← Back to all sparks
Elasticsearch logo

Elasticsearch

DEVOPSINFRA · APIS
Velocity6.3

Search and analytics

Elastic 9.5 lands, and the storage engine itself is now the thing being rewritten.

storage-enginepromqlvector-searchagent-buildersecurity-advisories
Current state
The July advisory wave has given way to a feature release. Elastic 9.5 promotes native PromQL, the Dashboards API, Cases as Data and natural language authoring to general availability, and puts Columnar Mode, a VectorDB index mode, a multimodal semantic field and Agent Builder tracing into technical preview. The feed also carries community forum threads alongside official notes, so not everything in this window is an Elastic release.
Where it's heading
Two lines of work are running at once. Elastic is absorbing neighbouring query languages and workloads — PromQL natively, vectors as a first-class index mode, semantic fields spanning modalities — which positions the cluster as the place observability, search and retrieval all land rather than one of three systems. Underneath that, Columnar Mode drops the inverted index by default, which is a change to what Elasticsearch fundamentally is for a given index, not a tuning knob. Agent Builder tracing suggests the agent surface is far enough along to need debugging tools.
Prediction
Expect Columnar Mode and the VectorDB index mode to drive the next round of GA work, since a storage layout that changes cost per ingested field is the kind of preview customers push hard to get supported. How the technical-preview features are licensed across tiers is not stated in the release note.

Recent moves

  1. 7d ago

    Elastic 9.5: PromQL and natural language authoring GA, Columnar Mode preview

    ⚡ SPARK

    The 9.5 release turns a quarter of preview work into supported product — PromQL, the Dashboards API, Cases as Data and natural language authoring all reach GA — while opening a new preview front around storage layout and vectors. It is the first substantive feature release in this window after weeks of advisories.

    View source ↗
  2. 7d ago

    Elasticsearch monitoring tool - A chrome extension

    A community forum post announcing a third-party Chrome extension for cluster metrics. Not an Elastic release; it appears here because the feed mixes discussion threads with official notes.

    View source ↗
  3. 20d ago

    9.4.4 tag but no 9.4.4 release

    A Homebrew maintainer asking why a 9.4.4 tag exists with no matching GitHub release. A packaging question rather than a product change, though it does show how directly downstream distributors track Elastic's tags.

    View source ↗
  4. 21d ago

    Elasticsearch 8.19.19, 9.3.8, 9.4.4 Security Update (ESA-2026-74)

    An advisory for a denial of service in the ES|QL engine, where a crafted query causes exponential CPU consumption that persists after the query completes. Part of the coordinated 9.4.4 patch wave that preceded this release cycle.

    View source ↗
  5. 21d ago

    Kibana 9.4.4 Security Update (ESA-2026-73)

    A missing-authorization advisory in Kibana allowing cross-space information disclosure through the SLO health scan. Scoped to the 9.4 line, which limits the upgrade burden for the wider installed base.

    View source ↗
  6. 21d ago

    Kibana 8.19.19, 9.3.8, 9.4.4 Security Update (ESA-2026-72)

    A Kibana denial of service via excessive memory allocation in a machine learning endpoint, reachable by a low-privileged user. One of several advisories in the same wave concentrated on the machine learning surface.

    View source ↗