Elastic, creators of Elasticsearch, released Elastic Stack 7.5.0, the latest version of the all-in-one datastore, search engine, and analytics platform.
Along with the introduction of Kibana Lens, a fast and intuitive way to craft visualizations, this release offers significant enhancements to Elastic’s Observability, Security, and Enterprise Search solutions.
It is an exciting time for folks using the Elastic Stack to protect their organizations. Since the last release, Elastic has joined forces with Endgame, a leading endpoint security company, and announced the end of per-endpoint pricing for the EPP/EDR space. Unlimited endpoints are now included with Elastic’s Enterprise subscriptions, so users no longer need to choose which machines deserve protection.
For servers, if you’re already collecting security and operational data, why not protect them at the same time? And it isn’t just about servers; the security events from all of your infrastructure, including desktops and laptops, should be available to security analysts. Elastic SIEM 7.5 includes endpoint security data and alerts directly in the SIEM app.
This release also continues the push to detect threats using machine learning, from identifying unusual patterns in DNS activity that could indicate DNS tunneling or command and control behavior, to unusual logins over RDP or using the runas command, and more. The SIEM app itself is expanding to include a number of new visualizations and widgets that make threat hunting easier, from interactive visualizations of host activity to a new TLS view that surfaces unusual certificates and simplifies hunting based on TLS fingerprints, such as JA3 hash.
Kibana Lens: An entirely new data visualization experience
Kibana is, and has always been, the best way to visualize data stored in Elasticsearch and to navigate the Elastic Stack. With 7.5, Elastic is introducing Kibana Lens — an entirely new way to craft visualizations. Lens is designed to work the way users think, letting users rapidly go from raw data to meaningful visualization without needing any previous technical experience or knowledge of Elasticsearch.
It starts with a new drag-and-drop experience, along with the ability to easily switch between chart types and different index patterns. As the user adds fields to the chart, Lens provides smart suggestions to show other views of the data. Combined with the speed of Elasticsearch, Lens makes it faster and easier than ever to visualize, explore, and understand data.
Index time enrichment
Way back in Elasticsearch 5.0, Elastic first introduced the Ingest Pipeline — a way to process and enrich documents at indexing time. By building this directly into Elasticsearch, configuration via API is simple, scaling out is easy, and performance is quite fast. Over the years, Elastic has seen wide adoption of this feature and now relies on it for processing and enrichment in nearly all of its modules — the many data sources that Elastic natively supports. Whether it’s parsing a log line with grok or dissect or adding location data to an IP address, ingest pipelines are increasingly the workhorse doing the ingest-time processing in the Elastic Stack.
With the 7.5 release, Elastic is delivering one of the most requested features: lookup-based enrichment. The new Enrich processor provides an efficient way to query an Elasticsearch index and add the results to a document at indexing time. This allows users to do things like identify web services or vendors based on known IP addresses, add postal codes based on user coordinates, or look up host information ingested from a configuration management database and add the relevant metadata to a document right at indexing time.
Elastic Enterprise Search
Elastic Enterprise Search aims to connect people and teams to the content that matters most to them. For organizations with a significant Microsoft product footprint, Elastic Enterprise Search now provides one-click integrations with SharePoint Online, Office 365, and OneDrive, making it easier than ever to unify and search across content platforms.
To top it off, Enterprise Search also includes a brand new ServiceNow connector, allowing users to centralize all business operation information in one place. With these new sources now available alongside the ones already included — Salesforce, Google Drive, Atlassian JIRA, Confluence, Dropbox, and more — teams can now focus on the task at hand.
Elastic believes that to truly understand your applications and infrastructure, you need to be able to see, or observe, each layer. Elastic Observability brings together the Elastic Logs, Metrics, APM, and Uptime products to give a view across an organization. Version 7.5 of the Elastic Stack brings a significant expansion of the Elastic Metrics story and adds several key integrations between APM, logging, and security data for organizations adopting observability initiatives.
Elastic’s metrics story has gained steam in recent releases with the addition of Metrics Explorer, a purpose-built user interface for real-time metrics analytics. Elastic has also made it easier to get started with metrics using turnkey data integrations for the most important infrastructure and service metrics, including Kubernetes, Prometheus, and AWS.
In 7.5, Elastic builds on that momentum by introducing turnkey monitoring of Microsoft Azure metrics and logs as part of Elastic’s partnership with Microsoft. Finally, Elastic has also added initial support for viewing endpoint security data directly in the Elastic Metrics and Logs apps. These advances help Elastic Stack users set up monitoring of critical services more quickly and enable them to combine metrics with important events, such as audit logs from endpoint devices, more efficiently.