Releases: opensearch-project/data-prepper
Releases · opensearch-project/data-prepper
Release list
2.16.0
Immutable
release. Only release title and notes can be modified.
2026-07-02 Version 2.16.0
Breaking Changes
- Default to point-in-time for the OpenSearch source on Amazon OpenSearch Serverless (#6335)
Features
- Add experimental pull-based ingestion to write to an existing OpenSearch index through Kafka (#6835)
- Continuously tail files with the
filesource, including offset tracking, rotation detection, and glob patterns (#6782) - Add
filter_listprocessor to keep only the array elements matching a condition (#6610) - Scrape metrics from Prometheus endpoints with the pull-based Prometheus source (#1997)
- Support writing metrics to OpenSearch TSDB indices with
index_type: tsdbin the OpenSearch sink (#6644) - Convert OpenTelemetry traces into span events with a new codec (#6650)
Enhancements
- Create the log group and log stream automatically in the CloudWatch Logs sink (#6861)
- Attach Entity attributes to requests in the CloudWatch Logs sink (#6860)
- Read the Confluence and Jira bearer token from a secrets manager (#6844)
- Support legacy MD5 checksum validation for S3-compatible storage (#6780)
- Support log signals, a configurable SigV4 signing service, and additional headers in the OTLP sink (#6763)
- Add a source-layer shuffle to the Iceberg source for correct and scalable CDC processing (#6666)
- Connect to an OpenSearch instance behind a reverse proxy in the OpenSearch sink (#6654)
- Support Confluence and Jira Data Center by allowing local addresses (#6496)
- Filter S3 objects by prefix and suffix for both SQS and scan in the S3 source (#6386)
- Support path-style access in the S3 source (#6340)
- Discover indexes with a single scan in the OpenSearch source (#6169)
- Support named credentials in the AWS extension (#4637)
- Support conditional script updates of documents in the OpenSearch sink (#3563)
- Support client certificate authentication for OpenSearch (#633)
- Split array fields into separate events with the
split_eventprocessor (#5707) - Configure the sort fields used for pagination in the OpenSearch source (#6332)
- Look up private IP addresses in the GeoIP processor (#6079)
Bug Fixes
- Fix the
filesource re-reading a file indefinitely when using a codec in non-tail mode (#6934) - Prevent the CloudWatch Logs sink uploader thread from silently terminating on unchecked errors (#6887)
- Safely handle non-String
PluginConfigVariablevalues in the Confluence and Jira OAuth2 configuration (#6874) - Resolve
derived.environmentfrom resource attributes in theotel_apm_service_mapprocessor instead of always returninggeneric:default(#6786) - Fix cardinality explosion and Prometheus compatibility in
otel_apm_service_mapmetrics (#6710) - Fix the Iceberg source initial-load completion detection race between leader and worker (#6686)
- Continue reading from the OpenSearch source when some documents fail to load, logging and counting the failures (#6337)
- Accept escaped JSON pointer syntax in processor keys such as
rename_keys(#5121) - Fix
delete_sourceremoving the parsed field when writing to root in theparse_jsonprocessor (#6443)
Security
- CVE-2026-6322, CVE-2026-6321, CVE-2026-45149 - aws-cdk-lib 2.253.1 (#6913)
Maintenance
- Update the release process for OpenSearch project organization changes (#6912)
- Support automatic plugin loading in Data Prepper core (#4838)
- Support experimental features within Data Prepper plugins (#6811)
- Fix the flaky DefaultAcknowledgementSetManagerTests (#6719)
- Fix the KafkaSourceJsonTypeIT ClassCastException on the kafka_headers cast (#6865)
- Move common HTTP Basic and Bearer Token authentication into a shared module (#6767)
- Generate the OpenSearch sink mTLS test certificates at runtime instead of committing them (#6826)
2.15.1
2.15.0
2026-04-06 Version 2.15.0
Breaking Changes
Features
- Support Prometheus Remote Write v1 as an experimental source (#6533)
- Add experimental Iceberg CDC source plugin for capturing row-level changes from Apache Iceberg tables (#6552)
- Add experimental S3 Enrich processor to merge enrichment data from S3 into pipeline events (#5992)
- Add substring expression functions:
substringAfter,substringBefore,substringAfterLast,substringBeforeLast(#6612) - Add
generateUuid()expression function for the add_entries processor (#6653) - Support function composition in expressions (#6322)
Enhancements
- Support server-side encryption with KMS and DSSE-KMS in the S3 sink (#6528)
- Support open source Prometheus in the prometheus sink (#6594)
- Support getting event size via expressions (#6278)
- Mark the SQS sink as generally available (#6661)
- Rename
otel_*source plugins tootlp_*for consistency while continuing to allow old names (#6530)
Bug Fixes
- Fix Prometheus sink NullPointerException when unit or aggregationTemporality is null (#6683)
- Fix error syntax in logs-otel-v1 index template (#6646)
- Fix default dlq_pipeline not receiving failed events from the OpenSearch sink (#6643)
- Fix invalid document version events still included in OpenSearch bulk requests (#6601)
- Fix KMS encryption plugin cache using incorrect key type for lookups (#6636)
- Fix empty plugin configurations failing after Jackson upgrade (#6598)
Security
- CVE-2026-25645 - requests 2.33.0 (#6677)
- CVE-2026-33750, CVE-2026-33532 - aws-cdk-lib 2.247.0 (#6715)
Maintenance
2.14.1
2.14.0
2026-02-25 Version 2.14.0
Breaking Changes
- Report
sinkRequestLatencyandsqsSinkRequestLatencymetrics with time units. If you were previously using the scale of these metrics is now different. (#6513, #6510)
Features
- Add
otel_apm_service_mapfor application performance monitoring service map along with deriving remote service and operation (#6482, (#6539) - Streaming Lambda response support in the Data Prepper Lambda processor (#5973)
Enhancements
- Support for ARM architectures (#640)
- Enable cross-region writes in the S3 sink. (#6323)
- Support files larger than 2GB in S3/SQS (#5276)
- RDS source now handles MySql decimal data types when precision value is 19 or higher (#6339)
- Make CloudWatchLogs sink retry indefinitely for retryable errors when no DLQ configured (#6300)
- Reduce the Data Prepper tar.gz and Docker image sizes (#3356)
- Improve Logging for OpenSearch Source when there are no matching indices. (#6341)
- Make shutdown timeout configurable to prevent message loss during scale-down (#6442)
- Support compressed files in
filesource (#5245)
Bug Fixes
- Flush remaining data to S3 during shutdown (#6424)
- Remove usage of buffer accumulator from Kafka custom consumer (#6357)
Security
- protobuf-4.25.8-cp37-abi3-manylinux2014_x86_64.whl: 1 vulnerabilities (highest severity is: 8.6) (#6441)
- urllib3-2.5.0-py3-none-any.whl: 2 vulnerabilities (highest severity is: 7.5) - autoclosed (#6344)
- werkzeug-3.0.6-py3-none-any.whl: 2 vulnerabilities (highest severity is: 5.3) (#6326)
Maintenance
2.13.1
2.13.0
Run the release build against Eclipse Temurin instead of the old Open…
2.12.2
2025-10-14 Version 2.12.2
Security
- Require full TLS trust in OpenSearch plugins by default unless insecure is configured. Fixes CVE-2025-62371 / GHSA-43ff-rr26-8hx4. (#6171)
- Use standard TLS when downloading the geoip database from an HTTP URL. Fixes GHSA-3xgr-h5hq-7299. (#6167)
- Use the TLS protocol identifier. Fixes GHSA-28gg-8qqj-fhh5. (#6166)
- Updated Netty to 4.1.125 to resolve CVE-2025-55163, CVE-2025-58057, CVE-2025-58056 (#6085, #5998)
- Updated commons-lang to 3.18.0 to resolve CVE-2025-48924 (#6085)
- Updated BouncyCastle to 1.81 to resolve CVE-2025-8916 (#6085)
Maintenance
2.12.1
2025-08-05 Version 2.12.1
Bug Fixes
- Service Map does not rotate with multiple workers (#5901)
- Fixes a regression in core where
@SingleThreadannotated processors are only running the last instance. (#5904) geoipS3 download fails to handle existing files during download (#5898)geoiplocal file fails to handle existing files during download (#5899)
Security
- CVE-2025-46762 - Parquet 1.15.2 (#5923)
- CVE-2025-48734 - commons-beanutils 1.11.0 and Checkstyle 10.26.1 (#5923)
- CVE-2024-57699 - json-smart 2.5.2 (#5923)
- CVE-2025-24970 - Netty 4.1.123 (#5923)
- CVE-2025-27817 - Apache Kafka 3.9.1 and Confluent Kafka 7.9.1 (#5923)
- CVE-2024-7254 - protobuf-java 3.25.5 (#5924)
- CVE-2025-49146 - Postgresql JDBC driver 42.7.1 (#5936)
- CVE-2025-23206 - aws-cdk-lib 2.190.0 (#5925)
- CVE-2025-5889 - aws-cdk-lib 2.190.0 (#5925)
- CVE-2025-47273 - setuptools v78 (#5926)
Maintenance
- Updated the smoke tests scripts to use the end-to-end tests (#5913)
2.12.0
2025-06-26 Version 2.12.0
Breaking Changes
Features
- OTel telemetry unified source (#5596)
- Add SQS sink to Data Prepper (#5634)
- KDS cross account stream (#5687)
- Add otlp sink (for AWS X-Ray) (#5663)
- Adds the Modulus operator to Data Prepper expressions (#5685)
- Add API tokens as an Authc/z method for OpenSearch Sink (#5549)
- Add support for convering keys to lowercase/uppercase in RenameKeyProcessor (#5810)
- Add multi-line csv support (#5784)
- Add auto conversion option to convert_type processor (#5782)
- Add detect format processor (#5774)
- Add
getEventType()expression function (#5686)
Enhancements
- Allow plugins to access the default pipeline role (#4958)
- Allow disabling metrics (#5431)
- Support enabling specific experimental plugins (#5675)
- Make opensearch source scroll timeout configurable and increase default value (#5679)
Bug Fixes
- [BUG] OpenTelemetry Spans are indexed using the span id causing collisions (#5370)
- [BUG] _default route no longer seems to exist in 2.11.0 (#5763)
- Fix kafka source with glue registry (#5765)
Security
- protobuf-3.19.5-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl: 1 vulnerabilities (highest severity is: 7.5) (#5802)
- urllib3-2.2.2-py3-none-any.whl: 2 vulnerabilities (highest severity is: 5.3) (#5801)
- protobuf-3.20.3-cp39-cp39-manylinux_2_5_x86_64.manylinux1_x86_64.whl: 1 vulnerabilities (highest severity is: 7.5) (#5800)
- urllib3-1.26.19-py2.py3-none-any.whl: 2 vulnerabilities (highest severity is: 5.3) (#5799)
Maintenance
- Refactor maven downloading logic to be dynamic (#5826)