OpenSearch 2.19.4

Any word on when this update (and all of the security fixes) will be certified for Graylog? It’s been out for about 2 months now.

We trail the most recent version of OS by a fair bit because:

  • Graylog’s OS instance should not be open to the internet; hence much less at risk. Many security fixes are not applicable to (a properly secured) GL.
  • It’s a significant effort to regression test a new version

If there’s a specific fix you are depending on, please let us know so we can take that into account in our version planning.

1 Like

I’m guessing it’s in reference to the below cve.

As long as OS is only connected to Graylog, this is not a concern.

Current planning is to support OS 3.x with upcoming GL 7.1.

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.