Home / Companies / Elastic / Blog / July 2019

July 2019 Summaries

34 posts from Elastic

Filter
Month: Year:
Post Summaries Back to Blog
The Beats 7.3.0 release introduces significant enhancements across several areas to expand its data source ecosystem and improve automation and monitoring capabilities. A key feature is the automation of Functionbeat deployment through CloudFormation templates, facilitating smoother integration with automation systems. The release also sees the introduction of a new Google Cloud module in Filebeat for monitoring VPC flow logs and a Google Pub/Sub input for event ingestion, both aimed at enhancing real-time analytics. Metricbeat now supports three additional databases, including Oracle, Amazon RDS, and CockroachDB, while also improving Kubernetes observability with new metricsets that cover various Kubernetes components. A novel approach to creating Metricbeat modules, known as light modules, has been introduced to simplify the process without requiring Go code. These updates, alongside enhancements in Elastic APM, Elastic Uptime, and Elastic Logs, mark a significant step forward in the capabilities of the Elastic Stack, catering to real-time analytics, database monitoring, and infrastructure observability.
Jul 31, 2019 765 words in the original blog post.
Kibana 7.3.0 introduces several significant updates and enhancements, including the production readiness of Elastic Maps, which now features advanced layer styling and a new top hits aggregation feature. The release also integrates Kerberos support for seamless single-sign-on (SSO) access, allowing users to authenticate without repeated logins. Enhancements in snapshot management include delete and restore capabilities, while CSV export from saved searches is now possible with specific configurations. The SIEM and Machine Learning apps are enhanced for improved anomaly detection, and the APM app introduces a "Time spent by type" chart for better performance analysis. Additionally, this version offers improved bar chart functionalities, expanded KQL + autocomplete features, and updates to Canvas with new templates and user experience enhancements. Overall, Kibana 7.3.0 offers robust improvements across various functionalities aimed at enhancing user experience and performance efficiency.
Jul 31, 2019 1,300 words in the original blog post.
Elastic APM 7.3.0 has been released, offering significant updates and new features for users of the Elastic Stack and Elasticsearch Service. This release includes enhancements to the APM App UI and introduces support for single-page applications (SPA) using React, along with the general availability of the .NET agent, which provides automatic instrumentation for ASP.NET Core and Entity Framework Core. Users now have access to aggregated service breakdown charts in beta, allowing for quicker identification of performance issues by visualizing time spent on services. The update also simplifies the process of configuring agent sample rates through the APM UI, eliminating the need to modify YAML files for each service. Furthermore, the Real User Monitoring (RUM) agent now supports React-based SPAs without manual transaction management, and features integration with Elastic Maps through enabled geo-ip and user-agent modules. These improvements are available via the Elasticsearch Service or as part of the Elastic Stack distribution.
Jul 31, 2019 476 words in the original blog post.
Elastic Uptime Monitoring 7.3.0 has been released, offering new features and improvements for users monitoring applications through the Elastic Stack or Elasticsearch Service. A key enhancement is the introduction of "Monitor Summaries," which groups multiple Heartbeat results into a single, expandable row per monitored endpoint, allowing users to visualize and assess user experience from geographically dispersed monitors. The update also includes a refined Monitors detail screen with a "Monitor duration" chart, enabling users to see and filter the duration of endpoint checks across various locations. This release aims to enhance the usability and effectiveness of monitoring tools for users managing multiple instances of Heartbeat.
Jul 31, 2019 252 words in the original blog post.
Elastic Logs 7.3.0 introduces new features aimed at enhancing workflow efficiency, including ad-hoc keyword highlighting and improved integration with Elastic APM. Ad-hoc keyword highlighting allows users to easily identify specific terms in large volumes of logs, such as the word "error," improving the ability to pinpoint important details. The integration between Elastic Logs and APM enables seamless navigation from log events to APM traces by automatically adding the trace.id field to log messages from applications supported by logging frameworks. This integration maintains trace context, facilitating a more comprehensive view of application performance. Users can access this latest version via the Elasticsearch Service on Elastic Cloud by creating or upgrading a cluster or downloading it as part of the Elastic Stack's default distribution.
Jul 31, 2019 228 words in the original blog post.
Elasticsearch 7.3.0, based on Lucene 8.1.0, introduces several significant updates and features, including data frame transforms, which allow users to pivot data for analysis and machine learning purposes, and the rare_terms aggregation, which efficiently identifies infrequent terms in datasets. The release also enhances vector similarity functions with built-in cosine and dot product similarity measures for improved document scoring and introduces improvements to the intervals query for advanced search capabilities. The flattened object field addresses challenges related to records with numerous dynamic fields, and a new feature allows updates to index synonyms without downtime. Additional updates include voting-only master-eligible nodes to optimize cluster resource use, cross-cluster replication improvements to handle aliases, SQL query support for frozen indices, and enhanced GUI support for snapshot management. The outlier detection feature helps identify unusual data points using an unsupervised approach, complemented by the Evaluate API for performance metrics. These features aim to enhance search, analysis, and data management capabilities in Elasticsearch.
Jul 31, 2019 1,854 words in the original blog post.
Logstash 7.3.0 has been released, offering improvements and new features to enhance data processing capabilities. Key updates include enhanced pipeline-to-pipeline communication, which allows for the modular construction of separate, isolated pipelines within the same Logstash instance, improving both performance and processing modularity. This feature, initially introduced in Logstash 6.3.0, has been refined to address all known bugs, although it remains in beta. Additionally, the JMS input plugin, which was overhauled in version 7.2.0 for better performance, security, and reliability, is now bundled by default with this release, allowing users to consume data from any JMS technology into the Elastic Stack using a bring-your-own-driver model. Users are encouraged to download the latest version, test its capabilities, and provide feedback through various channels, including Twitter, forums, and the Logstash GitHub issues page.
Jul 31, 2019 348 words in the original blog post.
Elastic Stack 7.3.0 introduces several significant enhancements across its suite of products, offering new features such as data frames for live entity-centric indexing and continuous data transformation in Elasticsearch, which facilitate advanced analyses including machine learning applications like outlier detection. Elastic SIEM has been upgraded to integrate anomaly detection directly within the app, enhancing threat detection and hunting capabilities, while Elastic Maps, now production-ready, offers improved geospatial data visualization with new features like GeoJSON file support. Other updates include Elasticsearch's addition of voting-only master nodes and rare-terms aggregation, Kibana's support for Kerberos and enhanced filter aggregation, and Beats' expanded data source compatibility, alongside various enhancements in Logstash, Elastic APM, Elastic Uptime, Elastic Logs, and Elastic Infrastructure. These updates collectively enhance the functionality and usability of the Elastic Stack for diverse applications such as cyber threat monitoring, crime data analysis, and geospatial data exploration.
Jul 31, 2019 1,075 words in the original blog post.
Elastic Maps has transitioned from beta to general availability in version 7.3, offering a robust Kibana application for enhanced geospatial data analysis within the Elastic Stack. This tool allows users to visually explore location data in Elasticsearch, facilitating use cases like application performance monitoring, network security, and operational visibility. Elastic Maps integrates geospatial data with search capabilities, leveraging improved query times and storage efficiencies through a new BKD tree structure. Users benefit from features like layer classification, custom icons, and last known location tracking, alongside a GeoJSON upload feature for easy integration of enriched maps. Elastic Maps can be embedded into Kibana dashboards for seamless correlation with other data attributes. Elastic aims to continue evolving its geospatial capabilities to support diverse analytics needs, encouraging users to explore Elastic Maps by spinning up a trial cluster or using existing data in Elasticsearch.
Jul 31, 2019 885 words in the original blog post.
Elastic SIEM 7.3.0, released in July 2019, incorporates significant enhancements including the integration of machine learning anomaly detection jobs to improve threat detection and streamline security workflows. This release follows the beta version 7.2 and has received positive community feedback. Users can easily enable machine learning jobs to identify attack-related behaviors, and customize detection with the Machine Learning app. Elastic SIEM 7.3.0 also allows analysts to view underlying queries for greater customization and includes a Filebeat module for ingesting Google Cloud VPC flow logs in Elastic Common Schema format. This version is available on the Elasticsearch Service and for download, encouraging users to explore its capabilities through various resources such as the Elastic SIEM solutions page, documentation, and webinars.
Jul 31, 2019 462 words in the original blog post.
Elastic Infrastructure version 7.3.0 has been released, featuring the general availability of Metrics Explorer, which facilitates smooth exploration and analysis of infrastructure metrics by enabling visualization of CPU information across various infrastructure assets. Users can enhance and publish graphs using the Time Series Visual Builder and switch to host overviews quickly. The release also includes improved monitoring for Kubernetes through new metricsets for key components, expanded AWS module for monitoring Amazon RDS, and a new Oracle module for collecting database metrics. Additionally, the introduction of configuration-only Metricbeat modules, or light modules, allows for simpler integration with supported services, exemplified by the new CockroachDB module. This release is available on the Elasticsearch Service on Elastic Cloud and as part of the default Elastic Stack distribution.
Jul 31, 2019 653 words in the original blog post.
Elastic Cloud on Kubernetes (ECK) version 0.9.0 Alpha 2 has been released, offering a pre-release version aimed at managing Elasticsearch and Kibana on Kubernetes, with a focus on testing rather than production deployment. This update extends support beyond Google Kubernetes Engine (GKE) and vanilla Kubernetes to include Red Hat OpenShift, Azure Kubernetes Service (AKS), and Amazon EKS. It introduces Elastic APM Server as a new custom resource for enhanced application performance monitoring, supporting multiple programming languages and integrating with standards like OpenTracing. The release also enhances custom resources for Elasticsearch and Kibana, allowing custom plugins, bundles, configurations, and Docker repository specifications, which is particularly beneficial for air-gapped environments. Security features have been upgraded, with default deployment security and support for custom HTTP certificates and authentication methods like SAML and OpenID. Users are encouraged to explore the release notes for additional details and provide feedback through the Discuss forum or GitHub repository.
Jul 30, 2019 503 words in the original blog post.
Hyperledger Fabric, a blockchain framework by the Linux Foundation, can be effectively monitored using the Elastic Stack, which includes tools like Metricbeat and Filebeat to track and manage various components such as Apache Kafka, CouchDB, and Docker containers. The setup assumes deploying Hyperledger Fabric applications with components like Kafka for consensus and CouchDB for data, and uses Metricbeat modules to monitor these services, while Filebeat is configured to handle Docker logs. By enabling Prometheus metrics and configuring Heartbeat to monitor HTTP endpoints, a comprehensive dashboard provides an overview of the network's performance. Additionally, the Elastic Stack's observability features, including logs, metrics, and uptime data, are enhanced by the Infrastructure app, which offers insights into container usage, and Elastic APM for application performance monitoring. Users can explore these capabilities through a free trial of the Elasticsearch Service or by downloading the Elastic Stack, with the added option of enabling Kibana's dark mode for a customized user experience.
Jul 30, 2019 644 words in the original blog post.
In the weekly update for Kibana, significant progress was made across various aspects of the platform, including the ongoing development of the "copy-to-space" feature with API changes ready for review and improvements to Kerberos authentication within cloud environments. The New Platform migration advanced with the merging of the HTTP route handler RFC and near completion of the ContextService review, facilitating plugin registration for HTTP endpoints. Geo-maps enhancements included the integration of EMS vector tiles and new features like custom color ramps and "pew pew" maps for SIEM. The Lens visual editor received updates to support multiple chart types and embedding capabilities, while Elastic Charts focused on a shared API and state management improvements. Discover introduced a detailed shard failure error dialog, enhancing user feedback. EUI updates featured progress on Elastic Chart snippets and data grid components, aiming for an August release. The alerting service saw enhancements in error handling and API key support, alongside the introduction of a new built-in action for data indexing. Reporting efforts concentrated on improving pipeline familiarity and addressing user-reported bugs, while QA and test automation continued with visual testing and issue triaging.
Jul 29, 2019 1,705 words in the original blog post.
In July 2019, Paul Ewing and Ross Wolf discussed recent advancements in the Event Query Language (EQL), a tool developed by Endgame for expressing relationships between events in security data. This summer saw EQL presentations at conferences like Circle City Con and Bsides San Antonio, with plans to feature at Blackhat USA alongside Red Canary. New updates to EQL include an interactive shell that enhances data exploration with features such as syntax highlighting, tab completion, and the ability to export results to CSV. Additionally, EQL has expanded its Analytics Library with over 60 new analytics mapped to MITRE ATT&CK™ techniques, which help enrich and contextualize security data. These enhancements aim to aid security analysts in distinguishing between benign and potentially malicious activities. The update also improved query validation, offering real-time detection capabilities and error messaging for users. Endgame encourages community collaboration and has streamlined its contribution process, inviting users to engage via platforms like Gitter, Twitter, and GitHub.
Jul 29, 2019 1,269 words in the original blog post.
Elastic Cloud Enterprise (ECE) version 2.3 has been released, introducing role-based access control (RBAC) to enhance user management and operational efficiency. This new feature allows organizations to expand self-service access while reducing the administrative burden by enabling more precise control over deployment access and management privileges. ECE 2.3 introduces four pre-configured roles that differentiate platform and deployment management, facilitating a more self-service approach and easier delegation of permissions. The integration with identity providers like Active Directory, SAML, and LDAP simplifies user onboarding. Additionally, the release includes stability improvements and new features such as Elasticsearch heap dumps, an advanced deployment activity pane, and a deployment REST API payload example. The update marks a significant step towards more granular access control, with plans for further enhancements in future versions.
Jul 25, 2019 637 words in the original blog post.
Elastic Cloud Enterprise (ECE) 2.3 now offers generally available role-based access control (RBAC) and external authentication features, enhancing user management and security. With this update, organizations can define roles with specific access permissions for different users and integrate existing directories like LDAP, Active Directory, or SAML for user authentication. ECE provides predefined roles to simplify management, allowing users to combine roles as needed for tasks such as platform administration, deployment management, and viewing. Users can be managed natively within ECE, where native users can have their roles and permissions configured, or through external authentication providers, allowing centralized management of user credentials. The system supports LDAP, Active Directory, and SAML for authentication, offering flexibility in how user attributes are mapped to roles within ECE. Additionally, a REST API allows for programmatically managing users and roles, facilitating automation and integration with other systems.
Jul 25, 2019 1,691 words in the original blog post.
The article by Camilla Montonen explains the concept of multi-bucket impact anomalies in Elastic's machine learning features, which are marked by crosses instead of circles in anomaly detection results. These anomalies arise not from a single anomalous value but from a sequence of values across multiple buckets, indicating an unusual region in the dataset's history. The article highlights their usefulness in detecting anomalies over longer time frames, as opposed to single bucket anomalies, by analyzing examples like server request data that show periodic patterns. It discusses how multi-bucket impact anomalies can occur within typical model bounds and examines how sided detectors, like high_count and low_count, interact with these anomalies. Additionally, it explains how these anomalies are scored using multi-bucket impact values, which are independent of anomaly scores, providing a broader view of data anomalies. Lastly, the article encourages readers to explore Elastic's documentation and offers a free trial for hands-on experience.
Jul 24, 2019 2,138 words in the original blog post.
Integrating JMS with Elasticsearch Service in Elastic Cloud using Logstash enables the asynchronous collection and analysis of data from message queues like IBM MQ, Apache ActiveMQ, or Solace PubSub+, facilitating enhanced data-driven decision-making for use cases such as IoT performance monitoring and application observability. The process involves configuring Logstash as a consumer of a message queue and connecting it to Elasticsearch to parse, index, and visualize the incoming data. The Logstash JMS input plugin, updated to version 3.1.0, offers features like TLS support, failover capabilities, enhanced documentation, and the ability to selectively include message headers, properties, and bodies. Users can adapt the configuration to suit different environments, and the setup allows for the creation of visualizations and dashboards in Kibana, with monitoring facilitated by enabling relevant settings in logstash.yml. The plugin documentation also provides guidance on configuring failover and TLS, as well as filtering incoming data based on specified criteria.
Jul 24, 2019 997 words in the original blog post.
Kibana 7.2 has introduced a new query bar in its Machine Learning app to facilitate searching anomaly results for specific influencers, enhancing the analysis of datasets, particularly when certain fields are not prominently displayed in the results view. This feature is beneficial in detecting unusual activities, such as potential web attacks, by analyzing anonymized data—like the NGINX web access logs—where atypical user behavior can be identified through unusually high event rates. The query bar allows users to input searches in KQL syntax, supports wildcard queries, and offers auto-suggestions for influencer field names and values, which simplifies the process of narrowing down results to specific influencers. By enabling users to search through anomalies more efficiently, the query bar enhances navigation and usability, offering a more refined focus on potential issues within large datasets. Elastic encourages users to try this feature with a free 14-day trial of the Elasticsearch Service and invites them to engage in discussions on their machine learning forum.
Jul 23, 2019 533 words in the original blog post.
In the July 2019 update for Kibana, significant developments were highlighted, including the completion of key changes to integrate authentication into the new platform, the introduction of feature privileges that can be excluded from base privileges to facilitate transitions for ML and Reporting, and numerous enhancements across various Kibana components. The security plugin migration issues have been resolved, and efforts are ongoing to migrate the Saved Object Client to the new platform. Changes were made to the Alerting Service, including schema updates, error handling improvements, and the addition of security support. The Kibana App Architecture saw progress with embeddables and actions, while the Lens visual editor introduced the concept of "layers" for combining data tables, although the related PR has not been merged yet. Elastic Charts version 8.0.2 introduced breaking changes and new features, such as the ability to override computed colors for series. Additionally, the Canvas embeddables project aims to enhance the creation and flexibility of personalized content, while design explorations for graph visualizations and menu systems are underway. The update concluded with the removal of a charting library from EUI, marking a breaking change, and the end of life for certain Sass mixins and K6 themes.
Jul 22, 2019 1,032 words in the original blog post.
Lookslike is an open-source library developed by Elastic for testing and schema validation in Go, designed to match the structure of Golang data structures in a more powerful and Go-like way compared to JSON Schema. It allows developers to precisely or loosely match data structures and reduce code duplication by composing different field definitions. The library emerged from the Heartbeat project at Elastic, which required validation of Elasticsearch documents produced by their Uptime solution. Lookslike's architecture is built around two main types: Validator and IsDef, with Validator being used to compile schemas and IsDef for matching individual fields. The library supports flexible, composable, and nestable schemas, and includes a test helper for clear test output, making it particularly useful in testing contexts. Elastic invites contributions to expand the set of IsDefs and has provided extensive documentation on godoc.org for further learning.
Jul 18, 2019 1,072 words in the original blog post.
An Elastic-sponsored survey conducted by the Government Business Council revealed that while 44% of US federal workers reported their agencies engaged in proactive threat hunting to combat cyber threats, a significant portion either maintained a reactive stance or were unaware of their cybersecurity posture. Only one-third of respondents believed their agencies could detect an active attack within hours, and a notable 61% lacked awareness of the necessary tools for effective threat hunting. The survey underscores the critical need for federal agencies to transition from reactive to proactive cybersecurity strategies, emphasizing that success in threat hunting relies on skilled specialists who can harness advanced technologies like the Elastic Stack. Despite the availability of such technologies, the report highlights a substantial gap in intrusion awareness and incident response times, calling attention to the human element of cybersecurity challenges.
Jul 17, 2019 652 words in the original blog post.
The article provides a comprehensive guide on monitoring NGINX web servers using the Elastic Stack, focusing on the installation and configuration of Metricbeat and Filebeat to collect data, which is then stored in Elasticsearch and visualized with Kibana. Metricbeat is used to gather metrics related to server connections and client requests, while Filebeat collects access and error logs, allowing users to identify potential issues such as spikes in error logs or client requests that could indicate resource deletion or malicious activities like DDoS attacks. The guide gives step-by-step instructions for setting up Elasticsearch and configuring Metricbeat and Filebeat, including Autodiscover setups for containerized environments like Docker. It concludes with instructions on using Kibana to visualize the collected data and loading pre-configured NGINX dashboards for easier monitoring, while also encouraging users to explore different options and configurations within the Elastic Stack.
Jul 16, 2019 1,484 words in the original blog post.
Cisco Systems faced challenges with its fragmented enterprise search experience across various departments, leading to difficulties in information findability and duplicated efforts. To address this, Cisco transitioned to Elastic Cloud Enterprise (ECE) to consolidate its Elasticsearch operations into a single, managed service. This move allowed for seamless upgrades, secure and on-demand cluster provisioning, centralized maintenance, and improved operational efficiency without the need for custom development. ECE quickly became integral to Cisco's operations, powering tools like the SalesConnect app and the sales compensation reporting system, which significantly reduced report generation times. Cisco's adoption of ECE has resulted in increased innovation, agility, and faster achievement of business goals, with applications extending to analytics, personalized recommendations, and data visualization through Kibana.
Jul 15, 2019 883 words in the original blog post.
The Elastic Stack is widely employed in the energy industry to manage and analyze vast and complex energy data, offering tools for integrating geospatial, time/depth series, and full-text data into comprehensive analyses. With its intuitive Maps solution in Kibana, users can seamlessly integrate geospatial layers with other data types to explore meaningful insights. Real-world applications include enhancing Hadoop ecosystems with Elasticsearch for faster data access, real-time geospatial vessel tracking, and improving rig analytics and downhole drilling processes through real-time data streaming and machine learning. Elastic's deployment options cater to various needs, including SaaS, Elastic Cloud Enterprise, and Elastic Cloud for Kubernetes, allowing users to choose between cloud-based and self-managed solutions.
Jul 11, 2019 680 words in the original blog post.
The blog post discusses the migration process to the Elastic Common Schema (ECS) within Beats environments, following the introduction of ECS in February 2019. ECS standardizes field names and data types to facilitate uniform search and analysis across diverse data sources, which is particularly beneficial in heterogeneous environments. Migrating to ECS involves translating data sources, resolving schema conflicts, and adjusting analysis content to accommodate ECS event formats. Beats 7 events are already ECS-compatible, but users with custom pipelines must map their event sources to ECS manually. To ease the transition, Elastic Stack 7 introduced field aliases, allowing new indices to recognize old field names, though these aliases have limitations and are meant to be temporary. The blog provides a detailed example of upgrading Filebeat from version 6.8 to 7.2, highlighting the steps necessary to reindex past data and modify incoming data to match ECS, while also addressing field conflicts and the usage of field aliases. The post emphasizes the benefits of ECS for scalability and reliability, encouraging users to update their environments and utilize provided resources and forums for guidance.
Jul 10, 2019 5,356 words in the original blog post.
IST Research leverages the Elastic Stack to enhance its Pulse Platform, which aids in addressing global human security issues such as human trafficking, violent extremism, and child soldier recruitment. Initially recognized as an Elastic Cause honoree in 2017, IST Research has significantly evolved its Elastic Stack implementation, transitioning to the Elasticsearch Service on Elastic Cloud to manage cluster operations efficiently. This transition has allowed for better segmentation and specialization of clusters to meet diverse performance and scale needs, such as using Percolator for reverse querying and Pelias for reverse geocoding. The company also employs Logstash and a dedicated logging cluster for improved application insights and utilizes a multi-instance Kibana setup to provide analysts with various data visualization options. Future plans include upgrading clusters, utilizing Kibana Spaces, enhancing application monitoring with Elastic APM, and integrating Elastic App Search to refine the user search experience. These advancements allow IST Research to expand its technological capabilities and continue its humanitarian mission.
Jul 09, 2019 1,122 words in the original blog post.
In July 2019, Elastic introduced the 7.0 Upgrade Assistant in Kibana 6.7, aimed at facilitating the upgrade of the Elastic Stack to version 7.x. This tool, along with the new Kibana Upgrade APIs, is designed to ensure a seamless transition by highlighting necessary preparations such as backing up the Elasticsearch cluster using the Snapshot and Restore API. Before initiating the upgrade, users are advised to review and fix breaking changes identified by the Upgrade Assistant, which categorizes issues into cluster-level and index-level concerns. A significant feature of the Upgrade Assistant is its built-in reindexing tool, which is vital for indices created in version 5.x to be compatible with 7.x. The tool also provides automation options via the Upgrade Assistant API for managing large-scale reindexing tasks. Users are encouraged to examine deprecation logs to identify outdated API calls from other applications. After addressing all deprecation warnings and logs, users can proceed with the upgrade, ensuring all components like Elasticsearch nodes, Kibana, Logstash, and Beats are updated. Post-upgrade, the Assistant may suggest additional steps, such as reindexing APM indices to align with the new Elastic Common Schema (ECS). Comprehensive guidance is available through the Stack Upgrade Guide, webinars, and detailed documentation.
Jul 08, 2019 980 words in the original blog post.
The Elastic community has been actively sharing their experiences using the Elastic Stack via the #ElasticStories hashtag on Twitter, with stories ranging from personal growth to significant technological applications. Users have described how the Elastic Stack has helped them push beyond their comfort zones and facilitated experimentation with open-source technologies, marking important learning milestones. Additionally, the technology has been employed to improve societal conditions, such as ensuring high-quality drinking water for millions and enhancing cybersecurity through effective threat intelligence and network protection. A notable achievement shared by a CEO involved the development of a business intelligence tool for telecoms within six months, highlighting the flexibility and efficiency of the Elastic Stack. Elastic continues to encourage the community to share their diverse range of use cases, showing the potential and possibilities of their technology.
Jul 03, 2019 575 words in the original blog post.
NEST and Elasticsearch.Net 7.0 have been officially released, bringing significant improvements in serialization performance, compatibility with new Elasticsearch 7.0 features, and codebase simplification. The release aligns with Elasticsearch's strategy to remove types, encouraging users to implement custom serialization to manage type information. By replacing SimpleJson and Newtonsoft.Json with Utf8Json, the update delivers faster serialization, though it omits certain features like JSON indentation for performance reasons. The client architecture has been revamped to shorten the API call chain and improve URL handling, enhancing debugging experiences. Furthermore, API methods are now namespaced for better discoverability, and a Nest.7xUpgradeAssistant Nuget package is available to aid developers in transitioning from version 6.x to 7.0. Additionally, the release introduces DiagnosticSource information to improve observability and integration with monitoring tools, and simplifies the response interface by shifting from interface to class returns, affecting the way users manage mocks and stubs. The semantics of response validation have also been refined, with changes to how success is determined based on status codes, particularly around 404 responses.
Jul 02, 2019 1,859 words in the original blog post.
Elastic has announced the beta release of its APM .NET agent, version 1.0.0-beta1, which includes significant enhancements since its alpha release, such as distributed tracing support and sampling capabilities to manage transaction recording. The agent adheres to the W3C Trace Context specification, enabling seamless tracing across services communicating over HTTP, while also allowing manual serialization and deserialization of trace-parent values for non-HTTP protocols. It introduces the capability to report various system metrics, such as memory and CPU usage, and has improved transaction naming based on routing information in ASP.NET Core to align with other Elastic APM agents. The beta version supports .NET Core and .NET Framework with automatic and manual instrumentation options, and it is compatible with Elastic APM Server version 6.5 and newer. User feedback is highly encouraged to refine features for the general availability (GA) release, with the development team actively seeking community input to enhance functionality and close the gap with other Elastic APM offerings.
Jul 02, 2019 1,691 words in the original blog post.
The Elastic App Search Magento module, now in its first beta release, integrates Elastic App Search as the base search engine for Magento, enhancing search functionality with refined APIs and dashboard tools for improved search experiences. It leverages Magento indexers to automatically sync data and synonyms with the App Search engine, enabling deep relevance tuning and analytics to optimize search results and boost conversion rates. The module can be deployed as either a managed service or a self-managed distribution, offering flexibility according to user needs and ensuring compatibility with Magento's core logic and various front-end designs. By focusing on extensibility, it allows for indexing and searching different content sources, aiming to provide a seamless developer experience. The beta release seeks feedback from the Magento community to refine the integration and ensure it meets the diverse requirements of its users.
Jul 01, 2019 865 words in the original blog post.
The Elastic Stack received the 2019 Fortress Cyber Security Award in the Threat Detection category for its innovative capabilities in securing data, infrastructure, and personnel against cyber threats. Known for its ability to process and analyze data from any source in real-time, Elastic Stack has been rapidly adopted in the security sector, enabling analysts to quickly generate and test hypotheses. Organizations like Slack, OmniSOC, and Sprint utilize Elastic to enhance their cybersecurity defenses, detect malicious activities, and reduce fraud. The introduction of Elastic SIEM in version 7.2 further demonstrates Elastic's commitment by providing an interactive workspace for security operations, enriched with machine learning and automated threat detection capabilities, which significantly boosts the efficiency and effectiveness of threat response. The Elastic Stack's ability to index data as it is ingested allows for near-instant access to information, thus facilitating the real-time monitoring and analysis necessary for modern security operations.
Jul 01, 2019 480 words in the original blog post.