What Changed

Logstash output plugin for Microsoft Sentinel updated from v2.2.0 to v2.2.1 with enhanced operational visibility and security guidance.

Security Impact (Visibility & Fidelity)

The functional change adds info-level logging when batches are successfully sent, improving operational observability for data ingestion monitoring. No data fidelity impact — this is enhanced telemetry, not a data processing fix.

Version Support Matrix Updates

README now includes explicit security warnings for multiple Logstash versions that require security updates according to Elastic Security Advisory ESA-2026-29:

  • Versions 8.0-8.9, 8.11-8.15, 8.19.2, 9.0.8, 9.1.10, and 9.2.4-9.2.5 all flagged as requiring security updates
  • Logstash 9.3.3 added as supported version
  • Direct link provided to Elastic security discussion

This guidance helps SOC teams assess their Logstash deployment security posture alongside Sentinel connector deployment planning.

Affected Files

DataConnectors/microsoft-sentinel-log-analytics-logstash-output-plugin/CHANGELOG.md
DataConnectors/microsoft-sentinel-log-analytics-logstash-output-plugin/README.md