Skip to content

Conversation

@eedugon
Copy link
Contributor

@eedugon eedugon commented Dec 17, 2025

When we added that document we didn't realized we already had documented some specific steps and checks for Elastic Security users regarding detection rules.

This PR adds a note for the 7.17 --> 8.19 upgrade step to remind Elastic Security users to read that doc and highlights some of the items.

Closes #3619

@github-actions
Copy link
Contributor

github-actions bot commented Dec 17, 2025

Vale Linting Results

Summary: 1 suggestion found

💡 Suggestions (1)
File Line Rule Message
deploy-manage/upgrade/deployment-or-cluster/upgrade-717.md 102 Elastic.Capitalization '8.19 upgrade preparations' should use sentence-style capitalization.

@github-actions
Copy link
Contributor

github-actions bot commented Dec 17, 2025

🔍 Preview links for changed docs

Copy link
Collaborator

@shainaraskas shainaraskas left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think the experience team should validate this as well

It's highly recommended to start this upgrade from the latest 7.17.x patch release to ensure that you’re using the most recent version of the Elastic Upgrade Assistant. You should also upgrade to the latest available 8.19.x patch release so that the same benefits apply when you later upgrade to 9.x.

:::::{note}
If you use the [{{elastic-sec}} solution](/solutions/security.md), read the full [Upgrade {{elastic-sec}} from 7.17 to 8.x](https://www.elastic.co/guide/en/security/8.19/upgrade-7.17-8x.html) guide when planning the upgrade.
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

perhaps this should be a warning?

Suggested change
If you use the [{{elastic-sec}} solution](/solutions/security.md), read the full [Upgrade {{elastic-sec}} from 7.17 to 8.x](https://www.elastic.co/guide/en/security/8.19/upgrade-7.17-8x.html) guide when planning the upgrade.
If you use the [{{elastic-sec}} solution](/solutions/security.md), then you need to perform additional steps as part of the upgrade process. Review [Upgrade {{elastic-sec}} from 7.17 to 8.x](https://www.elastic.co/guide/en/security/8.19/upgrade-7.17-8x.html) before you begin your upgrade.

Copy link
Contributor

@nastasha-solomon nastasha-solomon Dec 17, 2025

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'm in favor of switching the admonition to a warning and using the stronger, more direct language. There's a good amount of pre and post checks that users will need to complete when moving from 7.17->8.x, so the more emphasis, the better.

Copy link
Contributor

@nastasha-solomon nastasha-solomon left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Just left one suggestion that's totally optional. Otherwise, lgtm - thank you!

If you use the [{{elastic-sec}} solution](/solutions/security.md), read the full [Upgrade {{elastic-sec}} from 7.17 to 8.x](https://www.elastic.co/guide/en/security/8.19/upgrade-7.17-8x.html) guide when planning the upgrade.

In particular:
* Export all custom detection rules as a backup before upgrading, in case there are issues with the detection engine after the upgrade.
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We don't explicitly recommend this in the guide for upgrading from 7.17.x -> 8.x, but there's really no harm in advising it here. If anything, it's sound advice for upgrading to any Security version.


In particular:
* Export all custom detection rules as a backup before upgrading, in case there are issues with the detection engine after the upgrade.
* Review [alert schema changes](https://www.elastic.co/guide/en/security/8.19/alert-schema.html) if alerts are forwarded to an external SOAR, or if you directly query alert data in custom dashboards or tools.
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
* Review [alert schema changes](https://www.elastic.co/guide/en/security/8.19/alert-schema.html) if alerts are forwarded to an external SOAR, or if you directly query alert data in custom dashboards or tools.
* Review [alert schema changes](https://www.elastic.co/guide/en/security/8.19/alert-schema.html) if alerts are forwarded to an external SOAR, or if you directly query alert data in custom dashboards or visualizations.


It's highly recommended to start this upgrade from the latest 7.17.x patch release to ensure that you’re using the most recent version of the Elastic Upgrade Assistant. You should also upgrade to the latest available 8.19.x patch release so that the same benefits apply when you later upgrade to 9.x.

:::::{note}
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@natasha-moore-elastic or @jmikell821 can you please take a look at this change.

Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

hah. never mind, @nastasha-solomon beat me to it (again!)

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

me jumping on PR reviews:
pr-reviews

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Add to the 7.17 to 9.x upgrade doc info about Security solution

5 participants