Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

What's new in 8.16 #5953

Closed
20 of 24 tasks
natasha-moore-elastic opened this issue Oct 17, 2024 · 0 comments · Fixed by #6077
Closed
20 of 24 tasks

What's new in 8.16 #5953

natasha-moore-elastic opened this issue Oct 17, 2024 · 0 comments · Fixed by #6077
Assignees
Labels
Docset: ESS Issues that apply to docs in the Stack release Effort: Medium Issues that take moderate but not substantial time to complete highlights Priority: High Issues that are time-sensitive and/or are of high customer importance v8.16.0

Comments

@natasha-moore-elastic
Copy link
Contributor

natasha-moore-elastic commented Oct 17, 2024

Please add your features and enhancements for 8.16. Don't forget to include the related PR link!

Detections & Response

Rules Management

  • Enable prebuilt detection rules on installation (New option to install and enable rules in one step #6051)

    Previously, installing and enabling prebuilt rules took two steps. Users can now do both in one step with the Install and enable option. This works for both single rules and multiple rules that the user selects.

Detection Engine

Threat Hunting

Explore

  • Add features here

Investigations

  • More ways to add notes ([Serverless][8.16] Notes docs #6006)

    In 8.16, you can now attach notes to alerts, events, and Timelines and manage them from the Notes page. This provides an easy way to incorproate notes into your investigative workflows to coordinate responses, conduct threat hunting, and share investigative findings.

  • New advanced setting that allows you to view analyzed events from the alert details flyout ([Request][Serverless][8.16] Visualizations in alert flyout - technical preview + advanced setting #5963)

    Now, after enabling the new securitySolution:enableVisualizationsInFlyout advanced setting, you can view analyzed alerts and events in the Visualize tab of the alert details flyout. This allows you to maintain the context of the Alerts table during your investigation and provides an easy way to preview related alerts and events.

  • Resizeable alert and event details flyouts (PR pending)

    You can now resize the alert and event details flyouts and choose how it's displayed (over the Alerts table or next to it).

Entity Analytics

  • Entity store ([8.16] Adds entity store docs #6053)

    The entity store feature allows you to query, reconcile, and maintain entity metadata from various sources, such as ingested logs, integrated identity providers, external asset repositories, and more. By extracting and storing entities from all indices in the Elastic Security default data view, the Entity Store lets you query entity metadata without real-time data searches.

    After you enable the entity store, the Entity Analytics dashboard displays the Entities section, which offers a comprehensive view of your entities. Here, you can view all hosts and users in your environment, and filter them by their source, entity risk level, and asset criticality level.

  • Asset criticality available by default (Asset criticality advanced setting removed #5991)

    The asset criticality advanced setting has been removed, meaning that asset criticality is now available by default.

  • Entity risk scoring available in multiple spaces (Entity risk scoring available in multiple Kibana spaces #5931)

    You can now enable and run entity risk scoring in multiple Kibana spaces.

  • Risk scoring recalculation after file upload (Risk scoring recalculation after file upload #5924)

    When you bulk assign asset criticality using the file upload feature, the newly assigned criticality levels are factored in during the next hourly risk scoring calculation. You can now manually trigger an immediate recalculation of entity risk scores by clicking Recalculate entity risk scores now.

Generative AI

EDR Workflows/Asset Management

Cloud Security

Endpoint

  • Add features here

Protections Experience

  • Add features here

ResponseOps

  • Add features here
@natasha-moore-elastic natasha-moore-elastic added Docset: ESS Issues that apply to docs in the Stack release Effort: Medium Issues that take moderate but not substantial time to complete highlights Priority: High Issues that are time-sensitive and/or are of high customer importance v8.16.0 labels Oct 17, 2024
@natasha-moore-elastic natasha-moore-elastic self-assigned this Oct 17, 2024
@jmikell821 jmikell821 pinned this issue Oct 17, 2024
@natasha-moore-elastic natasha-moore-elastic unpinned this issue Nov 25, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Docset: ESS Issues that apply to docs in the Stack release Effort: Medium Issues that take moderate but not substantial time to complete highlights Priority: High Issues that are time-sensitive and/or are of high customer importance v8.16.0
Projects
None yet
Development

Successfully merging a pull request may close this issue.

1 participant