Plugin & Integration Updates
- AWS CloudWatch API plugin updated.
- VMware ESXi plugin updated.
- HAProxy plugin updated.
- IBM QRadar EDR plugin updated.
- Bluecoat Proxy plugin updated.
- Flowmon API plugin updated.
Technical Improvements
- Enhanced test coverage for bucket and rule management with Redis integration.
- Restructured rule flow service and decoupled alert processing logic.
- Added predefined reports and dashboards for Palo Alto Cortex XDR.
- Introduced async alert processing, improved match condition logic, and added new predicate functions.
- Integrated Redis for bucket table management and optimized bucket store initialization.
- Implemented bucket management, alert change callbacks, and alert loading functions.
- Added logsign-rule-flow and alert-rule-flow services.
- Updated alarm flow references to use rule-flow.
- Implemented buffering and drop handling in message channels for subscribers.
- Added defensive checks in FileValue parsing, and nil checks in alert predicates.
- Added plugin_factory_settings, internal_networks, and configuration sections to full backup.
- Enhanced rsync upload process with detailed logging and status tracking.
- Increased rsync timeout to 10 hours to support large transfers.
- Implemented signed and archive file uploads, including remote directory creation.
- Rule flow service logic restructuring.
- Redis-backed bucket store key generation.
- Modular initialization for RuleManager and supporting services.
- Updated time picker in scheduling forms to separate start and end time selections.
- Added validation for end time in alert rule scheduling and improved localization for configuration help texts.
- Localized time-related dashboard labels.
- Fixed font size issue in number ticker histogram widget.
- Improved alert preparation logic, incident distribution, and various internal alert rule operations.
- Improved NATS JetStream error handling and stream deletion logging.
Bug Fixes
- Fixed incorrect filter criteria in SourceStats to exclude 'None' measurements and use received value.
- Resolved layout and validation issues in leaf configuration forms.
- Updated SIEM binary build cache and added missing services to Ubuntu 24.04.