Releases: elastic/ecs
Releases · elastic/ecs
ECS 9.0.0-rc1
Schema Changes
Breaking changes
- Remove deprecated fields from previous major release; process.pgid, service.node.role, and inherited users. #2410
Bugfixes
- Fix link rendering issues and usage of http in links. #2423
Added
- Add origin_referrer_url and origin_url fields, which indicate the origin information to the file, process and dll schemas. #2441
Improvements
- Increase ignore_above value for url.query. #2424
- Set synthetic_source_keep = none on fields that represent sets. #2422
- Promote beta fields to GA. #2411
- Restrict the encoding of x509.serial_number to base 16. #2398
- Define base encoding of x509.serial_number. #2383
Tooling and Artifact Changes
Added
- Add mapping between ECS and OpenTelemetry. #2415
Improvements
- Update data_stream.yml with top level type: group. #2414
ECS 8.17.0
ECS 8.16.0
Schema Changes
Bugfixes
- Fix broken link in docs for vulnerability.id. #2328
Added
- Added
volume.*
as beta field set. #2269 - Advanced
process.env_vars
to GA. #2315 - Advanced
process.io
andprocess.tty
fields to GA. #2317 - Added
threat.indicator.id
. #2324 - Added
process.group
to generated schemas. #2335
Improvements
- Define base encoding of
x509.serial_number
. #2383
Tooling and Artifact Changes
Bugfixes
- Fix broken link for vulnerabilty.id #2328
Added
- Documentation in README.md providing instruction on contributions to ECS during the OTel donation #2325
ECS 8.11.0
ECS 8.10.0
ECS 8.10.0
Schema Changes
Added
- Added
container.security_context.privileged
to indicated whether a container was started in privileged mode. #2219, #2225, #2246 - Added
process.thread.capabilities.permitted
to contain the current thread's possible capabilities. #2245 - Added
process.thread.capabilities.effective
to contain the current thread's effective capabilities. #2245
Improvements
- Permit
ignore_above
if explicitly set on aflattened
field. #2248
Tooling and Artifact Changes
Improvements
ECS 8.9.0
ECS 8.8.0
ECS 8.8.0
Schema Changes
Added
- Add
access
as an allowed type forevent.type: file
. #2174 - Add
orchestrator.resource.annotation
andorchestrator.resource.label
. #2181 - Add
event.kind: asset
as a beta category. #2191
Tooling and Artifact Changes
Added
- Add
parameters
property for field definitions, to provide any mapping parameter. #2084
ECS 8.7.0
Schema Changes
Bugfixes
- remove duplicated
client.domain
definition #2120
Added
- adding
name
field tothreat.indicator
#2121 - adding
api
option toevent.category
#2147 - adding
library
option toevent.category
#2154
Improvements
- description for
host.name
definition updated to encourage use of FDQN #2122
Tooling and Artifact Changes
Improvements
ECS 8.7.0-rc1
Schema Changes
Bugfixes
- remove duplicated
client.domain
definition #2120
Added
- adding
name
field tothreat.indicator
#2121 - adding
api
option toevent.category
#2147 - adding
library
option toevent.category
#2154
Improvements
- description for
host.name
definition updated to encourage use of FDQN #2122