Kibana 8.11.0edit

For information about the Kibana 8.11.0 release, review the following information.

Known issuesedit

Gatekeeper error on macOS

Due to a version upgrade of the server binary used by Kibana and an upstream notarization issue, a Gatekeeper error may display for "node" when starting Kibana in macOS environments.

More information can be found at Download and install the Darwin package.

Breaking changesedit

Breaking changes can prevent your application from optimal operation and performance. Before you upgrade to 8.11.0, review the breaking changes, then mitigate the impact to your application.

Improve config output validation for default output.

Improve config output validation to not allow to defining multiple default outputs in Kibana configuration. For more information, refer to (#167085).

Convert filterQuery to KQL.

Converts filterQuery to a KQL query string. For more information, refer to (#161806).


The following functionality is deprecated in 8.11.0, and will be removed in 9.0.0. Deprecated functionality does not have an immediate impact on your application, but we strongly recommend you make the necessary updates after you upgrade to 8.11.0.

Updates to move from doc_root.vulnerability.package → doc_root.package (ECS).

This updates all instances of vulnerability.package to the ECS standard package fieldset. For more information, refer to (#164651).


Kibana 8.11.0 adds the following new and notable features.

  • Adds support for the new ES|QL language for Elasticsearch query rules (#165973).
  • Elasticsearch query rule can select multiple group-by terms (#166146).
  • Adds a Log tab to the Observability Rules page (#165115).
  • Adds a new Observability Rules type called Custom threshold under technical preview (#167782).
  • Adds bulk action to untrack selected alerts (#167579).
  • Introduce custom dashboards tab in service overview (#166789).
  • Adds service profiling Top 10 Functions (#166226).
  • Adds service profiling flamegraph (#165360).
  • Adds custom fields in Cases (#167016).
  • Copy panel refactor (#166991).
  • Make links panel available under technical preview (#166896).
  • Store view mode in local storage (#166523).
  • Adds a read only state for Managed Dashboards (#166204).
  • Adds resize support to the Discover field list sidebar (#167066).
Elastic Security
For the Elastic Security 8.11.0 release information, refer to Elastic Security Solution Release Notes.
Enterprise Search service
For the Elastic Enterprise Search service 8.11.0 release information, refer to Elastic Enterprise Search Release notes.
  • Set env variable ELASTIC_NETINFO:false in Kibana (#166156).
  • Added restart upgrade action (#166154).
  • Adds ability to set a proxy for agent binary source (#164168).
  • Adds ability to set a proxy for agent download source (#164078).
Lens & Visualizations
  • Adds color mapping for categorical dimensions in Lens available under technical preview (#162389).
  • Inline editing of Lens panels on a dashboard or canvas (#166169).
  • Individual annotation editing from library (#163346).
  • Convert log explorer profile into standalone app available under technical preview (#164493).
Machine Learning
  • Adds support for the ELSER v2 download in the Trained Models UI (#167407).
  • Adds data drift detection workflow from Trained Models to Data comparison view (#162853).
  • Supports for viewing and editing data retention per data stream in Index Management is available under technical preview (#167006).
  • Index details can now be viewed on a new index details page in Index Management (#165705).
  • Supports for managing, executing, and deleting enrich policies in Index Management (#164080).
  • ES|QL, a new query language, is available under technical preview in Discover and Dashboards (#146971).
Querying & Filtering
  • Saved queries can now be shared between multiple spaces (#163436).
  • Adds a document viewer to the summary pings table (#163926).

For more information about the features introduced in 8.11.0, refer to What’s new in 8.11.