New Features🎉
Index Management
Introduced a comprehensive Index Management interface with support for search, sorting, date filtering, reindexing, and bulk actions (open, close, delete).
Integrations & Plugins
- Added Cloudflare Zero Trust API integration with polling and log processing.
- Added AlienVault OTX Response Integration.
- Added S3M Security Management log parser with related functionality.
- Added F5 BIG-IP LTM plugin.
- Added Fortinet EDR plugin.
- Enhanced CryptTech Vatos DLP plugin with JSON format support.
- Added support for CEF format in Epati Antikor plugin.
- Updated CrowdStrike Falcon API
- Updated Office 365 API
- Updated NXLog plugin
- Updated SMB plugin
- Updated Oracle Database Activity Event Plugin
- Updated TR7 WAF plugin
- Updated Stormshield Netasq plugin
- Updated Updated Cisco Meraki VPN plugin
- Updated F5 BIG_IP ASM plugin
- Updated Google Cloud Audit API plugin
Bug Fixes
- Fixed TLS connection issue and improved TCP read process for syslog collector.
- Resolved SLA key missing issue and ensured SLA durations are not zero.
- Handled NoneType and type conversion errors in action value replacement.
- Patched ZK backup date parsing, UEFI support, resizing disks with LVM, and dynamic versioning in staging.
- Fixed SLA key lookup and improved close/normal incident transitions.
- Fixed bug when changing index types in reports.
Other Improvements
- Adjusted cron job frequency for MSS incident closure.
- Added InfluxDB metrics to enhance log processing observability.
- Added Excel export enhancement: created_date now included in headers.
- Introduced set_analyst_status route for audit logging.
- Added parser service status to health checks.
- Added TLS Syslog Collector service for secure log collection.
- Added auditd package support.
- Added support for expired UI certificate detection.
- Implemented script for cloning systemd services.
- Added Nmap and other required packages.
- Added parse_filters function to improve filter decoding in settings API.
- Added created date to Excel exports.
- Updated certificate status handling in event maps.
- Added Czechia and Türkiye to country code mappings.
- Updated explicit Elasticsearch mappings for better field alignment.
- Refined close action logic and distribution handling.
- Improved incident artifact handling, response widgets, and action processing.
- Addressed mapper severity and custom plugin time field issues.
- Added timeout handling for Cloudflare, SentinelOne, and VMware APIs.
- Patched UI bugs in LicenseManagement, Excel export, localeCompare, and sorting logic.
- Removed legacy diagnostic jobs and deprecated libraries.