diff --git a/CHANGELOG.next.asciidoc b/CHANGELOG.next.asciidoc index 622181854559..c73bbd843e31 100644 --- a/CHANGELOG.next.asciidoc +++ b/CHANGELOG.next.asciidoc @@ -109,7 +109,6 @@ https://github.com/elastic/beats/compare/v7.0.0-alpha2...master[Check the HEAD d - Change logging in logs input to structure logging. Some log message formats have changed. {pull}25299[25299] - All url.* fields apart from url.original in the Apache, Nginx, IIS, Traefik, S3Access, Cisco, F5, Fortinet, Google Workspace, Imperva, Microsoft, Netscout, O365, Sophos, Squid, Suricata, Zeek, Zia, Zoom, and ZScaler modules are now url unescaped due to using the Elasticsearch uri_parts processor. {pull}24699[24699] - Deprecated the cyberark module (replaced by cyberarkpas). {issue}25261[25261] {pull}25505[25505] -- Adds a script processor to the end of the filebeat-%{agent.version}-cisco-umbrella-pipeline pipeline to make sure username/email from cisco.umbrella.identities is being added to related.user *Heartbeat* @@ -863,6 +862,7 @@ https://github.com/elastic/beats/compare/v7.0.0-alpha2...master[Check the HEAD d - Add multiline support to aws-s3 input. {issue}25249[25249] {pull}25710[25710] - Add monitoring metrics to the `aws-s3` input. {pull}25711[25711] - Add Content-Type override to aws-s3 input. {issue}25697[25697] {pull}25772[25772] +- In Cisco Umbrella fileset add users from cisco.umbrella.identities to related.user. {pull}25776[25776] *Heartbeat*