowdstrike streaming input state in retryable errors. #49077
-
Fix memory leak when
harvester_limitis set. #49114 - Demote missing user/device state lookup to debug log in Azure entity analytics provider. #49127
- Fix CrowdStrike streaming session refresh scheduling to avoid tight refresh loops. #49175 #49158
Winlogbeat