Releases: elastic/ecs
Releases · elastic/ecs
ECS 8.6.1
ECS 8.6.0
ECS 8.6.0-rc1
ECS 8.5.2
ECS 8.5.1
ECS 8.5.0
What's new in ECS 8.5.0
Schema Changes
Added
- Adding
risk.*
fields as experimental. #1994, #2010 - Adding
process.io.*
as beta fields. #1956, #2031 - Adding
process.tty.rows
andprocess.tty.columns
as beta fields. #2031 - Changed
process.env_vars
field type to be an array of keywords. #2038 process.attested_user
andprocess.attested_groups
as beta fields. #2050- Added
risk.*
fieldset to beta. #2051, #2058 - Moved Linux event model fields to GA. #2082
Improvements
- Advances
threat.enrichments.indicator
to GA. #1928 - Added
ios
andandroid
as valid values foros.type
#1999
Tooling and Artifact Changes
Bugfixes
ECS 8.5.0-rc1
ECS Release Candidate
Schema Changes
Added
- Adding
risk.*
fields as experimental. #1994, #2010 - Adding
process.io.*
as beta fields. #1956, #2031 - Adding
process.tty.rows
andprocess.tty.columns
as beta fields. #2031 - Changed
process.env_vars
field type to be an array of keywords. #2038 process.attested_user
andprocess.attested_groups
as beta fields. #2050- Added
risk.*
fieldset to beta. #2051
Improvements
- Advances
threat.enrichments.indicator
to GA. #1928 - Added
ios
andandroid
as valid values foros.type
#1999
Tooling and Artifact Changes
Bugfixes
ECS 8.4.0
What's new in ECS 8.4
New field attribute expected_values
ECS schema field definitions will now support an attribute to provide a consistent location to capture a list of expected values.
Schema Changes
Added
Tooling and Artifact Changes
Added
- Introduce
expected_values
attribute. #1952
Improvements
- Additional type annotations. #1950