Skip to content

What's new in 8.16 #5953

@natasha-moore-elastic

Description

@natasha-moore-elastic

Please add your features and enhancements for 8.16. Don't forget to include the related PR link!

Detections & Response

Rules Management

  • Enable prebuilt detection rules on installation (New option to install and enable rules in one step #6051)

    Previously, installing and enabling prebuilt rules took two steps. Users can now do both in one step with the Install and enable option. This works for both single rules and multiple rules that the user selects.

Detection Engine

Threat Hunting

Explore

  • Add features here

Investigations

  • More ways to add notes ([Serverless][8.16] Notes docs #6006)

    In 8.16, you can now attach notes to alerts, events, and Timelines and manage them from the Notes page. This provides an easy way to incorproate notes into your investigative workflows to coordinate responses, conduct threat hunting, and share investigative findings.

  • New advanced setting that allows you to view analyzed events from the alert details flyout ([Request][Serverless][8.16] Visualizations in alert flyout - technical preview + advanced setting #5963)

    Now, after enabling the new securitySolution:enableVisualizationsInFlyout advanced setting, you can view analyzed alerts and events in the Visualize tab of the alert details flyout. This allows you to maintain the context of the Alerts table during your investigation and provides an easy way to preview related alerts and events.

  • Resizeable alert and event details flyouts (PR pending)

    You can now resize the alert and event details flyouts and choose how it's displayed (over the Alerts table or next to it).

Entity Analytics

  • Entity store ([8.16] Adds entity store docs #6053)

    The entity store feature allows you to query, reconcile, and maintain entity metadata from various sources, such as ingested logs, integrated identity providers, external asset repositories, and more. By extracting and storing entities from all indices in the Elastic Security default data view, the Entity Store lets you query entity metadata without real-time data searches.

    After you enable the entity store, the Entity Analytics dashboard displays the Entities section, which offers a comprehensive view of your entities. Here, you can view all hosts and users in your environment, and filter them by their source, entity risk level, and asset criticality level.

  • Asset criticality available by default (Asset criticality advanced setting removed #5991)

    The asset criticality advanced setting has been removed, meaning that asset criticality is now available by default.

  • Entity risk scoring available in multiple spaces (Entity risk scoring available in multiple Kibana spaces #5931)

    You can now enable and run entity risk scoring in multiple Kibana spaces.

  • Risk scoring recalculation after file upload (Risk scoring recalculation after file upload #5924)

    When you bulk assign asset criticality using the file upload feature, the newly assigned criticality levels are factored in during the next hourly risk scoring calculation. You can now manually trigger an immediate recalculation of entity risk scores by clicking Recalculate entity risk scores now.

Generative AI

EDR Workflows/Asset Management

Cloud Security

Endpoint

  • Add features here

Protections Experience

  • Add features here

ResponseOps

  • Add features here

Metadata

Metadata

Labels

Docset: ESSIssues that apply to docs in the Stack releaseEffort: MediumIssues that take moderate but not substantial time to completePriority: HighIssues that are time-sensitive and/or are of high customer importancehighlightsv8.16.0

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions