- SSL settings that were marked deprecated in version
11.14.0
are now marked obsolete, and will prevent the plugin from starting. - These settings are:
cacert
, which should be replaced byssl_certificate_authorities
keystore
, which should be replaced byssl_keystore_path
keystore_password
, which should be replaced byssl_keystore_password
ssl
, which should be replaced byssl_enabled
ssl_certificate_verification
, which should be replaced byssl_verification_mode
truststore
, which should be replaced byssl_truststore_path
truststore_password
, which should be replaced byssl_truststore_password
- #1197
- Add
x-elastic-product-origin
header to Elasticsearch requests #1195
- Vendor ECS template for Elasticsearch 9.x in built gem #1188
- Added ECS template for Elasticsearch 9.x #1187
- [DOC]
ssl_key
requires PKCS#8 format #1181
- [DOC] Logstash output.elasticsearch index can be alias or datastream #1179
- [DOC] Correct default data stream name (
logs-generic-default
) #1140
- [DOC] Adds note that ecs-compatibility is required for data streams to work properly #1174
- Fixes an issue where events containing non-unicode strings could fail to serialize correctly when compression is enabled #1169
- [DOC] Add content for sending data to Elasticsearch on serverless #1164
- Fix, avoid to populate
version
andversion_type
attributes when processing integration metadata and datastream is enabled. #1161
- Added support for propagating event processing metadata when this output is downstream of an Elastic Integration Filter and configured without explicit
version
,version_type
, orrouting
directives #1158
- Added support for propagating event processing metadata when this output is downstream of an Elastic Integration Filter and configured without explicit
index
,document_id
, orpipeline
directives #1155
- Doc: Replace
document_already_exist_exception
withversion_conflict_engine_exception
in thesilence_errors_in_log
setting example #1159
- Changed the register to initiate pipeline shutdown upon bootstrap failure instead of simply logging the error #1151
- Added
filter_path
to bulk requests to reduce the size of responses from elasticsearch #1154
- Added request header
Elastic-Api-Version
for serverless #1147
- Added support to http compression level. Deprecated
http_compression
in favour ofcompression_level
and enabled compression level 1 by default. #1148
- Added support to Serverless Elasticsearch #1445
- allow dlq_ settings when using data streams #1144
- Fixes a regression introduced in 11.14.0 which could prevent Logstash 8.8 from establishing a connection to Elasticsearch for Central Management and Monitoring core features #1141
- Fixes a regression introduced in 11.14.0 which could prevent a connection from being established to Elasticsearch in some SSL configurations #1138
- Fix: avoid to reject a batch when the Elasticsearch connection is alive and the processing should continue #1132.
- Fixes
undefined 'shutdown_requested' method
error when plugin checks if shutdown request is received #1134
- Improved connection handling under several partial-failure scenarios #1130
- Ensures an HTTP connection can be established before adding the connection to the pool
- Ensures that the version of the connected Elasticsearch is retrieved successfully before the connection is added to the pool.
- Fixes a crash that could occur when the plugin is configured to connect to a live HTTP resource that is not Elasticsearch
- Removes the ECS v8 unreleased preview warning #1131
- Restores DLQ logging behavior from 11.8.x to include the action-tuple as structured #1105
- Move async finish_register to bottom of register to avoid race condition #1125
- Added the ability to negatively acknowledge the batch under processing if the plugin is blocked in a retry-error-loop and a shutdown is requested. #1119
- [DOC] Fixed incorrect pull request link on the CHANGELOG
11.14.0
entry #1122
- Added SSL settings for: #1118
ssl_truststore_type
: The format of the truststore filessl_keystore_type
: The format of the keystore filessl_certificate
: OpenSSL-style X.509 certificate file to authenticate the clientssl_key
: OpenSSL-style RSA private key that corresponds to thessl_certificate
ssl_cipher_suites
: The list of cipher suites
- Reviewed and deprecated SSL settings to comply with Logstash's naming convention
- Deprecated
ssl
in favor ofssl_enabled
- Deprecated
cacert
in favor ofssl_certificate_authorities
- Deprecated
keystore
in favor ofssl_keystore_path
- Deprecated
keystore_password
in favor ofssl_keystore_password
- Deprecated
truststore
in favor ofssl_truststore_path
- Deprecated
truststore_password
in favor ofssl_truststore_password
- Deprecated
ssl_certificate_verification
in favor ofssl_verification_mode
- Deprecated
- Avoid crash by ensuring ILM settings are injected in the correct location depending on the default (or custom) template format, template_api setting and ES version #1102
- add technology preview support for allowing events to individually encode a default pipeline with
[@metadata][target_ingest_pipeline]
(as part of a technology preview, this feature may change without notice) #1113
- Changed the
manage_template
default value tofalse
when data streams is enabled #1111- Added the
manage_template => false
as a valid data stream option
- Added the
- Changed the log messages for data stream checks #1109
- Added more details about incompatible data streams supplied configurations
- Changed the data stream auto-configuration log levels from
debug
toinfo
- [Doc] Fixes the broken apache http client link #1101
- Log bulk request response body on error, not just when debug logging is enabled #1096
- Add legacy template API support for Elasticsearch 8 #1092
- When using an
api_key
along with eithercloud_id
or httpshosts
, you no longer need to also specifyssl => true
#1066. Fixes #935 and #1065
- Feature: expose
dlq_routed
document metric to track the documents routed into DLQ #1090
- DOC: clarify that
http_compression
option only affects requests; compressed responses have always been read independent of this setting #1030
- Fix broken link to Logstash Reference #1085
- Fixes a possible infinite-retry-loop that could occur when this plugin is configured with an
action
whose value contains a sprintf-style placeholder that fails to be resolved for an individual event. Events in this state will be routed to the pipeline's dead letter queue if it is available, or will be logged-and-dropped so that the remaining events in the batch can be processed #1080
- Feature: force unresolved dynamic index names to be sent into DLQ. This feature could be explicitly disabled using
dlq_on_failed_indexname_interpolation
setting #1084
- Feature: Adds a new
dlq_custom_codes
option to customize DLQ codes #1067
- Feature: deprecates the
failure_type_logging_whitelist
configuration option, renaming itsilence_errors_in_log
#1068
- Added support for
ca_trusted_fingerprint
when run on Logstash 8.3+ #1074
- Feat: add ssl_supported_protocols option #1055
- [DOC] Add
v8
to supported values for ecs_compatiblity defaults #1059
- Fixes an issue where events containing non-unicode strings could fail to serialize correctly when compression is enabled #1169
- NOTE: This is a backport of the relevant fix from v11.22.3 to the 11.4 series for inclusion with Logstash 7.17 maintenance releases
- Feat: upgrade manticore (http-client) library #1063
- the underlying changes include latest HttpClient (4.5.13)
- resolves an old issue with
ssl_certificate_verification => false
still doing some verification logic
- Updates ECS templates #1062
- Updates v1 templates to 1.12.1 for use with Elasticsearch 7.x and 8.x
- Updates BETA preview of ECS v8 templates for Elasticsearch 7.x and 8.x
- Feat: add support for 'traces' data stream type #1057
- Refactor: review manticore error handling/logging, logging originating cause in case of connection related error when debug level is enabled #1029
- Java causes on connection related exceptions will now be extra logged when plugin is logging at debug level
- ECS-related fixes #1046
- Data Streams requirement on ECS is properly enforced when running on Logstash 8, and warned about when running on Logstash 7.
- ECS Compatibility v8 can now be selected
- Adds ECS templates #1048
- Adds templates for ECS v1 for Elasticsearch 8.x
- Adds templates for BETA preview of ECS v8 for both Elasticsearch 7.x and 8.x
- Downgrade ECS templates, pinning to v1.10.0 of upstream; fixes an issue where ECS templates cannot be installed in Elasticsearch 6.x or 7.1-7.2, since the generated templates include fields of
type: flattened
that was introduced in Elasticsearch 7.3. #1049
- Update ECS templates from upstream;
ecs_compatiblity => v1
now resolves to templates for ECS v1.12.1 #1047. Fixes #1027
- Fix referencing Gem classes from global lexical scope #1044
- Added preflight checks on Elasticsearch #1026
- Feat: add
user-agent
header passed to the Elasticsearch HTTP connection #1038
- Fixed running post-register action when Elasticsearch status change from unhealthy to healthy #1035
- [DOC] Clarify that
http_compression
applies to requests, and remove noise about response decompression #1000
- Fixed SSL handshake hang indefinitely with proxy setup #1032
- Validate that required functionality in Elasticsearch is available upon initial connection #1015
-
Feat: Data stream support #988
-
Refactor: reviewed logging format + restored ES (initial) setup error logging
-
Feat: always check ES license #1005
Since Elasticsearch no longer provides an OSS artifact the plugin will no longer skip the license check on OSS Logstash.
- Fixed an issue where a single over-size event being rejected by Elasticsearch would cause the entire entire batch to be retried indefinitely. The oversize event will still be retried on its own and logging has been improved to include payload sizes in this situation #972
- Fixed an issue with
http_compression => true
where a well-compressed payload could fit under our outbound 20MB limit but expand beyond Elasticsearch's 100MB limit, causing bulk failures. Bulk grouping is now determined entirely by the decompressed payload size #823 - Improved debug-level logging about bulk requests.
- Feat: assert returned item count from _bulk #997
- Fixed an issue where a retried request would drop "update" parameters #800
- Avoid to implicitly set deprecated type to
_doc
when connects to Elasticsearch version 7.x #994
- [DOC] Update links to use shared attributes #985
- Fixed an issue when assigning the no-op license checker #984
- Refactored configuration options into specific and shared in PluginMixins namespace #973
- Refactored common methods into specific and shared in PluginMixins namespace #976
- Added composable index template support for elasticsearch version 8 #980
- [DOC] Fixed links to restructured Logstash-to-cloud docs #975
- [DOC] Document the permissions required in secured clusters #969
- Changed: don't set the pipeline parameter if the value resolves to an empty string #962
- [DOC] Added clarifying info on http compression settings and behaviors #943
- [DOC] Fixed entry for ilm_policy default value#956
- Fixed an issue introduced in 10.6.0 that broke Logstash Core's monitoring feature when this plugin is run in Logstash 7.7-7.8. #953
- Added
ecs_compatiblity
mode, for managing ECS-compatable templates #952
- [DOC] Removed outdated compatibility notices, reworked cloud notice, and fixed formatting for
hosts
examples #938
- Added api_key support #934
- [DOC] Added note about
_type
setting change fromdoc
to_doc
#884
- Fixed default index value #927
- [DOC] Replaced link to Elastic Cloud trial with attribute, and fixed a comma splice #926
- [DOC] Replaced setting name with correct value #919
- Fixed integration tests for Elasticsearch 7.6+ #922
- Fixed integration tests for Elasticsearch API
7.5.0
#923
- Fix: handle proxy => '' as if none was set #912
- Feat: Added support for cloud_id and cloud_auth #906
- Opened type removal logic for extension. This allows X-Pack Elasticsearch output to continue using types for special case
/_monitoring
bulk endpoint, enabling a fix for LogStash #11312. #900
- Fixed 8.x type removal compatibility issue #892
- Deprecation: Added warning about connecting a default Distribution of Logstash with an OSS version of ES #875
- Added template for connecting to ES 8.x #871
- Added sniffing support for ES 8.x #878
- Added cluster id tracking through the plugin metadata registry #857
- Fixed bug where index patterns in custom templates could be erroneously overwritten #861
- Reverted
document_type
obsoletion #844
- Changed deprecated
document_type
option to obsolete #824 - Remove support for parent child (still support join data type) since we don't support multiple document types any more
- Removed obsolete
flush_size
andidle_flush_time
- Switched default setting for ilm_enabled to 'auto' #838
- Added 'auto' setting for ilm_enabled with default of 'false'
- Fixed sniffing support for 7.x #827
- Fixed issue with escaping index names which was causing writing aliases for ILM to fail #831
- Adds support for Index Lifecycle Management for Elasticsearch 6.6.0 and above, running with at least a Basic License(Beta) #805
- Fixed support for Elasticsearch 7.x #812
- Tweaked logging statements to reduce verbosity
- Fixed numerous issues relating to builds on Travis #799
- Added text offering hosted Elasticsearch service
- Added support for customizing HTTP headers #782
- Log an error -- not a warning -- when ES raises an invalid_index_name_exception.
- Improve plugin behavior when Elasticsearch is down on startup #758
- No user facing changes, removed unnecessary test dep.
- Docs: Set the default_codec doc attribute.
- Set number_of_shards to 1 and document_type to '_doc' for es 7.x clusters #741 #747
- Fix usage of upsert and script when update action is interpolated #239
- Add metrics to track bulk level and document level responses #585
- Ignore master-only nodes when using sniffing
- Ignore event's type field for the purpose of setting document
_type
if cluster is es 6.x or above
- Update gemspec summary
- Change default document type to 'doc' from 'logs' to align with beats and reflect the generic nature of logstash.
- Deprecate 'document_type' option
- Use
#response_body
instead of#body
when debugging response from the server #679
- Docs: Add DLQ policy section
- Improved Elasticsearch version handling
- Improved event error logging when DLQ is disabled in Logstash
- Retry all non-200 responses of the bulk API indefinitely
- Improve documentation on retry codes
- Support Elasticsearch 6.x join field type
- Fix bug where logging errors for bad response codes would raise an unhandled exception
- Fix some documentation issues
- Breaking: make deprecated options :flush_size and :idle_flush_time obsolete
- Remove obsolete options :max_retries and :retry_max_items
- Fix: handling of initial single big event
- Fix: typo was enabling http compression by default this returns it back to false
- Properly support characters needing escaping in users / passwords across multiple SafeURI implementions (pre/post LS 5.5.1)
- Logstash 5.5.0 does NOT work with this release as it has a broken SafeURI implementation
- Bump for doc gen
- Fix incorrect variable reference when DLQing events
- Fix incorrect handling of bulk_path containing ?s
- Fix JRuby 9k incompatibilities and use new URI class that is JRuby 9k compatible
- Fix error where a 429 would cause this output to crash
- Wait for all inflight requests to complete before stopping
- Fix the backwards compatibility layer used for detecting DLQ capabilities in logstash core
- Log 429 errors as debug instead of error. These aren't actual errors and cause users undue concern. This status code is triggered when ES wants LS to backoff, which it does correctly (exponentially)
- Docs: Add requirement to use version 6.2.5 or higher to support sending Content-Type headers.
- Expose a
#post
method in the http client class to be use by other modules
- Support 6.0.0-alpha1 version of Elasticsearch by adding a separate 6x template
- Note: This version is backwards compatible w.r.t. config, but for ES 6.0.0,
_all
has been removed. This BWC issue only affects ES version 6.x; older versions can be used with this plugin as is.
- Add support to compress requests using the new
http_compression
option.
- introduce customization of bulk, healthcheck and sniffing paths with the behaviour:
- if not set: the default value will be used
- if not set and path is also set: the default is appended to path
- if set: the set value will be used, ignoring the default and path setting
- removes absolute_healthcheck_path and query_parameters
- Fixed: Change how the healthcheck_path is treated: either append it to any existing path (default) or replace any existing path Also ensures that the healthcheck url contains no query parameters regarless of hosts urls contains them or query_params being set. #554
- Send the Content-Type: application/json header that proper ES clients should send
- Fix bug where using escaped characters in the password field would attempt to show a warning but instead crash. The warning was also not necessary since escaped characters never worked there before.
- Fixed a bug introduced in 6.2.2 where passwords needing escapes were not actually sent to ES properly encoded.
- Fixed a bug that forced users to URL encode the
password
option. If you are currently manually escaping your passwords upgrading to this version will break authentication. You should unescape your password if you have implemented this workaround as it will otherwise be doubly encoded. URL escaping is STILL required for passwords inline with URLs in thehosts
option.
- When an HTTP error is encountered, log the response body instead of the request. The request body will still be logged at debug level.
- Add version number / version conflict support
- Add option to use an absolute healthcheck path
- Proxies requiring auth now always work when a URL is specified
- It is no longer possible to specify a proxy as a hash due to security reasons
- Fix URL normalization logic to correctly apply all settings to sniffed hosts
- Proxies requiring auth now always work when a URL is specified
- Switch internals to new LogStash::Util::SafeURI type for more defensive approach to logging credentials
- Correctly sniff against ES 5.x clusters
- Perform healthcheck against hosts right after startup / sniffing
- Add support for custom query parameters
- Docs: Remove mention of using the elasticsearch_java output plugin because it is no longer supported
- Add
sprintf
or event dependent configuration when specifying ingest pipeline
- Hide user/password in connection pool
- Use byte size, not char count for bulk operation size checks
- depends on Adressable ~> 2.3.0 to satisfy development dependency of the core (logstash/#6204)
- Bulk operations will now target 20MB chunks at a time to reduce heap usage
- Change default lang for scripts to be painless, inline with ES 5.0. Earlier there was no default.
- Hide credentials in exceptions and log messages (#482)
- [internal] Remove dependency on longshoreman project
- Hide user and password from the URL logged during sniffing process.
- Add check_connection_timeout parameter (default 10m)
- Set default timeout to 60s
- Breaking Change: Index template for 5.0 has been changed to reflect Elasticsearch's mapping changes. Most importantly,
the subfield for string multi-fields has changed from
.raw
to.keyword
to match ES default behavior. (#386)
Users installing ES 5.x and LS 5.x This change will not affect you and you will continue to use the ES defaults.
Users upgrading from LS 2.x to LS 5.x with ES 5.x
LS will not force upgrade the template, if logstash
template already exists. This means you will still use
.raw
for sub-fields coming from 2.x. If you choose to use the new template, you will have to reindex your data after
the new template is installed.
- Relax constraint on logstash-core-plugin-api to >= 1.60 <= 2.99
- Added a configuration called failure_type_logging_whitelist which takes a list of strings, that are error types from elasticsearch, so we prevent logging WARN if elasticsearch fails with that action. See #423
- Fix bug where setting credentials would cause fatal errors. See #441
- breaking,config: Removed obsolete config
host
andport
. Please use thehosts
config with the[host:port]
syntax. - breaking,config: Removed obsolete config
index_type
. Please usedocument_type
instead. - breaking,config: Set config
max_retries
andretry_max_items
as obsolete
- Make this plugin threadsafe. Workers no longer needed or supported
- Add pool_max and pool_max_per_route options
- Fix issues where URI based paths in 'hosts' would not function correctly
- Republish all the gems under jruby.
- Update the plugin to the version 2.0 of the plugin api, this change is required for Logstash 5.0 compatibility. See elastic/logstash#5141
- Add
pipeline
configuration option for setting an ingest pipeline to run upon indexing
- Fix bug where update index actions would not work with events with 'data' field
- Add 'retry_on_conflict' configuration option which should have been here from the beginning
- Fix bug with update document with doc_as_upsert and scripting (#364, #359)
- Make error messages more verbose and easier to parse by humans
- Retryable failures are now logged at the info level instead of warning. (issue #372)
- Fix bug where SSL would sometimes not be enabled
- Host settings now are more robust to bad input
- Host settings can now take full URLs
- Make flush_size actually cap the batch size in LS 2.2+
- Used debug level instead of info when emitting flush log message
- Updated docs about template
- Scripted update support courtesy of @Da-Wei
- Fix bug where max_retry_interval was not respected for HTTP error codes
- Bump manticore dependenvy to 0.5.2
- Now retry too busy and service unavailable errors infinitely.
- Never retry conflict errors
- Fix broken delete verb that would fail due to sending body with verb
- Serialize access to the connection pool in es-ruby client
- Add support for parent relationship
- Sprintf style 'action' parameters no longer raise a LogStash::ConfigurationError
- Improved the default template to disable fielddata on analyzed string fields. #309
- Dependend on logstash-core 2.0.0 released version, rather than RC1
- Improved the default template to use doc_values wherever possible.
- Template contains example mappings for every numeric type. You must map your own fields to make use of anything other than long and double.
- Fixed dependencies (#280)
- Fixed an RSpec test (#281)
- Made host config obsolete.
- New setting: timeout. This lets you control the behavior of a slow/stuck request to Elasticsearch that could be, for example, caused by network, firewall, or load balancer issues.
- Plugins were updated to follow the new shutdown semantic, this mainly allows Logstash to instruct input plugins to terminate gracefully, instead of using Thread.raise on the plugins' threads. Ref: elastic/logstash#3895
- Dependency on logstash-core update to 2.0
- Massive internal refactor of client handling
- Background HTTP sniffing support
- Reduced bulk request size to 500 from 5000 (better memory utilization)
- Removed 'host' config option. Now use 'hosts'
- Only support HTTP Protocol
- Removed support for node and transport protocols (now in logstash-output-elasticsearch_java)
- Add update API support
- Fix warning about Concurrent lib deprecation
- Update to Elasticsearch 1.7
- Add HTTP proxy support
- Upgrade Manticore HTTP Client
- Allow client certificates
- Add 'path' parameter for ES HTTP hosts behind a proxy on a subpath
- Add option to enable and disable SSL certificate verification during handshake (#160)
- Doc improvements for clarifying round robin behavior using hosts config
- Bump es-ruby version to 1.0.10
- Disable timeouts when using http protocol which would cause bulk requests to fail (#103)