docs/release-notes/index.md
Review the changes, fixes, and more in each version of Kibana.
To check for security updates, go to Security announcements for the Elastic stack.
% Release notes include only features, enhancements, and fixes. Add breaking changes, deprecations, and known issues to the applicable release notes sections.
% ## version.next [kibana-X.X.X-release-notes]
% ### Features and enhancements [kibana-X.X.X-features-enhancements] % *
% ### Fixes [kibana-X.X.X-fixes] % *
% FEATURES, ENHANCEMENTS, FIXES % Paste in index.md
Alerting:
xpack.alerting.alertsService.totalFieldsLimit (default 2800, range 2500–5000) to control the {{es}} index.mapping.total_fields.limit on .alerts-* indices, index templates, and component templates. Raise this above the current alert mapping field count to prevent mapping-update failures on large clusters with many rule types or custom alert fields #274024.Elastic Agent Builder:
GROK retain the correct escape levels when queries are embedded as JSON #272493.Alerting:
Dashboards and Visualizations:
labs:dashboard:deferBelowFold) because enabling it can cause some dashboards to fail to load. The option remains in Advanced Settings but has no effect from this version. It might be enabled again in a future version #275632.Connectivity:
Data ingestion and Fleet:
POST /api/fleet/setup performance for deployments with many configured outputs by fetching only the required outputs instead of decrypting all saved outputs on each call #273848.withAgentCount=true) to compute agent counts using a single aggregation instead of multiple queries per policy, greatly improving response time for large deployments #272429.xpack.fleet.productVersionsApiTimeoutMs (default: 60 s) to control the request timeout #272715.Discover:
null and undefined field values in the {{esql}} document summary column incorrectly counting toward the discover:maxDocFieldsDisplayed limit, which caused fields with real values to be hidden #273610.{{esql}} editor:
Elastic Observability solution: For the Elastic Observability 9.4.3 release information, refer to Elastic Observability Solution Release Notes.
Elastic Security solution: For the Elastic Security 9.4.3 release information, refer to Elastic Security Solution Release Notes.
Kibana platform:
notifications.connectors.default.email as a Docker environment variable #272761.run_as configurations, ensuring the nav bar displays the effective user's avatar and name rather than the proxy user's #271314.Management:
elasticsearch.query debug logger (method, path, and response status; request bodies are not included since Console streams them), and adds support for URL path prefixes in elasticsearch.hosts for Console proxy requests #271562.Workflows:
:::{important} The 9.4.2 release contains fixes for potential security vulnerabilities. Check our security advisory for more details. :::
Search:
Alerting and cases:
Connectivity:
server.basePath and space URL prefixes, preventing 404s on connector detail tabs and after creation #269571.Dashboards and Visualizations:
enhancements property #270230.rank_by with operation: "count" on terms buckets when no field is specified, so Count can rank by all documents without a field #268620.min, max, and goal configuration to reject unsupported reference-based metric operations (moving_average, differences, cumulative_sum, counter_rate) that require a date histogram #268168.Data ingestion and Fleet:
elasticsearch fields in integration packages on upgrade or reinstall #269080.event.ingested instead of @timestamp #268224.Discover:
{{esql}} editor:
null in CASE() expressions combined with other types #269051.Elastic Observability solution: For the Elastic Observability 9.4.2 release information, refer to Elastic Observability Solution Release Notes.
Elastic Security solution: For the Elastic Security 9.4.2 release information, refer to Elastic Security Solution Release Notes.
Management:
Machine Learning:
Workflows:
with block optional in workflow YAML for connector steps that have no required parameters #269047.Alerting:
kibana.alert.reason, on active alert documents when a delayed alert graduates to active during a flapping hold without an executor report. #266012Dashboards and Visualizations:
null titles. Control titles are now converted to undefined during transforms, allowing validation to pass #268220.Elastic Security solution: For the Elastic Security 9.4.1 release information, refer to Elastic Security Solution Release Notes.
:::{important} - New recommended {{kib}} instance minimum size of 2 GB
We now recommend that your {{kib}} instances have at least 2 GB of memory, especially when using Platinum or Enterprise {{kib}} features, and for production workloads.
New {{ech}} deployments now default to 2 GB of RAM for each {{kib}} instance. :::
Alerting:
maximumCasesToOpen a runtime property #259255.maximumCasesToOpen parameter in the case action connection #247990.Elastic Agent Builder:
configuration_overrides in agent_builder/converse API #249256.Connectivity:
region parameter to the Bedrock Connector #252956.Dashboards and Visualizations: % main features
% controls
% sections
% dashboard usability
% discover sessions in dashboards
% esql + viz
% chart options and improvements
Data ingestion and Fleet:
template_paths #257730.migrate_from field is specified in the package manifest #242934.Discover: % esql mode
STATS ... BY with a single grouping field. A new toolbar selector lets you pivot by that field or switch back to the standard table view. #220119.% metrics
tdigest and exponential_histogram histogram metrics in the Discover metrics grid #249269.% tabs and sessions
% general
% doc viewer
{{esql}} editor: % new commands and language features
USER_AGENT command #261314.MMR command #257208.approximate setting in the {{esql}} editor #248946.% GA commands
FORK command generally available #261904.RERANK command generally available #252242.% editor UI and experience
MATCH_PHRASE's second argument now only suggests literal values, and FTS functions are excluded from EVAL suggestions except inside SCORE() #247003.Elastic Observability solution: For the Elastic Observability 9.4.0 release information, refer to Elastic Observability Solution Release Notes.
Elastic Security solution: For the Elastic Security 9.4.0 release information, refer to Elastic Security Solution Release Notes.
Kibana platform:
Machine Learning:
v3_rare_process_by_host_windows bucket span to two hours #255855.location field to correctly set provider config in AI/Inference Connector creation #250838.timeout parameter to InferenceChatModel #248326.Search:
semantic_text fields when it's available #257464.semantic_text field inference endpoint select #249265.Workflows:
workflows.executionFailed trigger so you can run workflows when another workflow fails. Use it to send notifications (for example, Slack), run cleanup, or trigger retries #257633.entries Liquid filter for iterating over object keys #259249.Alerting:
active in {{kib}} instead of transitioning to recovered #261012.uiamApiKey leaking through object spread in rule updates #263887.sourceFields #263634.application/x-zip-compressed MIME type as an accepted value for cases file attachment #262414.cloneRule leaking source rule API keys to cloned rules #260549.incremental_id drift issues #258789.accessTokenUrl validation #258290.scheduleUnusedUrlsCleanupTask() #254574.204 responses #251090.total_event in the Elasticsearch document when attaching an event #247996.Connectivity:
defaultModel not being injected for the Other OpenAI provider on run and test sub-actions #260747.Dashboards and Visualizations:
timeFilter's quick mode in Maps stored state, that could prevent maps from loading #255178.| LIMIT 10 from the {{esql}} panel in dashboards when creating a visualization in Lens #247427.runtime_mappings being ignored or overridden in Vega visualization data requests #253560.Data ingestion and Fleet:
NOT latest_revision:false instead of latest_revision:true #263717.input_output in inference processor #260517.data_stream.type validation error for input-only integrations that use dynamic signal types, such as OpenTelemetry collector packages #258143.Discover:
{{esql}} editor:
STATS #260998.STATS generated columns with inline WHERE #260196.TS (time series) command #253635.GROK patterns not being recognized, which caused columns to appear as unknown #246871.Elastic Observability solution: For the Elastic Observability 9.4.0 release information, refer to Elastic Observability Solution Release Notes.
Elastic Security solution: For the Elastic Security 9.4.0 release information, refer to Elastic Security Solution Release Notes.
Kibana platform:
auto_expand_replicas to fix yellow health on single-node Elasticsearch clusters #263096.waitFor for the privilege button #255094.dateFormat:tz) #249016.createAuditEvents always returning failure as outcome #247152.Machine Learning:
time_of_day / time_of_week values in anomaly detection alerting rule notifications and results preview #261034.Management:
source_index entries when source_index is an array #261875.prefer_ilm is set. Index management's data view list now shows the current configuration in the Retention column #254609.{}/[] snippets instead of quoted braces when selecting suggestions in request bodies #256286.Search:
exact_fuzzy option from the Query Rules UI #258278.Elastic Agent Builder:
match_only_text and pattern_text #252082.origin on attachments for by-reference flows, and rejects attachments with neither data nor origin #259043.platform.core.search tool and index_search tool type where nested fields were ignored when searching for matching documents #255914.semantic_text fields #247877.Workflows:
allowedHosts at execution time #258080.viewInAppUrl and fixes ?? bug in redirect #257910.data.map steps #257703.Alerting and cases:
Connectivity:
Dashboards and Visualizations:
Data ingestion and Fleet:
POST /api/fleet/setup performance for deployments with a large number of configured outputs by no longer decrypting every output on each call #273848.Discover:
null values against the displayed field limit, which could hide fields with real values behind an "and X more fields" label #273610.Elastic Observability solution: For the Elastic Observability 9.3.7 release information, refer to Elastic Observability release notes.
Elastic Security solution: For the Elastic Security 9.3.7 release information, refer to Elastic Security release notes.
Kibana platform:
Management:
Alerting:
Connectivity:
Dashboards and Visualizations:
Data ingestion and Fleet:
GET /api/fleet/agent_policies (with withAgentCount=true) to compute agent counts in a single bucketed aggregation instead of multiple queries per policy, significantly reducing response time for deployments with many agent policies #272429.title field #272089.Discover:
Elastic Observability solution: For the Elastic Observability 9.3.6 release information, refer to Elastic Observability Solution Release Notes.
Elastic Security solution: For the Elastic Security 9.3.6 release information, refer to Elastic Security Solution Release Notes.
Kibana platform:
notifications.connectors.default.email to the list of supported Docker environment variables #272761.:::{important} The 9.3.5 release contains fixes for potential security vulnerabilities. Check our security advisory for more details. :::
Alerting and cases:
params values exceed Elasticsearch field size limits by adding ignore_above: 4096 to the actions.params mapping #269467.total_fields.limit because system-managed read-only fields were included in the update request #262534.Connectivity:
Dashboards and Visualizations:
Data ingestion and Fleet:
parse_exception by sorting agent policies on updated_at instead of the non-existent created_at field #267285.installed_es asset references for input packages and leave the Assets tab blank #266841.Discover:
METADATA _index, _id is available, and shows the original document without pagination when that result is no longer in the refreshed set #268328.Elastic Observability solution: For the Elastic Observability 9.3.5 release information, refer to Elastic Observability Solution Release Notes.
Elastic Security solution: For the Elastic Security 9.3.5 release information, refer to Elastic Security Solution Release Notes.
Kibana platform:
Machine Learning:
Management:
database_file and showing duplicate selections when a local database filename matches a managed database label #265740.server.basePath and {{kib}} space prefixes, resolving 404 errors on connector detail tabs and the post-creation Manage connector action #269571.Search:
.snippet values #265319.Elastic Observability solution: For the Elastic Observability 9.3.4 release information, refer to Elastic Observability Release Notes.
Elastic Security solution: For the Elastic Security 9.3.4 release information, refer to Elastic Security Release Notes.
Kibana platform:
Alerting:
active in {{kib}} instead of transitioning to recovered #261012.application/x-zip-compressed MIME type as an accepted value for case file attachments #262414.Data ingestion and Fleet:
# character by properly URL-encoding the content #264083.elasticsearch.compression is enabled #262394.input_output configuration shape #260517.Data management:
source_index entries when source_index is an array #261875.Discover:
STATS #260998.Kibana platform:
Machine Learning:
hono and @hono/node-server dependencies #263794.foreach has many iterations #253576.% ::::{NOTE} % ::::
Alerting:
accessTokenUrl validation #258290.Dashboards and Visualizations:
savedObjectId is present without saved object references #257779.Data ingestion and Fleet:
Data management:
Elastic Observability solution: For the Elastic Observability 9.3.3 release information, refer to Elastic Observability Solution Release Notes.
Elastic Security solution: For the Elastic Security 9.3.3 release information, refer to Elastic Security Solution Release Notes.
Elasticsearch solution:
semantic_text field in the Index Management mappings editor #256586.Machine Learning:
:::{important} The 9.3.2 release contains fixes for potential security vulnerabilities. Check our security advisory for more details. :::
Elastic Security solution: For the Elastic Security 9.3.2 release information, refer to Elastic Security Solution Release Notes.
Connectivity:
Elastic Agent Builder:
platform.core.search tool and index_search tool type where nested fields were ignored when searching for matching documents #255914.xpack.actions configuration property) #255813.Alerting:
204 responses #251090.Dashboards and Visualizations:
quick mode value #255178.Data ingestion and Fleet:
Discover:
Elastic Observability solution: For the Elastic Observability 9.3.2 release information, refer to Elastic Observability Solution Release Notes.
Elastic Security solution: For the Elastic Security 9.3.2 release information, refer to Elastic Security Solution Release Notes.
Kibana platform:
Kibana security:
waitFor for the privilege button #255094.Machine Learning:
Management:
Search:
:::{important} The 9.3.1 release contains fixes for potential security vulnerabilities. Check our security advisory for more details. :::
Data ingestion and Fleet:
Elastic Security solution: For the Elastic Security 9.3.1 release information, refer to Elastic Security Solution Release Notes.
Machine Learning:
Alerting and cases:
Connectivity:
Dashboards and Visualizations:
runtime_mappings being ignored or overridden in Vega specs when defined in data[].url.body #253560.Data ingestion and Fleet:
Discover:
Elastic Observability solution: For the Elastic Observability 9.3.1 release information, refer to Elastic Observability Solution Release Notes.
Elastic Security solution: For the Elastic Security 9.3.1 release information, refer to Elastic Security Solution Release Notes.
Kibana platform:
Machine Learning:
Management:
Search:
Workflows:
% ::::{NOTE} % ::::
Elastic Agent Builder:
Alerting:
kibana.alert.index_pattern to all Stack alerts. This change doesn't affect detection alerts #239450.Connectivity:
Dashboards and Visualizations:
Data ingestion and Fleet:
type@lifecycle ILM policies during Fleet setup #243333..fleet-policies index #242612.type@lifecycle ILM policies for new package installations #241992.xpack.fleet.experimentalFeatures config setting #238840.Discover:
{{esql}} editor:
WITH keyword for RERANK and COMPLETION commands #243047.parens node #242369.Elastic Observability solution: For the Elastic Observability 9.3.0 release information, refer to Elastic Observability Solution Release Notes.
Elastic Security solution: For the Elastic Security 9.3.0 release information, refer to Elastic Security Solution Release Notes.
Kibana platform:
defaultRoute advanced setting now controls the target of the Elastic logo link for spaces using a solution view #241571.object_src 'none' directive in Kibana's Content Security Policy and introduces a new csp.object_src configuration option to control its behaviorpopulate_file_data advanced option which enables entropy and header_bytes fields in file events #246197.Kibana security:
AI Assistants Settings privilege #239144.Machine Learning:
timeout parameter to the Inference chat model #248326.Search:
Workflows:
Alerting:
cases.total_event not showing the number of events attached to a case #247996.alert.consecutiveMatches to action context #244997.autoFocus to preserve proper focus when modal closed #239366.nodemailer to to 7.0.9 #238816.otherFields JSON editor to case creation flow #238435.ignoreFilterIfFieldNotInIndex advanced setting enabled #238945.Connectivity:
Dashboards and Visualizations:
Number.MAX_VALUE instead of Infinity for the default maximum height of a panel #243572.console.warn #242788.LensConfigBuilder that treated all dataview references the same, causing the UI to throw an error attempting to find an ad-hoc dataview that does not exist as a SavedObject #239431.Data ingestion and Fleet:
/api/fleet/agents when transient issues with {{es}} are encountered #243105.template_path asset selection for some integration packages #240750.ignore_above mapping for flattened fields #238890.Discover:
defaultColumns advanced setting #246664.{{esql}} editor:
Elastic Observability solution:
For the Elastic Observability 9.3.0 release information, refer to Elastic Observability Solution Release Notes.
Elastic Security solution:
For the Elastic Security 9.3.0 release information, refer to Elastic Security Solution Release Notes.
Kibana platform:
meta.error in JSON layouts. If it is an Error instance, only message, name, and stack are included. Other fields are no longer returned in the logs #244364.@custom suffix in its name would lead to updating mappings of all unrelated data streams and cause a popup to appear asking to roll over conflicting ones #237952.createAuditEvents always returning failure as outcome #247152.AI Assistants Visibility GenAI setting when opening AI Assistant from the header #239555.Kibana security:
Machine Learning:
TS command in Data Visualizer #247641.Search:
elser-2-elastic (ELSER in EIS) the default inference endpoint for adding semantic text fields. Refactors the SelectInferenceId component for clarity and stability, resolving a console warning and improving popover and flyout state handling #242436.semantic_text fields during deployment without forcing #237812.parsing_exception when passed through the query parameter in the Node.js Elasticsearch client. Retriever queries must be passed through the body parameter to ensure they are serialized correctly #237654.% ::::{NOTE} % ::::
Alerting:
accessTokenUrl validation #258290.Dashboards and Visualizations:
savedObjectId was present without saved object references #257779.Data ingestion and Fleet:
Data management:
Elastic Observability solution: For the Elastic Observability 9.2.8 release information, refer to Elastic Observability Solution Release Notes.
Elastic Security solution: For the Elastic Security 9.2.8 release information, refer to Elastic Security Solution Release Notes.
Elasticsearch solution:
Machine Learning:
:::{important} The 9.2.7 release contains fixes for potential security vulnerabilities. Check our security advisory for more details. :::
Elastic Security solution: For the Elastic Security 9.2.7 release information, refer to Elastic Security Solution Release Notes.
Alerting:
204 responses #251090.Dashboards and Visualizations:
Data ingestion and Fleet:
Elastic Observability solution: For the Elastic Observability 9.2.7 release information, refer to Elastic Observability Solution Release Notes.
Elastic Security solution: For the Elastic Security 9.2.7 release information, refer to Elastic Security Solution Release Notes.
Kibana platform:
Kibana security:
waitFor for the privilege button #255094.Management:
Search:
:::{important} The 9.2.6 release contains fixes for potential security vulnerabilities. Check our security advisory for more details. :::
Elastic Security solution: For the Elastic Security 9.2.6 release information, refer to Elastic Security Solution Release Notes.
Alerting and cases:
Dashboards and Visualizations:
runtime_mappings being ignored or overridden in Vega specs when defined in data[].url.body #253560.Discover:
Elastic Observability solution: For the Elastic Observability 9.2.6 release information, refer to Elastic Observability Solution Release Notes.
Elastic Security solution: For the Elastic Security 9.2.6 release information, refer to Elastic Security Solution Release Notes.
Kibana platform:
Search:
Alerting:
Dashboards and Visualizations:
Discover:
Elastic Observability solution: For the Elastic Observability 9.2.5 release information, refer to Elastic Observability Solution Release Notes.
Elastic Security solution: For the Elastic Security 9.2.5 release information, refer to Elastic Security Solution Release Notes.
Kibana platform:
dateFormat:tz) #249016.Machine Learning:
Elastic Security solution: For the Elastic Security 9.2.4 release information, refer to Elastic Security Solution Release Notes.
Alerting and cases:
Dashboards and Visualizations:
Discover:
Elastic Observability solution: For the Elastic Observability 9.2.4 release information, refer to Elastic Observability Solution Release Notes.
Elastic Security solution: For the Elastic Security 9.2.4 release information, refer to Elastic Security Solution Release Notes.
Kibana platform:
createAuditEvents always returning failure as the outcome #247152.Kibana security:
Machine Learning:
Platform:
Search:
% ::::{NOTE} % ::::
Data ingestion and Fleet:
FleetPolicyRevisionsCleanupTask which removes excess policy revisions from the .fleet-policies index #242612.Kibana platform:
Alerting:
consecutiveMatches to action context #244997.Discover:
Elastic Observability solution: For the Elastic Observability 9.2.3 release information, refer to Elastic Observability Solution Release Notes.
Elastic Security solution: For the Elastic Security 9.2.3 release information, refer to Elastic Security Solution Release Notes.
Kibana platform:
kibana_started.elasticsearch.waitTime value in logs #245706.meta.error in JSON layouts. If it is an Error instance, only message, name, and stack are included. Other fields are no longer returned in the logs #244364.% ::::{NOTE} % ::::
Elastic Observability solution: For the Elastic Observability 9.2.2 release information, refer to Elastic Observability Solution Release Notes.
Elastic Security solution: For the Elastic Security 9.2.2 release information, refer to Elastic Security Solution Release Notes.
Alerting and cases:
Dashboards and Visualizations:
max_value instead of infinity for the default maximum height of a panel #243572.Data ingestion and Fleet:
/api/fleet/agents when transient issues with {{es}} are encountered #243105.Discover:
Elastic Observability solution: For the Elastic Observability 9.2.2 release information, refer to Elastic Observability Solution Release Notes.
Elastic Security solution: For the Elastic Security 9.2.2 release information, refer to Elastic Security Solution Release Notes.
Kibana platform:
Machine Learning:
Search:
% ::::{NOTE} % ::::
{{product.kibana}} platform:
defaultRoute advanced setting now controls the target of the Elastic logo link for spaces using a solution view #241571.object_src 'none' directive in {{product.kibana}}'s Content Security Policy and introduces a new csp.object_src configuration option to control its behavior #241029.Machine Learning:
Alerting:
Dashboards and visualizations:
Data ingestion and Fleet:
{{esql}} editor:
TS commands after a comma #241402.{{product.observability}} solution: For the {{product.observability}} 9.2.1 release information, refer to {{product.observability}} Solution Release Notes.
{{product.security}} solution: For the {{product.security}} 9.2.1 release information, refer to {{product.security}} Solution Release Notes.
{{product.kibana}} platform:
Search:
Navigation and general interface:
i18n.locale: de-DE. If you find any issues, please raise them on Github #236903.Alerting:
xpack.actions.email.recipient_allowlist alert action setting, which lets you specify a list of allowed email recipient patterns (to, cc, or bcc) that can be used with email connectors #220058.Dashboards and Visualizations:
Data ingestion and Fleet:
logs and logs.* data streams #233374.discovery fields #232668.MIGRATE action type for migrating agents to a different cluster #239556.MIGRATE action to the SIGNED_ACTIONS set #228566.alerting_rule_template {{kib}} assets from packages; also enables a background task for reporting agent status changes in {{fleet}} #235842.url variable type in {{fleet}} packages which provides better input validation of URLs in configurations #231062.duration variable type in {{fleet}} packages which provides better input validation of duration strings in configurations #231027.keep option in the Remove processor in ingest pipelines #225638.Discover:
10 added to the query base query when switching to {{esql}} mode in Discover #234349.{{esql}} editor:
LOOKUP JOIN command. The same enhancement was applied to column suggestions when using the ENRICH command #233221.Elastic Observability solution: For the Elastic Observability 9.2.0 release information, refer to Elastic Observability Solution Release Notes.
Elastic Security solution: For the Elastic Security 9.2.0 release information, refer to Elastic Security Solution Release Notes.
Machine Learning:
Kibana platform and management:
Elasticsearch solution:
Alerting:
Dashboards and Visualizations:
(missing value) and (empty) respectively. This is now aligned across charts and tables, including Discover and Lens charts #233369.Data ingestion and Fleet:
Discover:
{{esql}} editor:
Elastic Observability solution: For the Elastic Observability 9.2.0 release information, refer to Elastic Observability Solution Release Notes.
Elastic Security solution: For the Elastic Security 9.2.0 release information, refer to Elastic Security Solution Release Notes.
Machine Learning:
Search:
% ::::{NOTE} % ::::
Elastic Observability solution: For the Elastic Observability 9.1.10 release information, refer to Elastic Observability Solution Release Notes.
Elastic Security solution: For the Elastic Security 9.1.10 release information, refer to Elastic Security Solution Release Notes.
Alerting and cases:
Dashboards and Visualizations:
Elastic Observability solution: For the Elastic Observability 9.1.10 release information, refer to Elastic Observability Solution Release Notes.
Elastic Security solution: For the Elastic Security 9.1.10 release information, refer to Elastic Security Solution Release Notes.
Kibana platform:
createAuditEvents always returning failure as the outcome #247152.Kibana security:
Machine Learning:
Platform:
Search:
% ::::{NOTE} % ::::
Data ingestion and Fleet:
FleetPolicyRevisionsCleanupTask which removes excess policy revisions from the .fleet-policies index #242612.Kibana platform:
Alerting:
consecutiveMatches to action context #244997.Elastic Observability solution: For the Elastic Observability 9.1.9 release information, refer to Elastic Observability Solution Release Notes.
Elastic Security solution: For the Elastic Security 9.1.9 release information, refer to Elastic Security Solution Release Notes.
Kibana platform:
kibana_started.elasticsearch.waitTime value in logs #245706.meta.error in JSON layouts: if the error is an Error instance, only message, name, and stack are included. Other fields are no longer returned in the logs #244364.Machine Learning:
% ::::{NOTE} % ::::
Elastic Observability solution: For the Elastic Observability 9.1.8 release information, refer to Elastic Observability Solution Release Notes.
Elastic Security solution: For the Elastic Security 9.1.8 release information, refer to Elastic Security Solution Release Notes.
Alerting and cases:
Dashboards and Visualizations:
Data ingestion and Fleet:
/api/fleet/agents when transient issues with {{es}} are encountered #243105.ignore_above mapping for flattened fields #238890.Elastic Observability solution: For the Elastic Observability 9.1.8 release information, refer to Elastic Observability Solution Release Notes.
Elastic Security solution: For the Elastic Security 9.1.8 release information, refer to Elastic Security Solution Release Notes.
Kibana platform:
Machine Learning:
% ::::{NOTE} % ::::
Machine Learning:
Alerting:
Dashboards and visualizations:
timeRestore and setting a time range #239992.Data ingestion and Fleet:
{{product.kibana}} platform:
max_tokens parameter is correctly passed as expected when connecting to Anthropic #241212 & #241188.{{product.observability}} solution: For the {{product.observability}} 9.1.7 release information, refer to {{product.observability}} Solution Release Notes.
{{product.security}} solution: For the {{product.security}} 9.1.7 release information, refer to {{product.security}} Solution Release Notes.
Machine Learning:
% ::::{NOTE} % ::::
Data ingestion and Fleet:
?showAgentless query param with a local storage setting called fleet:showAgentlessResources, which can be toggled from the {{fleet}} settings page. When enabled, agentless agents and policies are visible in the {{fleet}} UI #237528.Elastic Security solution: For the Elastic Security 9.1.6 release information, refer to Elastic Security Solution Release Notes.
Kibana security:
Dashboards and Visualizations:
timeRestore setting and selected a time and date using the date picker #239992.Data ingestion and Fleet:
Discover:
courier:ignoreFilterIfFieldNotInIndex advanced setting is enabled #238945.Elastic Observability solution: For the Elastic Observability 9.1.6 release information, refer to Elastic Observability Solution Release Notes.
Elastic Security solution: For the Elastic Security 9.1.6 release information, refer to Elastic Security Solution Release Notes.
Search:
:::{important} The 9.1.5 release contains fixes for potential security vulnerabilities. Check our security advisory for more details. :::
Data ingestion and Fleet:
Elastic Security solution: For the Elastic Security 9.1.5 release information, refer to Elastic Security Solution Release Notes.
Alerting:
Dashboards and Visualizations:
Data ingestion and Fleet:
Discover:
timestamp when navigating from classic to ES|QL mode #235338.Kibana security:
xpack.spaces.defaultSolution to be configured through environment variables for Docker deployments #236570.Machine Learning:
msearch usage #235611.Management:
managed field to the data views response schema to prevent the public API call from failing #236237.timeFieldName field to the data views response schema to prevent the public API call from failing #235975.superuser role was required, but now the cluster: manage and all privileges are sufficient #237055.Stack Management:
Search solution:
% ::::{NOTE} % ::::
Elastic Observability solution: For the Elastic Observability 9.1.4 release information, refer to Elastic Observability Solution Release Notes.
Stack management
Dashboards and Visualizations:
Elastic Security solution: For the Elastic Security 9.1.4 release information, refer to Elastic Security Solution Release Notes.
Machine Learning:
:::{important} The 9.1.3 release contains fixes for potential security vulnerabilities. Check our security advisory for more details. :::
Alerting:
Dashboards and Visualizations:
Data ingestion and Fleet:
deployment_modes evaluation for policy templates when creating a package policy. When deploying in agentless mode, this prevents the acceptance of inputs from policy templates that are not opted into the agentless mode at the template level #231679.Discover:
Elastic Observability solution: For the Elastic Observability 9.1.3 release information, refer to Elastic Observability Solution Release Notes.
Elastic Security solution: For the Elastic Security 9.1.3 release information, refer to Elastic Security Solution Release Notes.
Kibana platform:
share.url_expiration.duration changed #231883.reporting_user role to leverage a new reporting_user reserved privilege #231533.Alerting:
Data ingestion and Fleet:
text and password inputs in the package policy editor #229932.Elastic Observability solution: For the Elastic Observability 9.1.2 release information, refer to Elastic Observability Solution Release Notes.
Elastic Security solution: For the Elastic Security 9.1.2 release information, refer to Elastic Security Solution Release Notes.
Kibana platform:
% ::::{NOTE} % ::::
Dashboards and Visualizations:
Management:
Dashboards and Visualizations:
Data ingestion and Fleet:
Discover:
Elastic Observability solution: For the Elastic Observability 9.1.1 release information, refer to Elastic Observability Solution Release Notes.
Elastic Security solution: For the Elastic Security 9.1.1 release information, refer to Elastic Security Solution Release Notes.
Machine Learning:
Kibana platform:
If you're upgrading to version 9.1.0, you first need to upgrade to version 8.19 or 9.0.
Alerting:
xpack.actions.email.services.enabled {{kib}} setting, which allows you to enable or disable email services for email connectors #223363.xpack.actions.webhook.ssl.pfx.enabled {{kib}} setting, which allows you to disable Webhook connector PFX file support for SSL client authentication #222507.xpack.actions.email.services.ses.host {{kib}} setting, which lets you specify the SMTP endpoint for an Amazon Simple Email Service (SES) service provider that can be used by email connectors. Also adds the xpack.actions.email.services.ses.hostport {{kib}} setting, which allows you to specify the port number for an Amazon SES service provider that can be used by email connectors #221389.rrule notation support for task scheduling #217728.context.link variable to use the new Discover URL formatting in all {{es}} query rule types #216376.Dashboards and Visualizations:
?) when editing an {{esql}} visualization's query #216839.?_tstart and ?_tend named parameters when the {{esql}} visualization's query includes controls #225054."target": "_blank" option for the usermeta.embedOptions.loader property of the Vega chart configuration #216200.Data ingestion and Fleet:
403 response if attempted #220601.searchAfter and point-in-time (pit) parameters in the get agents list API #213486.Discover:
search:timeout advanced setting #219027._score column in Discover #211013.command/ctrl + click to open new Discover sessions in a separate tab. This is useful, for example, when conducting multiple searches simultaneously #210982.{{esql}} editor:
LOOKUP_JOIN command is now GA #225117.COMPLETION command is now available in technical preview #224811.FORK command is now available in technical preview #224680.date_nanos fields in BUCKET functions #213319.STATS ... WHERE queries #220691.STATS...WHERE #216379.CHANGE_POINT command #218100.CHANGE_POINT command #216043.KQL and QSTR functions #211457.Elastic Observability solution: For the Elastic Observability 9.1.0 release information, refer to Elastic Observability Solution Release Notes.
Elastic Security solution: For the Elastic Security 9.1.0 release information, refer to Elastic Security Solution Release Notes.
Kibana platform:
defaultSolution setting to spaces configuration so that you can start Kibana with its default space set to a specific solution view #218360.[%date][%level][%logger] %message %error. This includes the error name and stack trace if these were included in the log entry. To opt out of this behavior, you can omit the %error placeholder from your log pattern configuration in kibana.yml #219940. For example:logging:
appenders:
console:
type: console
layout:
type: pattern
pattern: "[%date][%level][%logger] %message"
Machine Learning:
CATEGORIZE function in {{esql}} #222871.No Results state for Change Point Detection #219072.Management:
Search solution:
Sharing:
Alerting:
Dashboards and Visualizations:
None option) in Lens #228183.Pie) prevented the user from selecting a legacy palette #228051.kebab-case warnings #226114.defaultTitle from being overwritten with a custom title after reload #225664.defaultTitle #225237.Data ingestion and Fleet:
Discover:
_ #213255.{{esql}} editor:
BUCKET function signatures #222553.COALESCE function #222425.?value when using the WHERE command #222312.* in queries #219832.WHERE command in case of a multiline query #213240.Elastic Observability solution: For the Elastic Observability 9.1.0 release information, refer to Elastic Observability Solution Release Notes.
Elastic Security solution: For the Elastic Security 9.1.0 release information, refer to Elastic Security Solution Release Notes.
Kibana platform:
migrateInputDocument #222313.Machine Learning:
Management:
Search:
z-index of the app menu header to not conflict with the Persistent Console #224708.:::{important} The 9.0.8 release contains fixes for potential security vulnerabilities. Check our security advisory for more details. :::
Dashboards and Visualizations:
Data ingestion and Fleet:
Discover:
timestamp when navigating from classic to ES|QL mode #235338.Machine Learning:
msearch usage #235611.Management:
Stack Management:
Elastic Security solution: For the Elastic Security 9.0.7 release information, refer to Elastic Security Solution Release Notes.
Kibana security:
Search solution:
:::{important} The 9.0.6 release contains fixes for potential security vulnerabilities. Check our security advisory for more details. :::
Dashboards and Visualizations:
Kibana platform:
reporting_user role to leverage a new reporting_user reserved privilege #231533.Search:
Dashboards and Visualizations:
Dashboards and Visualizations:
+ not being properly encoded when it's part of a date math expression #230469.Data ingestion and Fleet:
azure-blob-storage and gcs inputs to the AGENTLESS_DISABLED_INPUTS list #229117.Discover:
-1 in Advanced Settings #228697.Elastic Observability solution: For the Elastic Observability 9.0.5 release information, refer to Elastic Observability Solution Release Notes.
Elastic Security solution: For the Elastic Security 9.0.5 release information, refer to Elastic Security Solution Release Notes.
Kibana platform:
Machine Learning:
removeIfExists from the synchronization task scheduler #228783.Data ingestion and Fleet:
Machine Learning:
Dashboards and Visualizations:
Data ingestion and Fleet:
Discover:
Elastic Observability solution: For the Elastic Observability 9.0.4 release information, refer to Elastic Observability Solution Release Notes.
Elastic Security solution: For the Elastic Security 9.0.4 release information, refer to Elastic Security Solution Release Notes.
Kibana platform:
Search:
z-index of the header menu to avoid conflicting with Console #224708.:::{important} The 9.0.3 release contains fixes for potential security vulnerabilities. Check our security advisory for more details. :::
Elastic Observability solution: For the Elastic Observability 9.0.3 release information, refer to Elastic Observability Solution Release Notes.
Elastic Security solution: For the Elastic Security 9.0.3 release information, refer to Elastic Security Solution Release Notes.
Alerting:
xpack.alerting.cancelAlertsOnRuleTimeout was set to false in the kibana.yml file #222263.Dashboards and Visualizations:
Discover:
Elastic Observability solution: For the Elastic Observability 9.0.3 release information, refer to Elastic Observability Solution Release Notes.
Elastic Security solution: For the Elastic Security 9.0.3 release information, refer to Elastic Security Solution Release Notes.
Machine Learning:
Elastic Observability solution: For the Elastic Observability 9.0.2 release information, refer to Elastic Observability Solution Release Notes.
Alerting:
Dashboards:
Elastic Observability solution: For the Elastic Observability 9.0.2 release information, refer to Elastic Observability Solution Release Notes.
Elastic Security solution: For the Elastic Security 9.0.2 release information, refer to Elastic Security Solution Release Notes.
::::{important} The 9.0.1 release contains fixes for potential security vulnerabilities. See our security advisory for more details. ::::
Data ingestion and Fleet:
Elastic Security solution: For the Elastic Security 9.0.1 release information, refer to Elastic Security Solution Release Notes.
Dashboards & Visualizations:
Discover:
allow_hidden) option of the data view could be ignored #217628.Elastic Observability solution: For the Elastic Observability 9.0.1 release information, refer to Elastic Observability Solution Release Notes.
Elastic Security solution: For the Elastic Security 9.0.1 release information, refer to Elastic Security Solution Release Notes.
Kibana platform:
Machine Learning:
If you're upgrading to version 9.0.0, you first need to upgrade to version 8.18. We recommend checking the 8.18 release notes.
Theme:
{{kib}} 9.0 introduces a more modern and refined look and feel. This new theme brings a vibrant color palette, improved dark mode support (including honoring your system preferences), and more that will bring your data in Kibana to life.
Data ingestion and Fleet:
Uninstalled and Orphaned agents in Fleet, by differentiating them from Offline agents #205815.Elastic Observability solution:
screenshot_ref is truly not present #215241.Elastic Security solution: For the Elastic Security 9.0.0 release information, refer to Elastic Security Solution Release Notes.
Kibana security:
js-yaml to 4.1.0 #190678.Machine Learning:
ignore_throttled #199107.Platform:
Dashboards & Visualizations:
Pie, Treemap and Mosaic charts #209632.null flag is disabled #207308.Data ingestion and Fleet:
Elastic Observability solution:
Elastic Security solution: For the Elastic Security 9.0.0 release information, refer to Elastic Security Solution Release Notes.
Platform: