Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

8.9.0 Release notes #3536

Merged
merged 44 commits into from
Jul 25, 2023
Merged
Show file tree
Hide file tree
Changes from 29 commits
Commits
Show all changes
44 commits
Select commit Hold shift + click to select a range
d5bf1ba
First draft
nastasha-solomon Jul 6, 2023
f086efe
Adding include to TOC
nastasha-solomon Jul 6, 2023
33f4824
Merge branch 'main' into 8.9.0-rn
nastasha-solomon Jul 6, 2023
dd8f0e2
Fixed file name
nastasha-solomon Jul 6, 2023
168439d
Updating anchors and bc tags
nastasha-solomon Jul 17, 2023
9c900f0
Full rewrite of contents
benironside Jul 18, 2023
0eb2beb
Removing extra breaking changes tag
nastasha-solomon Jul 18, 2023
5c7103b
Merge branch 'main' into 8.9.0-rn
nastasha-solomon Jul 18, 2023
7a173ef
Removed discrete header
nastasha-solomon Jul 18, 2023
7288f00
Re-adding header
nastasha-solomon Jul 18, 2023
50afd4f
Update docs/release-notes/8.9.asciidoc
nastasha-solomon Jul 18, 2023
2360195
Hopefully fixing bc link
nastasha-solomon Jul 18, 2023
a83800d
Update docs/release-notes/8.9.asciidoc
nastasha-solomon Jul 18, 2023
9477453
Incorporates feedback
benironside Jul 20, 2023
9fb165a
edits
benironside Jul 20, 2023
17c1c70
Update docs/release-notes/8.9.asciidoc
nastasha-solomon Jul 23, 2023
beb793b
Update docs/release-notes/8.9.asciidoc
nastasha-solomon Jul 23, 2023
0595591
Update docs/release-notes/8.9.asciidoc
nastasha-solomon Jul 23, 2023
f128dd8
Update docs/release-notes/8.9.asciidoc
nastasha-solomon Jul 23, 2023
444d07c
Update docs/release-notes/8.9.asciidoc
nastasha-solomon Jul 23, 2023
f3e26f8
Janeen's input
nastasha-solomon Jul 23, 2023
1f04142
Merge branch '8.9.0-rn' of github.com:elastic/security-docs into 8.9.…
nastasha-solomon Jul 23, 2023
b31ba03
More edits from Janeen
nastasha-solomon Jul 23, 2023
f313954
Merge branch 'main' into 8.9.0-rn
nastasha-solomon Jul 23, 2023
63e618e
Update docs/release-notes/8.9.asciidoc
nastasha-solomon Jul 23, 2023
395c8fd
Removing ResponseOps PR
nastasha-solomon Jul 23, 2023
da4bbca
Merge branch '8.9.0-rn' of github.com:elastic/security-docs into 8.9.…
nastasha-solomon Jul 23, 2023
900eacc
Adds remaining content
nastasha-solomon Jul 23, 2023
ca90019
EDR team features
nastasha-solomon Jul 23, 2023
7323ddb
Removing bc tags for 8.8.2 rn
nastasha-solomon Jul 23, 2023
066ddbd
Update docs/release-notes/8.8.asciidoc
nastasha-solomon Jul 24, 2023
416d836
Update docs/release-notes/8.9.asciidoc
nastasha-solomon Jul 24, 2023
d15b026
Re-adding bc tags to 8.8.asciidoc file
nastasha-solomon Jul 24, 2023
c3a2e62
Update docs/release-notes/8.9.asciidoc
nastasha-solomon Jul 24, 2023
b4c83b2
Update docs/release-notes/8.9.asciidoc
nastasha-solomon Jul 24, 2023
cfb2222
Update docs/release-notes/8.9.asciidoc
nastasha-solomon Jul 24, 2023
acced87
Merge branch 'main' into 8.9.0-rn
nastasha-solomon Jul 24, 2023
397d33a
Updating sum for 160574 and 160577
nastasha-solomon Jul 24, 2023
6ff5a4b
Jatin's feedback
nastasha-solomon Jul 24, 2023
5ed5fbc
Merge branch 'main' into 8.9.0-rn
benironside Jul 25, 2023
4e89510
Update docs/release-notes/8.9.asciidoc
benironside Jul 25, 2023
74f6d33
Merge branch 'main' into 8.9.0-rn
benironside Jul 25, 2023
724f878
Merge branch 'main' into 8.9.0-rn
benironside Jul 25, 2023
56a170a
Merge branch 'main' into 8.9.0-rn
benironside Jul 25, 2023
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 2 additions & 0 deletions docs/release-notes.asciidoc
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,7 @@

This section summarizes the changes in each release.

* <<release-notes-8.9.0, {elastic-sec} version 8.9.0>>
* <<release-notes-8.8.2, {elastic-sec} version 8.8.2>>
* <<release-notes-8.8.1, {elastic-sec} version 8.8.1>>
* <<release-notes-8.8.0, {elastic-sec} version 8.8.0>>
Expand Down Expand Up @@ -40,6 +41,7 @@ This section summarizes the changes in each release.
:issue: https:/elastic/kibana/issues/
:pull: https:/elastic/kibana/pull/

include::release-notes/8.9.asciidoc[]
include::release-notes/8.8.asciidoc[]
include::release-notes/8.7.asciidoc[]
include::release-notes/8.6.asciidoc[]
Expand Down
5 changes: 0 additions & 5 deletions docs/release-notes/8.7.asciidoc
Original file line number Diff line number Diff line change
Expand Up @@ -231,12 +231,7 @@ GET .kibana*/_search
[[breaking-changes-8.7.0]]
==== Breaking changes

//tag::breaking-changes[]
// NOTE: The breaking-changes tagged regions are reused in the Elastic Installation and Upgrade Guide. The pull attribute is defined within this snippet so it properly resolves in the output.
:pull: https:/elastic/kibana/pull/
There are no breaking changes in 8.7.0.
//end::breaking-changes[]


[discrete]
[[deprecations-8.7.0]]
Expand Down
72 changes: 72 additions & 0 deletions docs/release-notes/8.9.asciidoc
Original file line number Diff line number Diff line change
@@ -0,0 +1,72 @@
[[release-notes-header-8.9.0]]
== 8.9.0

[discrete]
[[release-notes-8.9.0]]
=== 8.9

[discrete]
[[known-issue-8.9.0]]
==== Known issues

* On the new Detection rule monitoring dashboard, total `Rule executions` will not always equal the sum of `Succeeded`, `Warning`, and `Failed` executions. This is expected because rules can write multiple statuses per execution. One typical example is gap detection: if a rule detects a gap in rule execution it will write an intermediate `Failed` status, then continue to run, and write a final status (such as `Warning`) before finishing its execution.
* Rule changes can't be saved if the rule's action frequency is shorter than the rule's run interval.
nastasha-solomon marked this conversation as resolved.
Show resolved Hide resolved
* The upload response action does not report the correct amount of available disk space. The correct amount is approximately four gigabytes.
Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@nfritts please review this summary when you can. Thank you!

nastasha-solomon marked this conversation as resolved.
Show resolved Hide resolved

[discrete]
[[breaking-changes-8.9.0]]
==== Breaking changes
//tag::breaking-changes[]
// NOTE: The breaking-changes tagged regions are reused in the Elastic Installation and Upgrade Guide. The pull attribute is defined within this snippet so it properly resolves in the output.
// THIS ALSO MEANS IF YOU USE LINKS HERE, THEY SHOULD BE FULL URLS WITH NO ATTRIBUTES

:pull: https:/elastic/kibana/pull/

There are no breaking changes in 8.9.0.

//end::breaking-changes[]

[discrete]
[[deprecations-8.9.0]]
==== Deprecations
* Removes the option to use the legacy navigation menu ({pull}158094[#158094]).
* Several prebuilt threat indicator match rules were deprecated and replaced with improved indicator type rules.
benironside marked this conversation as resolved.
Show resolved Hide resolved
benironside marked this conversation as resolved.
Show resolved Hide resolved

[discrete]
[[features-8.9.0]]
==== New features
* Allows you to install the Cloud Security Posture Management (CSPM) integration via CloudFormation ({pull}159994[#159994]).
* Creates a new dashboard, Cloud Native Vulnerability Management, that provides an overview of vulnerabilities on your cloud hosts ({pull}159699[#159699]).
* Allows you to group vulnerabilities by resource (host) on the Vulnerabilities Findings page, and creates a Resource flyout that displays detailed vulnerability findings for individual hosts ({pull}159873[#159873], {pull}158987[#158987]).
* Adds a new custom dashboard, "Detection rule monitoring" ({pull}159875[#159875]).
* Allows you to anonymize event field values sent to AI Assistant ({pull}159857[#159857]).
* Adds a *Chat* button that opens AI Assistant to the alert details flyout ({pull}159633[#159633]).
* Updates AI Assistant to let you create and delete custom system prompts and default conversations ({pull}159365[#159365]).
* Allows you to add alert tags ({pull}157786[#157786]).
* Adds the ability to automatically isolate a host through a rule’s endpoint response action.
* Moves response actions to General Availability.
* Adds a new response action that allows you to upload files to an endpoint that has {elastic-endpoint} installed.
Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@kevinlog @caitlinbetz would you mind reviewing lines 46-48 when you have a moment? I couldn't find the PRs for these features so please let me know what those are if they should be included. Thank you!

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I found a couple of possible PRs to reference, but not for all three lines.

nastasha-solomon marked this conversation as resolved.
Show resolved Hide resolved
* Makes the Lateral Movement Detection advanced analytics package General Availability, and adds the ability to detect malicious activities in Windows RDP events (https:/elastic/integrations/pull/6588[#6588]).

[discrete]
[[enhancements-8.9.0]]
==== Enhancements
nastasha-solomon marked this conversation as resolved.
Show resolved Hide resolved
* Adds a *Last response* dropdown menu to the Rules table that allows you to filter rules by the status of their last execution ("Succeeded", "Warning", or "Failed") ({pull}159865[#159865]).
* Creates a Lens dashboard for monitoring the use of tokens by AI Assistant ({pull}159075[#159075]).
* Creates a connector for D3 Security ({pull}158569[#158569]).
* Improves the interface for installing and upgrading Elastic prebuilt rules ({pull}158450[#158450]).
* Shows a rule's actions on its details page ({pull}158189[#158189]).
* Allows you to add Lens visualizations to cases from the visualization's *More actions* menu ({pull}154918[#154918]).
* Adds a tooltip to snoozed rules that shows exactly when alerting will resume ({pull}157407[#157407]).
* Enhances the Data Exfiltration Detection package by adding the ability to detect exfiltration anomalies through USB devices and Airdrop (https:/elastic/integrations/pull/6577[#6577]).

[discrete]
[[bug-fixes-8.9.0]]
==== Bug fixes
nastasha-solomon marked this conversation as resolved.
Show resolved Hide resolved
* Fixes a bug that prevented rule exceptions from being auto-populated when you created a new exception from an alert's **Take action** menu.
* Fixes a UI bug that overlaid **Default Risk score** values as you created a new rule.
* Fixes a bug that restricted the number of cloud accounts which could appear on the Cloud Security Posture dashboard to 10 ({pull}157233[#157233]).
nastasha-solomon marked this conversation as resolved.
Show resolved Hide resolved
* Fixes a bug that allowed you to save a rule with an alert filter missing a query ({pull}159690[#159690]).
* Fixes inconsistent filtering behavior on the Alerts page. Now, when you select a filter that would exclude all alerts, an empty table appears as expected ({pull}160374[#160374]).
* Improves input validation for investigation guide queries ({pull}160574[#160574], {pull}160577[#160577]).
* Fixes a bug that caused rules to snooze longer than specified ({pull}152873[#152873]).