03/08/2026 - Version 6.4.114 Release Notes

New Features

  • UEBA: redesigned entity overview with activity and risk trend cards, entity score rings, an urgency distribution view, and a Total Involvement Matrix heatmap that drills down into originated incidents, involved alerts, and behaviour events.
  • UEBA: new entity relationship graph on user and host detail pages, visualizing peer activity, alerts, and top actions.
  • UEBA: identities are now correlated across directory syncs (mail, UPN, sAMAccountName) and shown together on the user profile with cross-links.
  • UEBA: "Devices" is renamed to "Hosts" across UEBA and enrichment settings, and info tooltips on entity cards explain where each metric comes from.
  • Directory enrichment: the sync interval can now be configured per source for LDAP, Microsoft Entra ID, and Google Workspace.
  • Response actions now record how they were triggered (action rule, API, or user) in the new Response.TriggerSource column.
  • Host audit trail: journal monitoring can now collect an OS-level audit trail of commands executed on monitored hosts.
  • Scheduled reports now support Excel/CSV export for multiple reports, with unique file names per export job.
  • The white list permission can now be granted from the Roles page.
  • API-backed lists now support the IP match type in rule evaluation.

Plugin & Integration Updates

  • Added Ribbon GSX log parsing for GSX SYS and GSX CDR formats.
  • Added Trend Micro TippingPoint response integration.
  • Added a vendor-agnostic S3-compatible storage poller (Custom S3).
  • Added VMware VeloCloud SD-WAN poller.
  • Added Seclore EDRM plugin.
  • Added Cribl Windows Event Logs plugin with source geo-location fields (City, Country).
  • Added ManageEngine DLP Plus API poller.
  • Added Varonis Alerts SaaS API poller.
  • Added Zoho CRM audit log poller.
  • Added Zoho Mail poller with mail audit and login history streams.
  • Added FileZilla Server 1.x log format support.
  • Improved Barracuda firewall log parsing and event categorization.
  • Restored previously removed Office 365 Management fields per the normalization documentation.
  • Improved Kaspersky Security Center parsing: connection details, positional fields, and non-English console labels are now normalized into standard columns.
  • FortiMail: comma-delimited (CSV) syslog format is now supported.
  • JumpServer PAM: log lines containing NUL bytes are now parsed correctly.
  • GreyCortex Mendel: multi-word protocol and service names are now parsed.
  • ESET Endpoint: ESET PROTECT event-log notification messages are now parsed.
  • F5 BIG-IP LTM: event parsing now includes a custom category field.
  • Microsoft Exchange JSON logs: key naming is normalized for consistency.
  • Palo Alto Networks: full PAN-OS messages are now surfaced and block-IP actions have improved timeout handling.
  • Arbor Edge Defense: blacklist host actions now support automatic recovery and expiry time.
  • Cisco ISE: the connection test now checks both MnT and ERS APIs and reports per-API error details.
  • Poller reliability: corrected initial lookback windows, Netskope alert collection, the first MSSQL checkpoint, and Cloudflare R2 position tracking.

Other Improvements

  • The alarm processing pipeline has been re-engineered for higher throughput, with an auto-scaling worker pool.
  • Internal service hardening: messaging, coordination, and file synchronization services now communicate over cluster-internal interfaces only.
  • Connection Test flows for integrations and log sources have been hardened to further protect stored credentials.
  • Strengthened input validation across management and configuration APIs.
  • Sensitive parameters are no longer included in configuration import status messages.

Bug Fixes

  • MSS: hub incidents are now always stored with a valid status.
  • Configuration restore is more resilient: recovery and status gaps are closed, cross-version imports are handled, and failures are clearly reported.
  • Custom configuration export keeps reference fields, and import prunes entries whose references are missing.
  • Built-in library content is no longer missing after forming a cluster.
  • Installation safeguard: factory defaults are never re-applied over an existing installation.
  • Alert matching: empty field values are evaluated correctly in notEqual conditions, and empty match conditions are rejected.
  • Response actions: failed recoveries are retried before being dropped, and response card creation is no longer blocked by incident bookkeeping errors.
  • Health-check diagnostics no longer remain stuck in the running state after a restart.
  • Source status checks now treat out-of-window cache entries as a miss, giving accurate status results.
  • Log capture sender filters are now validated as * or an IP list.
  • Threat intelligence list snapshots now load reliably under heavy load.
  • Various UEBA accuracy and display fixes: trend cards, matrix labels, entity card queries, and machine-account exclusion.
Was this article helpful?
0 out of 0 found this helpful

Articles in this section

See more
Become a Certified Logsign User/Administrator
Sign-up for Logsign Academy and take the courses to learn about Logsign USO Platform in detail. Enjoy the courses, and get your badges and certificates. In these courses, you'll learn how to use Logsign in your work and add value to your career.
Visit Our Blog
Our Logsign USO Platform illustrate our expertise. So do the blog. Through our blog posts, deepen your knowledge on various SecOps topics or get updated about important news & modern approaches for cybersecurity. Get into the habit of reading valuable information provided by Logsign. Be a step ahead.