Skip to content
Merged
Show file tree
Hide file tree
Changes from 5 commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions docs/release-notes.asciidoc
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,7 @@ This section summarizes the changes in each release.
* <<release-notes-8.18.2, {elastic-sec} version 8.18.2>>
* <<release-notes-8.18.1, {elastic-sec} version 8.18.1>>
* <<release-notes-8.18.0, {elastic-sec} version 8.18.0>>
* <<release-notes-8.17.10, {elastic-sec} version 8.17.10>>
* <<release-notes-8.17.9, {elastic-sec} version 8.17.9>>
* <<release-notes-8.17.8, {elastic-sec} version 8.17.8>>
* <<release-notes-8.17.7, {elastic-sec} version 8.17.7>>
Expand Down
23 changes: 19 additions & 4 deletions docs/release-notes/8.17.asciidoc
Original file line number Diff line number Diff line change
Expand Up @@ -2,13 +2,28 @@
== 8.17

[discrete]
[[release-notes-8.17.9]]
=== 8.17.9
[[release-notes-8.17.10]]
=== 8.17.10

[discrete]
[[enhancements-8.17.9]]
[[enhancements-8.17.10]]
==== Enhancements
* Shortens the time it takes to recover from a `DEGRADED` status caused by {elastic-agent} communication issues.
* Due to an issue in macOS, {elastic-defend} would sometimes send network events without `user.name` populated. {elastic-defend} now identifies these events and populates `user.name` if necessary.
* Reduces {elastic-defend} CPU when processing events from the System process.
* Reduces {elastic-defend} CPU usage for ETW events, API events, and Behavioral Protections. In some cases, this may be a significant reduction.

[discrete]
[[bug-fixes-8.17.10]]
==== Fixes
* Fixes a race condition in {elastic-defend} on Windows that occasionally resulted in corrupted process command lines. This could cause incorrect values for `process.command_line`, `process.args_count`, and `process.args`, leading to false positives.
* Improves the efficiency of the {elastic-defend} malware scan queue by not blocking scan requests when an oplock for the file being scanned cannot be acquired.
* Fixes an issue in {elastic-defend} performance metrics that resulted in `endpoint_uptime_percent` always being 0 for behavioral rules.
* Fixes an issue in {elastic-defend} that could result in a crash if a {ls} output configuration is specified containing a certificate which cannot not be parsed.
* Shortens the time it takes for {elastic-defend} to recover from a `DEGRADED` status caused by {agent} communication issues.

[discrete]
[[release-notes-8.17.9]]
=== 8.17.9

[discrete]
[[bug-fixes-8.17.9]]
Expand Down