Skip to content

Commit 4bea7fc

Browse files
Merge branch 'main' into release-docs-9.4.4
2 parents e4e3155 + fd835b3 commit 4bea7fc

9 files changed

Lines changed: 34 additions & 25 deletions

File tree

_search.md

Lines changed: 0 additions & 7 deletions
This file was deleted.

deploy-manage/deploy/cloud-enterprise/ece-install-offline-images.md

Lines changed: 16 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -47,11 +47,11 @@ Enterprise Search is not available in versions 9.0+.
4747
| docker.elastic.co/cloud-release/kibana-cloud:9.4.4 | ECE 4.0.0 |
4848
| docker.elastic.co/cloud-release/elastic-agent-cloud:9.4.4 | ECE 4.0.0 |
4949
| | |
50-
| [{{es}}, {{kib}}, APM, and Enterprise Search stack pack: 8.19.18](https://download.elastic.co/cloud-enterprise/versions/8.19.18.zip) | ECE 3.0.0<br>(+ Docker 20.10.10+ required for 8.16+) |
51-
| docker.elastic.co/cloud-release/elasticsearch-cloud-ess:8.19.18 | ECE 3.0.0<br>(+ Docker 20.10.10+ required for 8.16+) |
52-
| docker.elastic.co/cloud-release/kibana-cloud:8.19.18 | ECE 3.0.0 |
53-
| docker.elastic.co/cloud-release/elastic-agent-cloud:8.19.18 | ECE 3.0.0 |
54-
| docker.elastic.co/cloud-release/enterprise-search-cloud:8.19.18 | ECE 3.0.0 |
50+
| [{{es}}, {{kib}}, APM, and Enterprise Search stack pack: 8.19.19](https://download.elastic.co/cloud-enterprise/versions/8.19.19.zip) | ECE 3.0.0<br>(+ Docker 20.10.10+ required for 8.16+) |
51+
| docker.elastic.co/cloud-release/elasticsearch-cloud-ess:8.19.19 | ECE 3.0.0<br>(+ Docker 20.10.10+ required for 8.16+) |
52+
| docker.elastic.co/cloud-release/kibana-cloud:8.19.19 | ECE 3.0.0 |
53+
| docker.elastic.co/cloud-release/elastic-agent-cloud:8.19.19 | ECE 3.0.0 |
54+
| docker.elastic.co/cloud-release/enterprise-search-cloud:8.19.19 | ECE 3.0.0 |
5555
| | |
5656
| [{{es}}, {{kib}}, APM, and Enterprise Search stack pack: 7.17.29](https://download.elastic.co/cloud-enterprise/versions/7.17.29.zip) | ECE 2.2.2 |
5757
| docker.elastic.co/cloud-assets/elasticsearch:7.17.29-0 | ECE 2.2.2 |
@@ -96,6 +96,11 @@ Enterprise Search is not available in versions 9.0+.
9696
| docker.elastic.co/cloud-release/kibana-cloud:9.4.0 | ECE 4.0.0 |
9797
| docker.elastic.co/cloud-release/elastic-agent-cloud:9.4.0 | ECE 4.0.0 |
9898
| | |
99+
| [{{es}}, {{kib}}, and APM stack pack: 9.3.8](https://download.elastic.co/cloud-enterprise/versions/9.3.8.zip) | ECE 4.0.0 |
100+
| docker.elastic.co/cloud-release/elasticsearch-cloud-ess:9.3.8 | ECE 4.0.0 |
101+
| docker.elastic.co/cloud-release/kibana-cloud:9.3.8 | ECE 4.0.0 |
102+
| docker.elastic.co/cloud-release/elastic-agent-cloud:9.3.8 | ECE 4.0.0 |
103+
| | |
99104
| [{{es}}, {{kib}}, and APM stack pack: 9.3.7](https://download.elastic.co/cloud-enterprise/versions/9.3.7.zip) | ECE 4.0.0 |
100105
| docker.elastic.co/cloud-release/elasticsearch-cloud-ess:9.3.7 | ECE 4.0.0 |
101106
| docker.elastic.co/cloud-release/kibana-cloud:9.3.7 | ECE 4.0.0 |
@@ -276,6 +281,12 @@ Enterprise Search is not available in versions 9.0+.
276281
| docker.elastic.co/cloud-release/kibana-cloud:9.0.0 | ECE 4.0.0 |
277282
| docker.elastic.co/cloud-release/elastic-agent-cloud:9.0.0 | ECE 4.0.0 |
278283
| | |
284+
| [{{es}}, {{kib}}, APM, and Enterprise Search stack pack: 8.19.19](https://download.elastic.co/cloud-enterprise/versions/8.19.19.zip) | ECE 3.0.0<br>(+ Docker 20.10.10+ required for 8.16+) |
285+
| docker.elastic.co/cloud-release/elasticsearch-cloud-ess:8.19.19 | ECE 3.0.0<br>(+ Docker 20.10.10+ required for 8.16+) |
286+
| docker.elastic.co/cloud-release/kibana-cloud:8.19.19 | ECE 3.0.0 |
287+
| docker.elastic.co/cloud-release/elastic-agent-cloud:8.19.19 | ECE 3.0.0 |
288+
| docker.elastic.co/cloud-release/enterprise-search-cloud:8.19.19 | ECE 3.0.0 |
289+
| | |
279290
| [{{es}}, {{kib}}, APM, and Enterprise Search stack pack: 8.19.18](https://download.elastic.co/cloud-enterprise/versions/8.19.18.zip) | ECE 3.0.0<br>(+ Docker 20.10.10+ required for 8.16+) |
280291
| docker.elastic.co/cloud-release/elasticsearch-cloud-ess:8.19.18 | ECE 3.0.0<br>(+ Docker 20.10.10+ required for 8.16+) |
281292
| docker.elastic.co/cloud-release/kibana-cloud:8.19.18 | ECE 3.0.0 |

deploy-manage/deploy/cloud-enterprise/manage-elastic-stack-versions.md

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -41,7 +41,7 @@ $$$ece-elastic-stack-stackpacks-recent$$$
4141
| Stack pack download link | Minimum required ECE version |
4242
| --- | --- |
4343
| [{{es}}, {{kib}}, and APM stack pack: 9.4.4](https://download.elastic.co/cloud-enterprise/versions/9.4.4.zip) | ECE 4.0.0 |
44-
| [{{es}}, {{kib}}, APM, and Enterprise Search stack pack: 8.19.18](https://download.elastic.co/cloud-enterprise/versions/8.19.18.zip) | ECE 3.0.0<br>(+ Docker 20.10.10+ required for 8.16+) |
44+
| [{{es}}, {{kib}}, APM, and Enterprise Search stack pack: 8.19.19](https://download.elastic.co/cloud-enterprise/versions/8.19.19.zip) | ECE 3.0.0<br>(+ Docker 20.10.10+ required for 8.16+) |
4545
| [{{es}}, {{kib}}, APM, and Enterprise Search stack pack: 7.17.29](https://download.elastic.co/cloud-enterprise/versions/7.17.29.zip) | ECE 2.2.2 |
4646

4747

@@ -57,6 +57,7 @@ Following is the full list of available packs containing {{stack}} versions. Not
5757
| [{{es}}, {{kib}}, and APM stack pack: 9.4.2](https://download.elastic.co/cloud-enterprise/versions/9.4.2.zip) | ECE 4.0.0 | Kibana requires 2GB instance
5858
| [{{es}}, {{kib}}, and APM stack pack: 9.4.1](https://download.elastic.co/cloud-enterprise/versions/9.4.1.zip) | ECE 4.0.0 | Kibana requires 2GB instance
5959
| [{{es}}, {{kib}}, and APM stack pack: 9.4.0](https://download.elastic.co/cloud-enterprise/versions/9.4.0.zip) | ECE 4.0.0 | Kibana requires 2GB instance
60+
| [{{es}}, {{kib}}, and APM stack pack: 9.3.8](https://download.elastic.co/cloud-enterprise/versions/9.3.8.zip) | ECE 4.0.0 |
6061
| [{{es}}, {{kib}}, and APM stack pack: 9.3.7](https://download.elastic.co/cloud-enterprise/versions/9.3.7.zip) | ECE 4.0.0 |
6162
| [{{es}}, {{kib}}, and APM stack pack: 9.3.6](https://download.elastic.co/cloud-enterprise/versions/9.3.6.zip) | ECE 4.0.0 |
6263
| [{{es}}, {{kib}}, and APM stack pack: 9.3.5](https://download.elastic.co/cloud-enterprise/versions/9.3.5.zip) | ECE 4.0.0 |
@@ -93,6 +94,7 @@ Following is the full list of available packs containing {{stack}} versions. Not
9394
| [{{es}}, {{kib}}, and APM stack pack: 9.0.2](https://download.elastic.co/cloud-enterprise/versions/9.0.2.zip) | ECE 4.0.0 |
9495
| [{{es}}, {{kib}}, and APM stack pack: 9.0.1](https://download.elastic.co/cloud-enterprise/versions/9.0.1.zip) | ECE 4.0.0 |
9596
| [{{es}}, {{kib}}, and APM stack pack: 9.0.0](https://download.elastic.co/cloud-enterprise/versions/9.0.0.zip) | ECE 4.0.0 |
97+
| [{{es}}, {{kib}}, APM, and Enterprise Search stack pack: 8.19.19](https://download.elastic.co/cloud-enterprise/versions/8.19.19.zip) | ECE 3.0.0<br>(+ docker 20.10.10+ required for 8.16+) |
9698
| [{{es}}, {{kib}}, APM, and Enterprise Search stack pack: 8.19.18](https://download.elastic.co/cloud-enterprise/versions/8.19.18.zip) | ECE 3.0.0<br>(+ docker 20.10.10+ required for 8.16+) |
9799
| [{{es}}, {{kib}}, APM, and Enterprise Search stack pack: 8.19.17](https://download.elastic.co/cloud-enterprise/versions/8.19.17.zip) | ECE 3.0.0<br>(+ docker 20.10.10+ required for 8.16+) |
98100
| [{{es}}, {{kib}}, APM, and Enterprise Search stack pack: 8.19.16](https://download.elastic.co/cloud-enterprise/versions/8.19.16.zip) | ECE 3.0.0<br>(+ docker 20.10.10+ required for 8.16+) |

deploy-manage/monitor/autoops/ec-autoops-faq.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -115,8 +115,8 @@ $$$maintenance$$$ **Do I have to do any maintenance when using AutoOps for ECE,
115115
* When using the ECK installation method, make sure your instance of {{agent}} meets the [version requirements](/deploy-manage/monitor/autoops/cc-connect-self-managed-to-autoops.md#prerequisites) for your license type.
116116

117117
$$$trial-ending$$$ **I connected my ECE, ECK, or self-managed cluster to AutoOps during a free trial of {{ecloud}}. What happens after my trial ends?**
118-
: After your free trial ends, your cluster remains connected and AutoOps continues to process your {{es}} metrics as long as:
119-
* You have an [active {{ecloud}} account](../../cloud-organization/billing/add-billing-details.md).
118+
: You don't need a paid {{ecloud}} subscription or an active {{ecloud}} trial to keep using AutoOps for ECE, ECK, or self-managed clusters. AutoOps is free across all [self-managed license types](https://www.elastic.co/subscriptions) through Cloud Connect. After your free trial ends, your cluster remains connected and AutoOps continues to process your {{es}} metrics as long as:
119+
* You have an [active {{ecloud}} account](../../cloud-organization/billing/add-billing-details.md). Creating an {{ecloud}} account is free and doesn't require a paid subscription.
120120
* {{agent}} is running and shipping metrics to {{ecloud}}.
121121

122122
$$$access-autoops$$$**Who has access to AutoOps in my cluster?**

docset.yml

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -111,7 +111,6 @@ toc:
111111
- file: archive.md
112112
- file: versions.md
113113
- hidden: 404.md
114-
- hidden: _search.md
115114

116115
subs:
117116
subscriptions: "https://www.elastic.co/subscriptions"

explore-analyze/discover/try-esql.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -106,7 +106,7 @@ When you write a query, the {{esql}} editor includes two interactive browsers th
106106
- **Fields browser**: lists fields for the data sources currently in your query and lets you insert one field at a time at the cursor position.
107107

108108
:::{note}
109-
:applies_to: {stack: preview 9.4.0, serverless: unavailable}
109+
:applies_to: {stack: preview 9.4.0, serverless: preview}
110110
[{{esql}} views](elasticsearch://reference/query-languages/esql/esql-views.md) aren't shown in the data source browser but they're visible through the autocomplete menu suggestions.
111111
:::
112112

reference/fleet/fleet-server-scalability.md

Lines changed: 7 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -66,6 +66,10 @@ stack: ga
6666

6767
The following advanced settings are available to fine tune your {{fleet-server}} deployment.
6868

69+
::::{note}
70+
You can't configure agent offline detection through these settings. An agent is marked offline after it stops checking in with {{fleet-server}} for 5 minutes. This threshold is fixed and can't be changed.
71+
::::
72+
6973
`cache`
7074
: `num_counters`
7175
: Size of the hash table. Best practice is to have this set to 10 times the max connections.
@@ -75,10 +79,10 @@ The following advanced settings are available to fine tune your {{fleet-server}}
7579

7680
`server.timeouts`
7781
: `checkin_timestamp`
78-
: How often {{fleet-server}} updates the "last activity" field for each agent. Defaults to `30s`. In a large-scale deployment, increasing this setting might improve performance. If this setting is higher than `2m`, most agents will be shown as "offline" in the Fleet UI. For a typical setup, it’s recommended that you set this value to less than `2m`.
82+
: How often {{fleet-server}} updates the **Last activity** field for each agent. Defaults to `30s`. In a large-scale deployment, increasing this setting might improve performance. To avoid agents appearing offline in {{fleet}}, keep this value well below 5 minutes.
7983

8084
`checkin_long_poll`
81-
: How long {{fleet-server}} allows a long poll request from an agent before timing out. Defaults to `5m`. In a large-scale deployment, increasing this setting might improve performance.
85+
: How long {{fleet-server}} allows a long poll request from an agent before timing out. Defaults to `5m`. In a large-scale deployment, increasing this setting might improve performance. This setting controls the connection lifecycle between {{fleet-server}} and agents. It doesn't affect how quickly an agent is marked offline in {{fleet}}.
8286

8387
`server.limits`
8488
: `policy_throttle`
@@ -101,7 +105,7 @@ The following advanced settings are available to fine tune your {{fleet-server}}
101105
: Burst of check-ins allowed before falling back to the rate defined by `interval`.
102106

103107
`checkin_limit.max_body_byte_size`
104-
: Maximum size in bytes of the checkin API request body. Defaults to `1048576` bytes (1 MiB). Deployments running many Synthetics monitors might need to increase this value to avoid check-in failures that cause agents to appear offline or unhealthy in the Fleet UI despite monitors executing successfully. For example:
108+
: Maximum size in bytes of the checkin API request body. Defaults to `1048576` bytes (1 MiB). Deployments running many Synthetics monitors might need to increase this value to avoid check-in failures that cause agents to appear offline or unhealthy in {{fleet}} despite monitors executing successfully. For example:
105109

106110
```yaml
107111
server:

reference/fleet/monitor-elastic-agent.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -55,7 +55,7 @@ The **Agents** tab in **{{fleet}}** displays a maximum of 10,000 agents, shown o
5555
| **Unhealthy** | {{agent}}s have errors or are running in a degraded state. An agent will be reported as `unhealthy` as a result of a configuration problem on the host system. For example, an {{agent}} may not have the correct permissions required to run an integration that has been added to the {{agent}} policy. In this case, you may need to investigate and address the situation. |
5656
| **Orphaned** | For {{agent}}s enrolled in {{elastic-defend}}, the `orphaned` status indicates an error in the communication between the {{agent}} service on the host system and the endpoint security service provided by {{elastic-defend}}. On agents reported as `orphaned`, the {{elastic-defend}} integration is still running and protecting the host. |
5757
| **Updating** | {{agent}}s are updating the agent policy, updating the binary, or enrolling or unenrolling from {{fleet}}. |
58-
| **Offline** | {{agent}}s have stayed in an unhealthy status for a period of time. Offline agent’s API keys remain valid. You can still see these {{agent}}s in the {{fleet}} UI and investigate them for further diagnosis if required. |
58+
| **Offline** | {{agent}}s have stopped checking in with {{fleet-server}} for at least 5 minutes. This offline detection threshold is fixed at 5 minutes and can't be configured. The offline agents' API keys remain valid. You can still see these {{agent}}s in the {{fleet}} UI and investigate them for further diagnosis if required. |
5959
| **Inactive** | {{agent}}s have been offline for longer than the time set in your [inactivity timeout](/reference/fleet/set-inactivity-timeout.md). These {{agent}}s are valid, but have been removed from the main {{fleet}} UI. |
6060
| **Unenrolled** | {{agent}}s have been manually unenrolled and their API keys have been removed from the system. You can [unenroll](/reference/fleet/unenroll-elastic-agent.md) an offline {{agent}} using {{agent}} actions if you determine it’s offline and no longer valid.<br>These agents need to re-enroll in {{fleet}} to be operational again. |
6161
| **Uninstalled** | {{agent}}s have been successfully uninstalled and removed from the host system. |

reference/machine-learning/ootb-ml-jobs-siem.md

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1341,9 +1341,9 @@ This job is replaced by `dns_tunneling_ea` in the [Network module](#security-net
13411341

13421342
**Supported OS:** Windows, Linux
13431343

1344-
**Job (JSON):** [code](https://github.com/elastic/kibana/blob/main/x-pack/platform/plugins/shared/ml/server/models/data_recognizer/modules/security_packetbeat/ml/packetbeat_dns_tunneling_ea.json)
1344+
**Job (JSON):** [code](https://github.com/elastic/kibana/blob/9.4/x-pack/platform/plugins/shared/ml/server/models/data_recognizer/modules/security_packetbeat/ml/packetbeat_dns_tunneling_ea.json)
13451345

1346-
**Datafeed:** [code](https://github.com/elastic/kibana/blob/main/x-pack/platform/plugins/shared/ml/server/models/data_recognizer/modules/security_packetbeat/ml/datafeed_packetbeat_dns_tunneling_ea.json)
1346+
**Datafeed:** [code](https://github.com/elastic/kibana/blob/9.4/x-pack/platform/plugins/shared/ml/server/models/data_recognizer/modules/security_packetbeat/ml/datafeed_packetbeat_dns_tunneling_ea.json)
13471347

13481348
:::
13491349

@@ -1383,9 +1383,9 @@ This job is replaced by `rare_dns_question_ea` in the [Network module](#security
13831383

13841384
**Supported OS:** Windows, Linux
13851385

1386-
**Job (JSON):** [code](https://github.com/elastic/kibana/blob/main/x-pack/platform/plugins/shared/ml/server/models/data_recognizer/modules/security_packetbeat/ml/packetbeat_rare_dns_question_ea.json)
1386+
**Job (JSON):** [code](https://github.com/elastic/kibana/blob/9.4/x-pack/platform/plugins/shared/ml/server/models/data_recognizer/modules/security_packetbeat/ml/packetbeat_rare_dns_question_ea.json)
13871387

1388-
**Datafeed:** [code](https://github.com/elastic/kibana/blob/main/x-pack/platform/plugins/shared/ml/server/models/data_recognizer/modules/security_packetbeat/ml/datafeed_packetbeat_rare_dns_question_ea.json)
1388+
**Datafeed:** [code](https://github.com/elastic/kibana/blob/9.4/x-pack/platform/plugins/shared/ml/server/models/data_recognizer/modules/security_packetbeat/ml/datafeed_packetbeat_rare_dns_question_ea.json)
13891389

13901390
:::
13911391

0 commit comments

Comments
 (0)