Plugin & Integration Updates
- MSSQL audit poller has been updated.
Other Improvements
- Added support for
epoch_msposition mode. - Added missing cluster health check components.
- Added support for syncing configurations and pulling actions for connected Cyfusions.
- Added visibility for JetStream backlog and rule-flow drops in UI metrics.
- Updated threat field mapping by renaming
threattothreat_level. - Updated event mappings and log type tests.
- Improved NATS KV bucket handling with thread safety, dynamic replicas, and more reliable watchers.
- Improved NATS KV configuration handling for cluster deployments.
- Improved alert and bucket processing performance.
- Improved handling of user configurations with missing username values.
- Improved incident reconciliation and incident close tracking.
- Improved co-managed configuration synchronization and action queues.
- Improved MSS incident synchronization stability.
- Improved Redis memory configuration and connection behavior.
- Improved cache usage for source, tag, profile, asset, and Threat Intelligence lookups.
- Improved unknown source statistics and related chart performance.
- Improved LogsignStats performance with optimized RedisTimeSeries queries.
- Improved Elasticsearch readiness checks and cluster startup stability.
- Improved cluster configuration reconciliation and upgrade reliability.
- Improved NATS, Redis, and Elasticsearch restart handling during system updates.
- Improved system upgrade flow for cluster environments.
- Improved rule-flow, indexer, and persist pipeline reliability.
- Improved drop, failed, and filtered event visibility in statistics and UI charts.
- Improved source statistics by using per-bucket counters and host-agnostic metrics.
- Improved message field lookup performance.
- Improved incident distribution performance.
- Improved TableManager metrics behavior when CLI flags override configuration.
- Improved HotCache defaults and added CLI override support.
- Restored internal comment option for external organization incidents.
- Reduced RedisTimeSeries statistics retention for better resource usage.
- Removed Zookeeper dependencies and migrated configuration and state management to NATS KV and Redis.
- Removed unused legacy SOAR setup installer.
- Removed unused legacy logsign-processor subsystem.
- Removed unused InfluxDB dependencies.
- Removed unused Zookeeper imports and legacy configuration branches.
- Optimized NATS client limits and Redis connection pooling for better performance.
- SSH login monitoring has been updated with journal-based checking.
- Prevented super admin users from being assigned as analysts.
- Limited unknown sources chart to top IPs by event count.
- NTP health check integration has been added.
- Disabled JetStream by default.