Skip to content

What's new in 8.17 #6237

@natasha-moore-elastic

Description

@natasha-moore-elastic

Please add your features and enhancements for 8.17. Don't forget to include the related PR link!

Detections & Response

Rules Management

  • N/A

Detection Engine

  • Suppress alerts for EQL sequence rules (No docs PR yet) - Alert suppression now supports the EQL sequence rule type. You can use it to reduce the number of repeated or duplicate detection alerts generated from EQL sequence rules.
  • LogsDB index mode with detection rules and alerts [8.17] Document impact of using logsDB for security users #6272 - The logsDB index mode allows you to store log data more efficiently. If you're considering using it, refer to to learn how it can impact your rules and alerts. This feature requires the .

Threat Hunting

Explore

  • N/A

Investigations

  • N/A

Entity Analytics

  • Add features here

Generative AI

  • Add features here

EDR Workflows/Asset Management

Cloud Security

  • Add features here

Endpoint

  • Add features here

Protections Experience

  • Add features here

ResponseOps

  • The Case action feature, which automatically creates cases from rules and was first introduced in 8.14 as a technical preview, is now generally available.

Metadata

Metadata

Labels

Docset: ESSIssues that apply to docs in the Stack releaseEffort: SmallIssues that can be resolved quicklyPriority: HighIssues that are time-sensitive and/or are of high customer importancehighlightsv8.17.0

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions