New Features
- Windows Event Forwarding: added per-machine management and approval controls, with floating IP support for failover — docs: Windows Event Forwarding (WEF) Collector Configuration
- Windows Event Forwarding: selected Windows Security event categories can now be excluded at the source — docs: Windows Event Forwarding (WEF) Collector Configuration
- Added host audit events for startup, shutdown, restart, and unexpected shutdown.
- The syslog facility value is now available in the
Event.Facilitycolumn. - Syslog messages now retain the priority header in the raw message.
Plugin & Integration Updates
- Added FortiDLP integration through the Event Streaming API — docs: FortiDLP Integration via API
- Added syslog integration for Tigera Calico, available by selecting Tigera as the vendor and Calico as the product — docs: Adding Tigera Calico via Syslog
- Added support for Seclore EDRM Policy Server audit events — docs: Adding Seclore EDRM via Syslog
- Google Cloud Audit: TLS certificate verification is now configurable — docs: Google Cloud Audit Integration via API
- AWS GuardDuty: alerts are now associated with incidents correctly so response rules can act on them.
- Sophos XDR: firewall VPN, gateway, and potentially unwanted application events previously categorized as “Other Info” are now classified correctly — docs: Sophos XDR Integration via API
- Check Point Log Exporter: events now populate
Destination.DomainNamefromdestination_domain_name. - Microsoft IIS: forwarded client IP addresses are now extracted and validated — Related setup guide: Microsoft IIS Source Adding via SMB
- Microsoft DNS: debug logs forwarded with a syslog header are now supported.
- Cisco ISE: added two previously missing configuration fields to the response-action form.
- Cisco Switch: event-specific log parsing is corrected — Related setup guide: Adding Cisco Switch Source via Syslog
- FortiAnalyzer: routing of logs from non-FortiGate products is corrected.
- Microsoft IAS: invalid or unrecognized records no longer cause log-processing failures.
- Nginx: error logs without request details are now classified correctly.
- GFI FaxMaker: logs that omit sender information are now parsed correctly.
- NPCore Zombie ZERO Inspector: supported log messages are recognized correctly, and unrelated messages are skipped earlier to improve parsing efficiency.
- Expanded event classification for Fortinet, Sophos, and HP ProCurve logs.
- Corrected missing event classifications across eight integrations.
- Corrected inconsistent event classification labels across multiple integrations.
- FortiAnalyzer, F5 Unified Logs, and Apache: unrelated log messages are skipped earlier to improve parsing efficiency.
- Nginx, Cisco ASA, and FortiGate: unrelated log messages are skipped earlier to improve parsing efficiency.
- Symantec Endpoint, Brocade Network OS, and ipoque PRX: unrelated log messages are skipped earlier to improve parsing efficiency.
- Brocade Fabric OS, Cisco Switch, and TACACS SCADA: unrelated log messages are skipped earlier to improve parsing efficiency.
- Improved parsing efficiency for BIND, DHCP, and ESET logs.
- Improved parsing efficiency for MikroTik, ProFTPD, and pfSense logs.
- Improved parsing efficiency for Symantec EDR CEF logs.
Other Improvements
- Response actions now consistently use the global proxy configuration, and the per-device proxy field has been removed.
- Improved rule-processing performance.
- Increased the maximum report-note length to 3,000.
Bug Fixes
- Improved security when processing integration configuration.
- Hardened file permissions during cluster operations.
- Tightened permissions on certificate-management files.
- Hardened file permissions during installation and upgrade.
- Windows Event Forwarding: collection definitions are now included in configuration storage and backups — Related setup guide: Windows Event Forwarding (WEF) Collector Configuration
- Corrected field extraction for Windows events.
- Email response actions:
$GETevent-field placeholders now resolve correctly in the “To Others” recipient field. - Fixed conflicts when multiple operations update the same feed list, and made repeated feed-list updates consistent.
- Improved response-action completion handling.
- Fixed matching of numeric values in queries containing OR lists.
- Sigma rule conversion now rejects unsupported negated filters spanning multiple fields instead of producing incorrect queries.
- Corrected column-name resolution in search results.
- Aligned UEBA processing with the licensed feature configuration — Related setup guide: User Entity Behavior Analytics (UEBA) Overview
- Improved background-job coordination to prevent duplicate execution and prioritize overdue jobs.
- Fixed initial cluster setup to process all planned nodes and report failures correctly.
- Corrected cluster reseeding so every node included in the operation processes the reset request.
- Corrected cleanup and validation during cluster recovery.
- Fixed certificate generation checks when a certificate-authority directory already exists.
- Corrected installation order so the web interface certificate is created before the web server is configured.
- Removed an invalid symbolic link from the installation package.
- Fixed interface errors caused by a missing dependency.