Plugin & Integration Updates
- Tenable Response integration has been updated.
- Microsoft IIS Server plugin has been updated.
- Vectra X Series plugin has been updated.
- IBM QRadar integration has been updated.
- VMware ESXi plugin has been updated.
- AWS GuardDuty plugin has been updated.
- Microsoft Defender plugin has been updated.
Other Improvements
- Improved report scheduling, execution, and duration handling.
- Enhanced alert processing stability and message publishing reliability.
- Optimized caching and lookup mechanisms for static and dynamic data sources.
- Improved concurrency handling and resource management across core services.
- Enhanced configuration flexibility for alerting, indexing, and rule processing.
- Improved documentation for configuration and service behavior.
- Enhanced integration test coverage for alerting, enrichment, and indexing scenarios.
- Added audit logging for report search queries.
- Added hourly and multi-hour scheduling options for reports.
- Improved report publishing with configurable timeout and enhanced message handling.
- Enhanced Elasticsearch connection handling and configuration.
- Introduced IP range validation for alert match conditions.
- Added performance profiling support using pprof.
- Improved indexing performance with configurable bulk indexer parameters.
- Enhanced RuleFlow processing with configurable worker limits and performance metrics.
- Introduced state tracking for improved alert processing and consistency.
- Enhanced alert enrichment with bucket descriptions and contextual information.
- Added support for bucket-based threat intelligence enrichment.
- Improved Redis configuration with enhanced connection pooling and timeout handling.
- Optimized alert matching logic for better evaluation performance.
- Added support for advanced match conditions including existence checks.
- Introduced logsign-indexer service for improved indexing and scalability.
Bug Fixes
- Fixed report export and formatting issues.
- Resolved session handling and timeout-related issues.
- Fixed handling of closed offenses in IBM QRadar integration.
- Corrected scheduled report execution timing.
- Resolved Elasticsearch connection and URL handling issues.
- Improved error handling and stability in background processing tasks.