Back

Elastic
Patches for Winlogbeat x64
Windows
18 patches available
Winlogbeat ships Windows event logs to Elasticsearch or Logstash. You can install it as a Windows service. Winlogbeat reads from one or more event logs using Windows APIs, filters the events based on user-configured criteria, then sends the event data to the configured outputs
Winlogbeat x64 Version 9.0.3
Release Date
6/24/2025
Bug Fix?
Yes
Minor Release?
Yes
Patch Notes

Features and enhancements$$$Authorization:$$$$$$Fix unsupported privileges error message during role and API key creation $$$Engine:$$$$$$Threadpool merge executor is aware of available disk space $$$Threadpool merge scheduler $$$Ingest Node:$$$$$$Update traces duration mappings with appropriate unit type$$$Snapshot/Restore:$$$$$$Update shardGenerations for all indices on snapshot finalization$$$Stats:$$$$$$Optimize sparse vector stats collection
Winlogbeat x64 Version 9.0.2
Release Date
5/28/2025
Bug Fix?
Yes
Minor Release?
Yes
Patch Notes

9.0.2$$$Features and enhancements$$$Authentication:$$$$$$Http proxy support in JWT realm #127337 (issue: #114956)$$$ES|QL:$$$$$$Limit Replace function memory usage #127924$$$Fixes$$$Aggregations:$$$$$$Fix a bug in significant_terms #127975$$$Audit:$$$$$$Handle streaming request body in audit log #127798$$$Data streams:$$$$$$Fix system data streams incorrectly showing up in the list of template validation problems #128161$$$Downsampling:$$$$$$Downsampling does not consider passthrough fields as dimensions #127752 (issue: #125156)$$$ES|QL:$$$$$$Dont push down filters on the right hand side of an inlinejoin #127383$$$ESQL: Avoid unintended attribute removal #127563 (issue: #127468)$$$ESQL: Fix alias removal in regex extraction with JOIN #127687 (issue: #127467)$$$ESQL: Keep DROP attributes when resolving field names #127009 (issue: #126418)$$$Ensure ordinal builder emit ordinal blocks #127949$$$Fix union types in CCS #128111$$$Infra/Core:$$$$$$Add missing outbound_network entitlement to x-pack-core #126992 (issue: #127003)$$$Check hidden frames in entitlements #127877$$$Infra/Scripting:$$$$$$Avoid nested docs in painless execute api #127991 (issue: #41004)$$$Machine Learning:$$$$$$Append all data to Chat Completion buffer #127658$$$Fix services API Google Vertex AI Rerank location field requirement #127856$$$Relevance:$$$$$$Fix: Add NamedWriteable for RuleQueryRankDoc #128153 (issue: #126071)$$$Security:$$$$$$Remove dangling spaces wherever found #127475$$$Snapshot/Restore:$$$$$$Add missing entitlement to repository-azure #128047 (issue: #128046)$$$TSDB:$$$$$$Skip the validation when retrieving the index mode during reindexing a time series data stream #127824$$$Vector Search:$$$$$$[9.x] Revert Enable madvise by default for all builds #127921
Winlogbeat x64 Version 9.0.2
Release Date
5/28/2025
Bug Fix?
Yes
Minor Release?
Yes
Patch Notes

9.0.2$$$Features and enhancements$$$Authentication:$$$$$$Http proxy support in JWT realm #127337 (issue: #114956)$$$ES|QL:$$$$$$Limit Replace function memory usage #127924$$$Fixes$$$Aggregations:$$$$$$Fix a bug in significant_terms #127975$$$Audit:$$$$$$Handle streaming request body in audit log #127798$$$Data streams:$$$$$$Fix system data streams incorrectly showing up in the list of template validation problems #128161$$$Downsampling:$$$$$$Downsampling does not consider passthrough fields as dimensions #127752 (issue: #125156)$$$ES|QL:$$$$$$Dont push down filters on the right hand side of an inlinejoin #127383$$$ESQL: Avoid unintended attribute removal #127563 (issue: #127468)$$$ESQL: Fix alias removal in regex extraction with JOIN #127687 (issue: #127467)$$$ESQL: Keep DROP attributes when resolving field names #127009 (issue: #126418)$$$Ensure ordinal builder emit ordinal blocks #127949$$$Fix union types in CCS #128111$$$Infra/Core:$$$$$$Add missing outbound_network entitlement to x-pack-core #126992 (issue: #127003)$$$Check hidden frames in entitlements #127877$$$Infra/Scripting:$$$$$$Avoid nested docs in painless execute api #127991 (issue: #41004)$$$Machine Learning:$$$$$$Append all data to Chat Completion buffer #127658$$$Fix services API Google Vertex AI Rerank location field requirement #127856$$$Relevance:$$$$$$Fix: Add NamedWriteable for RuleQueryRankDoc #128153 (issue: #126071)$$$Security:$$$$$$Remove dangling spaces wherever found #127475$$$Snapshot/Restore:$$$$$$Add missing entitlement to repository-azure #128047 (issue: #128046)$$$TSDB:$$$$$$Skip the validation when retrieving the index mode during reindexing a time series data stream #127824$$$Vector Search:$$$$$$[9.x] Revert Enable madvise by default for all builds #127921
Winlogbeat x64 Version 9.0.1
Release Date
5/6/2025
Bug Fix?
Yes
Minor Release?
Yes
Patch Notes

9.0.1$$$Features and enhancements$$$Infra/Core:$$$$$$Validation checks on paths allowed for files entitlements. Restrict the paths we allow access to; forbidding plugins to specify/request entitlements for reading or writing to specific protected directories. #126852$$$Ingest Node:$$$$$$Updating tika to 2.9.3 #127353$$$Search:$$$$$$Enable sort optimization on float and half_float #126342$$$Security:$$$$$$Add Issuer to failed SAML Signature validation logs when available #126310 (issue: #111022)$$$Fixes$$$Aggregations:$$$$$$Rare terms aggregation false positive fix #126884$$$Allocation:$$$$$$Fix shard size of initializing restored shard #126783 (issue: #105331)$$$CCS:$$$$$$Cancel expired async search task when a remote returns its results #126583$$$Data streams:$$$$$$[otel-data] Bump plugin version to release _metric_names_hash changes #126850$$$ES|QL:$$$$$$Fix count optimization with pushable union types #127225 (issue: #127200)$$$Fix join masking eval #126614$$$Fix sneaky bug in single value query #127146$$$No; line noise isnt a valid ip #127527$$$ILM+SLM:$$$$$$Fix equality bug in WaitForIndexColorStep #126605$$$Infra/CLI:$$$$$$Use terminal reader in keystore add command #126729 (issue: #98115)$$$Infra/Core:$$$$$$Fix: consider case sensitiveness differences in Windows/Unix-like filesystems for files entitlements #126990 (issue: #127047)$$$Rework uniquify to not use iterators #126889 (issue: #126883)$$$Workaround max name limit imposed by Jackson 2.17 #126806$$$Machine Learning:$$$$$$Adding missing onFailure call for Inference API start model request #126930$$$Fix text structure NPE when fields in list have null value #125922$$$Leverage threadpool schedule for inference api to avoid long running thread #126858 (issue: #126853)$$$Ranking:$$$$$$Fix LTR rescorer with model alias #126273$$$LTR score bounding #125694$$$Search:$$$$$$Fix npe when using source confirmed text query against missing field #127414$$$TSDB:$$$$$$Improve resiliency of UpdateTimeSeriesRangeService #126637$$$Task Management:$$$$$$Fix race condition in RestCancellableNodeClient #126686 (issue: #88201)$$$Vector Search:$$$$$$Fix vec_caps to test for OS support too (on x64) #126911 (issue: #126809)$$$Fix bbq quantization algorithm but for differently distributed components #126778
Winlogbeat x64 Version 9.0.0
Release Date
4/15/2025
Bug Fix?
Yes
Minor Release?
No
Patch Notes

9.0.0$$$Highlights$$$rank_vectors field type is now available for late-interaction ranking$$$ES|QL LOOKUP JOIN is now available in technical preview$$$The semantic_text field type is now GA$$$Features and enhancements$$$Allocation:$$$$$$Add a not-master state for desired balance #116904$$$Only publish desired balance gauges on master #115383$$$Reset relocation/allocation failure counter on node join/shutdown #119968$$$Authentication:$$$$$$Allow SSHA-256 for API key credential hash #120997$$$Authorization:$$$$$$Allow kibana_system user to manage .reindexed-v8-internal.alerts indices #118959$$$Do not fetch reserved roles from native store when Get Role API is called #121971$$$Grant necessary Kibana application privileges to reporting_user role #118058$$$Make reserved built-in roles queryable #117581$$$[Security Solution] Add create_index to kibana_system role for index/DS .logs-endpoint.action.responses-* #115241$$$[Security Solution] allows kibana_system user to manage .reindexed-v8-* Security Solution indices #119054$$$CCS:$$$$$$Resolve/cluster allows querying for cluster info only (no index expression required) #119898$$$CRUD:$$$$$$Metrics for indexing failures due to version conflicts #119067$$$Remove INDEX_REFRESH_BLOCK after index becomes searchable #120807$$$Suppress merge-on-recovery for older indices #113462$$$Cluster Coordination:$$$$$$Include clusterApplyListener in long cluster apply warnings #120087$$$Data streams:$$$$$$Add action to create index from a source index #118890$$$Add index and reindex request settings to speed up reindex #119780$$$Add rest endpoint for create_from_source_index #119250$$$Add sanity check to ReindexDatastreamIndexAction #120231$$$Adding a migration reindex cancel API #118291$$$Adding get migration reindex status #118267$$$Consistent mapping for OTel log and event bodies #120547$$$Filter deprecated settings when making dest index #120163$$$Ignore closed indices for reindex #120244$$$Improve how reindex data stream index action handles api blocks #120084$$$Initial work on ReindexDatastreamIndexAction #116996$$$Make requests_per_second configurable to throttle reindexing #120207$$$Optimized index sorting for OTel logs #119504$$$Reindex data stream indices on different nodes #125171$$$Report Deprecated Indices That Are Flagged To Ignore Migration Reindex As A Warning #120629$$$Retry ILM async action after reindexing data stream #124149$$$Set cause on create index request in create from action #124363$$$Update data stream deprecations warnings to new format and filter searchable snapshots from response #118562$$$Distributed:$$$$$$Make various alias retrieval APIs wait for cluster to unblock #117230$$$Metrics for incremental bulk splits #116765$$$Use Azure blob batch API to delete blobs in batches #114566$$$Downsampling:$$$$$$Improve downsample performance by buffering docids and do bulk processing #124477$$$Improve rolling up metrics #124739
Winlogbeat x64 Version 8.17.4
Release Date
3/25/2025
Bug Fix?
Yes
Minor Release?
Yes
Patch Notes

Elasticsearch version 8.17.4$$$Bug fixes$$$edit$$$ES|QL$$$Catch parsing exception #124958 (issue: #119025)$$$Fix early termination in LuceneSourceOperator #123197$$$Indices APIs$$$Avoid hoarding cluster state references during rollover #124107 (issue: #123893)$$$[8.17] Avoid hoarding cluster state references during rollover #124267$$$Infra/Core$$$Prevent rare starvation bug when using scaling EsThreadPoolExecutor with empty core pool size. #124732 (issue: #124667)$$$Machine Learning$$$Migrate model_version to model_id when parsing persistent elser inference endpoints #124769 (issue: #124675)$$$Search$$$Do not let ShardBulkInferenceActionFilter unwrap / rewrap ESExceptions #123890$$$Don’t generate stacktrace in TaskCancelledException #125002$$$Fix concurrency issue in ScriptSortBuilder #123757$$$Revert fail-fast disconnect strategy for _resolve/cluster #124241$$$Upgrades$$$edit$$$Security$$$Bump nimbus-jose-jwt to 10.0.2 #124544
Winlogbeat x64 Version 8.17.3
Release Date
3/4/2025
Bug Fix?
Yes
Minor Release?
Yes
Patch Notes

Elasticsearch version 8.17.3$$$$$$Bug fixes$$$edit$$$Aggregations$$$Disable concurrency when top_hits sorts on anything but _score #123610$$$Allocation$$$Deduplicate allocation stats calls #123246$$$Authentication$$$Improve jwt logging on failed auth #122247$$$CRUD$$$Reduce license checks in LicensedWriteLoadForecaster #123346 (issue: #123247)$$$Data streams$$$Add _metric_names_hash field to OTel metric mappings #120952$$$EQL$$$Fix JOIN command validation (not supported) #122011$$$ES|QL$$$Fix ENRICH validation for use of wildcards #121911$$$Fix listener leak in exchange service #122417 (issue: #122271)$$$Speed up VALUES for many buckets #123073$$$Infra/Node Lifecycle$$$Block running ES 8.17 with JDK 24+ #122517$$$Ingest$$$Fix ArrayIndexOutOfBoundsException in ShardBulkInferenceActionFilter #122538$$$Ingest Node$$$Canonicalize processor names and types in IngestStats #122610$$$Deduplicate IngestStats and IngestStats.Stats identity records when deserializing #122496$$$Fix redact processor arraycopy bug #122640$$$Register IngestGeoIpMetadata as a NamedXContent #123079$$$Use ordered maps for PipelineConfiguration xcontent deserialization #123403$$$Logs$$$Fix issues that prevents using search only snapshots for indices that use index sorting. This is includes Logsdb and time series indices. #122199$$$Use min node version to guard injecting settings in logs provider #123005 (issue: #122950)$$$Mapping$$$Fix synthetic source bug that would mishandle nested dense_vector fields #122425$$$fix stale data in synthetic source for string stored field #123105 (issue: #123110)$$$Stats$$$Fixing serialization of ScriptStats cache_evictions_history #123384$$$Upgrades$$$edit$$$Authentication$$$Bump json-smart and oauth2-oidc-sdk #122737
Winlogbeat x64 Version 8.17.1
Release Date
1/21/2025
Bug Fix?
Yes
Minor Release?
Yes
Patch Notes

Elasticsearch version 8.17.1$$$Bug Fixes:$$$Aggregations$$$Fix moving function linear weighted avg #118435 (issue: #113751)$$$CCS$$$Resolve/cluster should mark remotes as not connected when a security exception is thrown #119793$$$Data streams$$$Add missing traces ilm policy for OTel traces data streams #119449$$$Downsampling$$$Handle index.mapping.ignore_malformed in downsampling #119134 (issue: #119075)$$$Support flattened field with downsampling #118816 (issue: #116319)$$$ES|QL$$$Allow DATE_PARSE to read the timezones #118603 (issue: #117680)$$$Fix ESQL async get while task is being cancelled #119897$$$Fix RLIKE folding with (unsupported) case insensitive pattern #118454$$$ILM+SLM$$$Add missing timeouts to rest-api-spec ILM APIs #118837$$$Add missing timeouts to rest-api-spec SLM APIs #118958$$$Infra/Node Lifecycle$$$Add missing timeouts to rest-api-spec shutdown APIs #118921$$$Infra/REST API$$$Add missing parameter to xpack.info rest-api-spec #118954$$$Ingest Node$$$Add missing timeouts to rest-api-spec ingest APIs #118844$$$Expose BwC enrich cache setting in plugin #119131$$$Fixing GetDatabaseConfigurationAction response serialization #119233$$$License$$$Remove unsupported timeout from rest-api-spec license API #118919$$$Machine Learning$$$Fix loss of context in the inference API for streaming APIs #118999 (issue: #119000)$$$Fix spike detection for short spikes at the tail of the data #119637$$$Fix timeout ingesting an empty string into a semantic_text field #117840$$$[Inference API] Fix bug checking for e5 or reranker default IDs #119797$$$Search$$$ESQL: connect_transport_exception should be thrown instead of verification_exception when ENRICH-ing if remote is disconnected #119750$$$Fix: do not let _resolve/cluster hang if remote is unresponsive #119516$$$Handle exceptions in query phase can match #117469 (issue: #104994)$$$$$$Enhancements:$$$$$$Authorization$$$Improve handling of nested fields in index reader wrappers #118757$$$Data streams$$$Add mapping for event_name for OTel logs #119495$$$Monitoring$$$Addition of tier_preference; creation_date and version fields in Elasticsearch monitoring template #117851$$$$$$New Features:$$$$$$Logs$$$Make logsdb general available #118559$$$$$$Refer - https://www.elastic.co/guide/en/elasticsearch/reference/8.17/release-notes-8.17.1.html
Winlogbeat x64 Version 8.17.0
Release Date
12/12/2024
Bug Fix?
Yes
Minor Release?
No
Patch Notes

Refer - https://www.elastic.co/guide/en/elasticsearch/reference/8.17/release-notes-8.17.0.html
Winlogbeat x64 Version 8.16.1
Release Date
11/21/2024
Bug Fix?
Yes
Minor Release?
Yes
Patch Notes

Beats version 8.16.1$$$View commits$$$Breaking changes$$$Packetbeat$$$Expire source port mappings. 41581$$$Bugfixes$$$Filebeat$$$Fix AWS region in aws-s3 input S3 polling mode. 41572
Winlogbeat x64 Version 8.16.0
Release Date
11/12/2024
Bug Fix?
Yes
Minor Release?
Yes
Patch Notes

Elasticsearch version 8.16.0$$$Breaking changes$$$Analysis$$$Set lenient to true by default when using updateable synonyms #110901$$$Data streams$$$Update data stream lifecycle telemetry to track global retention #112451$$$ES|QL$$$ESQL: Entirely remove META FUNCTIONS #113967$$$Mapping$$$JDK locale database change #113975$$$Search$$$Adding breaking change entry for retrievers #115399$$$Bug fixes$$$edit$$$Aggregations$$$Always check the parent breaker with zero bytes in PreallocatedCircuitBreakerService #115181$$$Force using the last centroid during merging #111644 (issue: #111065)$$$Authentication$$$Check for disabling own user in Put User API #112262 (issue: #90205)$$$Expose cluster-state role mappings in APIs #114951$$$Authorization$$$Fix DLS & FLS sometimes being enforced when it is disabled #111915 (issue: #94709)$$$Fix DLS using runtime fields and synthetic source #112341$$$CRUD$$$Don’t fail retention lease sync actions due to capacity constraints #109414 (issue: #105926)$$$Cluster Coordination$$$Ensure clean thread context in MasterService #114512$$$$$$For more details refer - https://www.elastic.co/guide/en/elasticsearch/reference/8.16/release-notes-8.16.0.html
Winlogbeat x64 Version 8.15.3
Release Date
10/17/2024
Bug Fix?
Yes
Minor Release?
Yes
Patch Notes

Elasticsearch version 8.15.3$$$Bug fixes$$$Aggregations$$$Don’t validate internal stats if they are empty #113846 (issue: #113811)$$$Fix needsScore computation in GlobalOrdCardinalityAggregator #113129 (issue: #112975)$$$Authentication$$$Enables cluster state role mapper; to include ECK operator-defined role mappings in role resolution #114337$$$ES|QL$$$ES|QL: Ensure minimum capacity for PlanStreamInput caches #114116$$$ES|QL: Skip CASE function from InferIsNotNull rule checks #113123 (issue: #112704)$$$[ESQL] Fix init value in max float aggregation #113699$$$[ESQL] Support datetime data type in Least and Greatest functions #113961$$$Machine Learning$$$Fix check on E5 model platform compatibility #113437 (issue: #113577)$$$Handle parsing ingest processors where definition is not a object #113697 (issue: #113615)$$$[ML][backport] Warn for model load failures if they have a status code <500 #113410$$$[M] Fix error message formatting #113266$$$Search$$$Fix analyzed wildcard query in simple_query_string when disjunctions is empty #114264 (issue: #114185)$$$Fix collapse interaction with stored fields #112761 (issue: #112646)$$$Enhancements$$$edit$$$Machine Learning$$$Write downloaded model parts async #111684$$$Upgrades$$$edit$$$Snapshot/Restore$$$Upgrade protobufer to 3.25.5 #113869
Winlogbeat x64 Version 8.15.1
Release Date
9/2/2024
Bug Fix?
Yes
Minor Release?
Yes
Patch Notes

Elasticsearch version 8.15.1$$$edit$$$Also see Breaking changes in 8.15.1$$$$$$Known issues$$$edit$$$Elasticsearch will not start if custom role mappings are configured using the xpack.security.authc.realms.*.files.role_mapping configuration option. As a workaround; custom role mappings can be configured using the REST API (issue: #112503)$$$Bug fixes$$$edit$$$Aggregations$$$Revert Avoid bucket copies in Aggs #111758 (issue: #111679)$$$Authorization$$$Fix DLS over Runtime Fields #112260 (issue: #111637)$$$ES|QL$$$Avoid losing error message in failure collector #111983 (issue: #111894)$$$Avoid wrapping rejection exception in exchange #112178 (issue: #112106)$$$ESQL: Fix for overzealous validation in case of invalid mapped fields #111475 (issue: #111452)$$$Geo$$$Add maximum nested depth check to WKT parser #111843$$$Always check crsType when folding spatial functions #112090 (issue: #112089)$$$Fix NPE when executing doc value queries over shape geometries with empty segments #112139$$$Indices APIs$$$Fix template alias parsing livelock #112217$$$Infra/Core$$$Fix windows memory locking #111866 (issue: #111847)$$$Ingest Node$$$Fixing incorrect bulk request took time #111863 (issue: #111854)$$$Improve performance of grok pattern cycle detection #111947$$$Logs$$$Merge multiple ignored source entires for the same field #111994 (issue: #111694)$$$Machine Learning
Winlogbeat x64 Version 8.15.0
Release Date
8/5/2024
Bug Fix?
Yes
Minor Release?
Yes
Patch Notes

Refer - https://www.elastic.co/guide/en/elasticsearch/reference/8.15/release-notes-8.15.0.html$$$
Winlogbeat x64 Version 8.14.3
Release Date
5/9/2024
Bug Fix?
Yes
Minor Release?
Yes
Patch Notes

Elasticsearch version 8.14.3$$$edit$$$Also see Breaking changes in 8.14.$$$$$$Bug fixesedit$$$Cluster Coordination$$$Ensure tasks preserve versions in MasterService #109850$$$ES|QL$$$Introduce compute listener #110400$$$Mapping$$$Automatically adjust ignore_malformed only for the @timestamp #109948$$$TSDB$$$Disallow index.time_series.end_time setting from being set or updated in normal indices #110268 (issue: #110265)
Winlogbeat x64 Version 8.13.4
Release Date
5/9/2024
Bug Fix?
Yes
Minor Release?
Yes
Patch Notes

Beats version 8.13.4edit$$$View commits$$$$$$Bugfixesedit$$$Auditbeat$$$$$$Prevent scenario of losing children-related file events in a directory for recursive fsnotify backend of auditbeat file integrity module. 39133$$$Allow extra syscalls by auditbeat required in FIM with kprobes back-end. 39361$$$Fix losing events in FIM for MacOS X by allowing always to walk an added directory to monitor. 39362$$$Metricbeat$$$$$$Fix Azure Monitor support for multiple aggregation types. 39192 39204
Winlogbeat x64 Version 8.12.2
Release Date
2/19/2024
Bug Fix?
Yes
Minor Release?
Yes
Patch Notes

Beats version 8.12.2edit$$$View commits$$$$$$Bugfixesedit$$$Filebeat$$$$$$[threatintel] MISP pagination fixes. 37898$$$Fix file handle leak when handling errors in filestream. 37973$$$Packetbeat$$$$$$Fix interface device parsing for packetbeat protocols. 37946
Winlogbeat x64 Version 8.11.3
Release Date
12/12/2023
Bug Fix?
Yes
Minor Release?
Yes
Patch Notes

Refer-$$$https://www.elastic.co/guide/en/starting-with-the-elasticsearch-platform-and-its-solutions/8.11/new.html
Winlogbeat x64 Version 8.10.4
Release Date
10/17/2023
Bug Fix?
Yes
Minor Release?
Yes
Patch Notes

Not provided by vendor;$$$For more details$$$https://www.elastic.co/guide/en/starting-with-the-elasticsearch-platform-and-its-solutions/8.10/new.html
Interested in automating patching for Winlogbeat x64?