07/09/2026 - Version 6.4.117 Release Notes

New Features

  • Windows Event Forwarding: added per-machine management and approval controls, with floating IP support for failover — docs: Windows Event Forwarding (WEF) Collector Configuration
  • Windows Event Forwarding: selected Windows Security event categories can now be excluded at the source — docs: Windows Event Forwarding (WEF) Collector Configuration
  • Added host audit events for startup, shutdown, restart, and unexpected shutdown.
  • The syslog facility value is now available in the Event.Facility column.
  • Syslog messages now retain the priority header in the raw message.

Plugin & Integration Updates

  • Added FortiDLP integration through the Event Streaming API — docs: FortiDLP Integration via API
  • Added syslog integration for Tigera Calico, available by selecting Tigera as the vendor and Calico as the product — docs: Adding Tigera Calico via Syslog
  • Added support for Seclore EDRM Policy Server audit events — docs: Adding Seclore EDRM via Syslog
  • Google Cloud Audit: TLS certificate verification is now configurable — docs: Google Cloud Audit Integration via API
  • AWS GuardDuty: alerts are now associated with incidents correctly so response rules can act on them.
  • Sophos XDR: firewall VPN, gateway, and potentially unwanted application events previously categorized as “Other Info” are now classified correctly — docs: Sophos XDR Integration via API
  • Check Point Log Exporter: events now populate Destination.DomainName from destination_domain_name.
  • Microsoft IIS: forwarded client IP addresses are now extracted and validated — Related setup guide: Microsoft IIS Source Adding via SMB
  • Microsoft DNS: debug logs forwarded with a syslog header are now supported.
  • Cisco ISE: added two previously missing configuration fields to the response-action form.
  • Cisco Switch: event-specific log parsing is corrected — Related setup guide: Adding Cisco Switch Source via Syslog
  • FortiAnalyzer: routing of logs from non-FortiGate products is corrected.
  • Microsoft IAS: invalid or unrecognized records no longer cause log-processing failures.
  • Nginx: error logs without request details are now classified correctly.
  • GFI FaxMaker: logs that omit sender information are now parsed correctly.
  • NPCore Zombie ZERO Inspector: supported log messages are recognized correctly, and unrelated messages are skipped earlier to improve parsing efficiency.
  • Expanded event classification for Fortinet, Sophos, and HP ProCurve logs.
  • Corrected missing event classifications across eight integrations.
  • Corrected inconsistent event classification labels across multiple integrations.
  • FortiAnalyzer, F5 Unified Logs, and Apache: unrelated log messages are skipped earlier to improve parsing efficiency.
  • Nginx, Cisco ASA, and FortiGate: unrelated log messages are skipped earlier to improve parsing efficiency.
  • Symantec Endpoint, Brocade Network OS, and ipoque PRX: unrelated log messages are skipped earlier to improve parsing efficiency.
  • Brocade Fabric OS, Cisco Switch, and TACACS SCADA: unrelated log messages are skipped earlier to improve parsing efficiency.
  • Improved parsing efficiency for BIND, DHCP, and ESET logs.
  • Improved parsing efficiency for MikroTik, ProFTPD, and pfSense logs.
  • Improved parsing efficiency for Symantec EDR CEF logs.

Other Improvements

  • Response actions now consistently use the global proxy configuration, and the per-device proxy field has been removed.
  • Improved rule-processing performance.
  • Increased the maximum report-note length to 3,000.

Bug Fixes

  • Improved security when processing integration configuration.
  • Hardened file permissions during cluster operations.
  • Tightened permissions on certificate-management files.
  • Hardened file permissions during installation and upgrade.
  • Windows Event Forwarding: collection definitions are now included in configuration storage and backups — Related setup guide: Windows Event Forwarding (WEF) Collector Configuration
  • Corrected field extraction for Windows events.
  • Email response actions: $GET event-field placeholders now resolve correctly in the “To Others” recipient field.
  • Fixed conflicts when multiple operations update the same feed list, and made repeated feed-list updates consistent.
  • Improved response-action completion handling.
  • Fixed matching of numeric values in queries containing OR lists.
  • Sigma rule conversion now rejects unsupported negated filters spanning multiple fields instead of producing incorrect queries.
  • Corrected column-name resolution in search results.
  • Aligned UEBA processing with the licensed feature configuration — Related setup guide: User Entity Behavior Analytics (UEBA) Overview
  • Improved background-job coordination to prevent duplicate execution and prioritize overdue jobs.
  • Fixed initial cluster setup to process all planned nodes and report failures correctly.
  • Corrected cluster reseeding so every node included in the operation processes the reset request.
  • Corrected cleanup and validation during cluster recovery.
  • Fixed certificate generation checks when a certificate-authority directory already exists.
  • Corrected installation order so the web interface certificate is created before the web server is configured.
  • Removed an invalid symbolic link from the installation package.
  • Fixed interface errors caused by a missing dependency.
Was this article helpful?
0 out of 0 found this helpful

Articles in this section

See more
Become a Certified Logsign User/Administrator
Sign-up for Logsign Academy and take the courses to learn about Logsign USO Platform in detail. Enjoy the courses, and get your badges and certificates. In these courses, you'll learn how to use Logsign in your work and add value to your career.
Visit Our Blog
Our Logsign USO Platform illustrate our expertise. So do the blog. Through our blog posts, deepen your knowledge on various SecOps topics or get updated about important news & modern approaches for cybersecurity. Get into the habit of reading valuable information provided by Logsign. Be a step ahead.