Beats breaking changes

edit

This list summarizes the most important breaking changes in Beats. For the complete list, go to Beats breaking changes.

Field changes

edit

The following field changes are potentially breaking for anything that relies on these fields:

  • In Filebeat, the suricata.eve.timestamp alias field has been removed from the Suricata module.
  • In Auditbeat, the file integrity dataset no longer includes a leading dot in file.extension values. For example, it will report png instead of .png to comply with Elastic Common Schema (ECS).