# 🎉 What’s new in Elastic 9.2

**URL:** <https://discuss.elastic.co/t/what-s-new-in-elastic-9-2/383071>\
**Category:** Announcements\
**Created:** [October 29, 2025, 11:25am UTC](https://discuss.elastic.co/t/what-s-new-in-elastic-9-2/383071 "2025-10-29T11:25:38Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [October 29, 2025, 11:25am UTC](https://discuss.elastic.co/t/what-s-new-in-elastic-9-2/383071/1 "2025-10-29T11:25:38Z")

</div>

# 🎉 What’s new in Elastic 9.2

Learn about [Elastic 9.2](https://www.elastic.co/blog/whats-new-elastic-9-2-0) with Agent Builder, DiskBBQ, Streams, Significant Events, and more.

 ![9.2](https://us1.discourse-cdn.com/elastic/original/3X/4/a/4a2d0ac9933855875b56e141125dacb221fd0cdd.png)

> Note that some of those new features are in tech preview and hidden by default but there are feature flags to enable them.

## Agent Builder

A set of AI-powered capabilities that enable developers to natively chat with their Elasticsearch data and simplify the development of custom AI agents that can achieve higher accuracy, relevance, and efficiency.

This new layer provides a framework with all the essential building blocks for creating AI Agents powered by Elasticsearch: an open set of primitives, standards‑based protocols, and secure access to data - so you can build agentic systems tailored to real-world data and requirements. For example, start to define a tool using ES|QL:

```auto
POST kbn://api/agent_builder/tools
{
  "id": "news_on_asset",
  "type": "esql",
  "description": "Find news and reports about a particular asset where ...",
  "configuration": {
    "query": "FROM financial_news, financial_reports | where MATCH(company_symbol, ?symbol) OR MATCH(entities, ?symbol) | limit 5",
    "params": {
      "symbol": {
        "type": "keyword",
        "description": "The asset symbol"
      }
    }
  ...
  }
...
}

```

You can optionally create your custom agent with:

```auto
POST kbn://api/agent_builder/agents
{
  "id": "custom_agent",
  "name": "My Custom Agent",
  "description": "Description of the custom agent",
  "configuration": {
      "instructions": "You are a finance specialist providing advices to your customers ...",
      "tools": [
          {
            "tool_ids": [
              "platform.core.search",
              "platform.core.list_indices",
              "platform.core.get_index_mapping",
              "platform.core.get_document_by_id",
              "news_on_asset"
            ]
          }
        ]
...
   }
}

```

And then just converse with your agent:

```auto
POST kbn://api/agent_builder/converse
{
    "input": "What news about DIA?",
    "agent_id": "custom_agent"
}

```

Even easier, you can also use the default agent:

```auto
POST kbn://api/agent_builder/converse
{
    "input": "what is our top portfolio account?"
}

```

## Streams

Streams brings AI-assisted parsing, intelligent logs organization, and proactive event detection into a simple, intuitive workflow, so you can focus on solving problems, not wrangling pipelines. It comes with:

- **Log parsing & structuring** : Turn chaotic log lines into structured, queryable data. Streams uses AI to find patterns, [extract fields](https://www.elastic.co/docs/solutions/observability/streams/management/extract), and [partition](https://www.elastic.co/docs/solutions/observability/streams/management/partitioning) your logs automatically — cutting through noise before the investigation begins.
- **Significant events** : Start your investigations with logs. [Significant Events](https://www.elastic.co/docs/solutions/observability/streams/management/significant-events) uses agentic AI to automatically flag signals to watch, such as errors, anomalies, or certificate expirations — so you can focus on cause, not clutter.
- **Agentless ingest** : Ingest any logs from any source, from OpenTelemetry, Fluentd, or through Elastic's one-click integrations. You can [stream directly](https://www.elastic.co/docs/solutions/observability/streams/wired-streams) to our /logs endpoint — no agents required.

**All that powered by agentic AI** : In Elastic, agentic workflows organize logs, surface significant events, and guide investigations. Combined with organizational [context](https://www.elastic.co/elasticsearch/context-engineering) grounded in your knowledgebases and runbooks, fast [ES|QL](https://www.elastic.co/docs/explore-analyze/query-filter/languages/esql) queries, and [machine learning](https://www.elastic.co/docs/explore-analyze/machine-learning), agentic AI turns raw logs into a ready-to-use source of truth.

To add it to your favorite OTel collector, just add:

```yaml
processors:
  transform/logs-streams:
      log_statements:
        - context: resource
          statements:
            - set(attributes["elasticsearch.index"], "logs")
exporters:
  debug:
  otlp/ingest:
    endpoint: ${env:ELASTIC_OTLP_ENDPOINT}
    headers:
      Authorization: ApiKey ${env:ELASTIC_API_KEY}

service:
  pipelines:
      logs:
        receivers: [filelog]
        processors: [batch, transform/logs-streams]
        exporters: [elasticsearch, debug]

```

## DiskBBQ

DiskBBQ is a disk-based alternative to HNSW for [kNN search](https://www.elastic.co/docs//solutions/search/vector/knn) on compressed vectors. It stores the vector data on disk instead of in memory, lowering RAM requirements and reducing the overall cost of vector storage and search.

To activate DiskBBQ on your index (`bbq_disk`), set the following mapping:

```json
{
  "mappings": {
    "properties": {
       "image-vector": {
        "type": "dense_vector",
        "dims": 3,
        "similarity": "l2_norm",
        "index_options": {
          "type": "bbq_disk"
        }
      }
    }
  }
}

```

## Highlights for the Elasticsearch Platform with 9.2:

**ES|QL Smart Lookup Joins** : Building on [ES|QL enhancements from Elastic 9.1](https://www.elastic.co/blog/whats-new-elastic-9-1-0), ES|QL now enables users to match on multiple fields and expressions (including \<, \>, !=) and enrich rows from a lookup index — even across remote clusters!

```auto
FROM logs-*, remote:logs-* 
| LOOKUP JOIN lookup_index ON left_field1 > right_field1 AND left_field2 <= right_field2

```

**ES|QL Time Series** : Elastic 9.2 brings native time-series analysis (`RATE`, `*_OVER_TIME`, `TBUCKET`, `TS`).

```auto
TS k8s
| STATS max_rate=MAX(RATE(network.total_bytes_in)) BY time_bucket = TBUCKET(5minute)

```

**ES|QL Smart Enrichment in Discover** : Elastic 9.2 brings in-place enrichment with LOOKUP JOIN right into Discover.

 ![Smart Enrichments](https://us1.discourse-cdn.com/elastic/original/3X/7/d/7d2c25157110580b7867b0b09643fb803d066f53.png)

**Background Search for Long-Running Queries** : Stop fighting timeouts on complex queries. This new feature in technical preview lets users run ES|QL, KQL, or DSL queries as asynchronous jobs directly from Discover. Kick off hour-long searches across years of data without blocking your workflow, and get notified upon completion.

![background-search](https://us1.discourse-cdn.com/elastic/original/3X/a/e/ae8262a5e9ae87d8b437be7497693f5a91f4450d.gif)

**Discover Tabs** : Context-switching turns into a single click (!), reducing cognitive load and enabling users to compare, validate, and pivot in parallel.

![discover-tabs](https://us1.discourse-cdn.com/elastic/original/3X/8/c/8c26a381101bf19b50110f42797deaa507fde5c8.gif)

## Start today on cloud or locally

Wanna get started on your machine in minutes with the new `start-local` feature? It's easy as:

```sh
curl -fsSL https://elastic.co/start-local | sh

```

Or start on the cloud with a free trial. Just click [here](https://www.elastic.co/cloud/).
