Release notes

16.0.0

Breaking Changes

Elasticsearch 7 Removed

Support for Elasticsearch 7 has been completely removed. The minimum supported Elasticsearch version is now 8.2.3. Deployments running Elasticsearch 7 must upgrade before migrating to this version of Investigate.

KbnTopNavController Button Label

The KbnTopNavController no longer automatically derives a button label from the key property. Plugin authors who register top navigation buttons via topNavMenu or addItems() must now explicitly define a label property on each button object. Previously, omitting label would fall back to capitalizing each word of key (for example, key: 'my action' would render as My Action). That fallback has been removed.

// Before (label was auto-generated from key — no longer works)
{ key: 'my action', run: () => { ... } }

// After (label must be explicitly provided)
{ key: 'my action', label: i18n.translate('my.plugin.nav.myAction', { defaultMessage: 'My Action' }), run: () => { ... } }

High availability

The deprecated gun-based High Availability (HA) setup for Siren Alert has been removed. The sentinl.settings.cluster configuration option (and all of its nested properties) no longer exists. Any leftover sentinl.settings.cluster configuration in investigate.yml will now cause Investigate to fail at startup. Use the Elasticsearch-based high_availability configuration instead. For details, see the High Availability documentation.

React 19

React has been upgraded from 18 to 19. This introduces a breaking change to all Investigate plugins that use React. Plugin writers need to update how they mount their root React component from this:

import { render } from 'react-dom';
...
render(<App/>, domElement);

to this:

import { createRoot } from 'react-dom/client';
...
createRoot(domElement).render(<App/>);

Please see here for other changes that may be required depending on the React APIs your plugins use.

Deprecated

Renaming and deleting fields in the Entity Table

Renaming and deleting fields on the data model (Entity Table) page is deprecated as of 16.0.0 and will be removed in a future release. A deprecation warning is now shown when renaming or deleting fields.

New Features

  • Computed fields scripts introduced which use the Siren Scripting API to aid in data fetching and enrichment across the app. They are used predominantly to supplement graph nodes and DataRecord with externally related data. For additional details, see the Computed Fields Scripts API.

  • Semantic search support introduced for semantic_text and dense_vector fields in Dashboard’s filters Siren Search and Global Search. For additional details, see the Semantic Search.

  • Investigate now supports connecting to an array of Elasticsearch hosts. The elasticsearch.url property in investigate.yml is now deprecated and should be replaced with elasticsearch.hosts. This eliminates the single point of failure between the Investigate node and an Elasticsearch node. For example:

elasticsearch.hosts:
  - 'https://localhost:9221'
  - 'https://localhost:9222'
  - 'https://localhost:9223'

When one host becomes unreachable, Investigate will seamlessly switch to either of the remaining hosts. As long as the cluster is in a healthy state, Investigate will keep working.

Deprecations

Timelion App and Visualization

The Timelion app and visualization are deprecated and will be removed in a future release. A warning banner is now shown on the Timelion page, and the Timelion visualization is marked as deprecated in the visualization wizard. Existing Timelion visualizations continue to work.

Improvements

Bug Fixes

Security Fixes

  • Changed the ACL policy for saved objects with missing metadata from fully public to inaccessible. See Missing metadata objects for more details.