Plugin & Integration Updates
- Dell OpenManage plugin has been added.
- Huawei CloudEngine plugin has been updated.
- Dell PowerProtect plugin has been added.
- ExtremeCloud IQ API integration has been added.
- Microsoft DNS plugin has been updated.
- AWS GuardDuty plugin has been updated.
- Cisco WLC plugin has been updated.
- Veeam Backup plugin has been updated.
- Huawei CES plugin has been added.
- Flowmon API plugin has been updated.
- Microsoft Entra Login Audit plugin has been added.
- HP A Series Switch plugin has been updated.
- IBM QRadar plugin has been updated.
Other Improvements
- Added /get_version API endpoint for system version retrieval.
- Added offline report path customization support.
- Added support for custom log directories with realpath resolution.
- Added bulk incident deletion support and optimized closure processes.
- Improved disk space handling, added warnings for critical thresholds, and removed old limit configs.
- Improved file locking mechanisms in poller and health check modules.
- Enhanced maintenance operations with quiet windows, cron jobs, and graceful shutdowns.
- Added tooltips for health check periods and advanced form settings.
- Enhanced UEBA urgency indicators and severity color mapping.
- Improved dashboard page permissions and sudoers validation for system users.
- Added logging for configuration issues, including KeyDB change detection.
- Added rule-flow processing updates and enrichment enhancements for alerts.
- Improved alert handling, enrichment with contextual bucket info, and asynchronous processing.
- Enhanced Elasticsearch connection logic, timeout configs, and request handling.
- Added support for MatchConditions with keyword types and existence checks.
- Improved background task reliability, including maintenance restarts and watcher states.
- Enhanced log message handling for signed/archived logs.
- Improved notification error logging and email alerting.
- Enhanced Threat Intelligence UI components (TI Table, Form Modal, API updates).
- Added system source toggle, STIX removal, and severity normalization for TI indicators.
- Added event mapping improvements for multiple plugins.
- Restructured RuleManager to support STIX → TI source queries and modifier processing.
Bug Fixes
- Fixed incident processing issues in IBM QRadar poller for closed updates.
- Fixed disk usage alerts, removed obsolete threshold configs.
- Resolved NATS subscription shutdown race conditions.
- Fixed JSON parsing issues in TriggeredAlert.
- Resolved Oracle connection test timeout and added loading messages.
- Fixed logsign-parser restart timing with added delay for graceful shutdown.
- Fixed archive watcher to run maintenance tasks upon restart.
- Resolved Redis timeout configuration and connection pooling logic.
- Fixed alert-rule-flow permission handling.
- Fixed signed log directory watchers with path resolution.
- Improved match condition evaluation performance and consistency.
- Fixed Elasticsearch URL handling and added timeout to API requests.
- Improved plugin field flattening logic and key normalization.
- Resolved dashboard access bugs for read-only users in reports section.