New Features
- Reports: table reports can now be exported as CSV with up to 1,000,000 rows.
- Authentication: OpenID Connect single sign-on (AD FS) is now available for LDAP-synced users.
- Incidents: the AbuseIPDB card on the incident timeline now shows whether the IP address is whitelisted.
- Data Transfer (rsync): added optional lookback and full synchronization modes.
- Cluster: improved the upgrade and node addition flow to prevent log loss.
Plugin & Integration Updates
- New integration: Google Workspace Gmail (API). Docs: Google Gmail Integration via API
- New integration: Zabbix trigger events and audit log (API). Docs: Zabbix Integration via API
- New integration: ClickHouse (API). Docs: ClickHouse Integration via API
- Windows Event Forwarding: IIS request logs, DNS Server audit events and DHCP Server operational events can now be collected. Docs: Windows Event Forwarding (WEF) Collector Configuration
- AWS GuardDuty: findings are now collected as regular events instead of one incident per finding.
- AWS Security Hub: findings with nanosecond timestamps no longer stop the poller from saving its position. Docs: AWS SecurityHub - Event Poller
- Office 365 Management: Entra ID group membership changes are now classified as group events, and personal OneDrive sharing no longer raises group membership alerts. Docs: Office 365 Management API Activation with Microsoft Azure
- Azure Microsoft Graph Audit: results are now paginated and de-duplicated, and sign-in logs can be enabled optionally. Docs: Azure Microsoft Graph Audit Logs integration via API
- Trend Micro Vision One: all result pages are now read in order, and the position is kept per log type. Docs: Trend Micro Vision One Integration via API
- HarfangLab EDR: process PE and parent process fields are now mapped. Docs: HarfangLab EDR Data Collection and Response Integration Guide
- GLPI: ticket creation now supports entity, priority and mention fields, and can be used in action rules.
- Check Point Harmony Endpoint (API): fixed request errors in the poller.
- Check Point Log Exporter and nginx: IPv6 source and destination addresses are now shown.
- DrayTek Vigor: firewall filter logs are now parsed.
- ESET PROTECT: RFC 3164 notifications are now parsed. Docs: Adding ESET PROTECT (On-Prem) via Syslog
- F5 BIG-IP DNS: RFC 5424 framed DNS query and response lines are now parsed. Docs: Adding F5 BIG-IP DNS via Syslog
- Forescout CounterACT: RFC 5424 syslog headers and CEF messages behind a syslog header are now parsed.
- FortiGate: added event mapping for UTM/SSL log IDs 62200, 62220 and 62308. Docs: Adding Fortigate Firewall via Syslog
- Cisco Meraki: MS switch events relayed through Vector are now parsed.
- Netwrix Endpoint Protector (CoSoSys): RFC 5424 timestamps with fractions and a Z suffix are now accepted. Docs: Adding Netwrix Endpoint Protector (CoSoSys) via Syslog
- SAP Security Audit Log: added sequence id support.
- Wallix PAM: authentication logs are now mapped to Identity/User events. Docs: Adding Wallix PAM via Syslog
- Whalebone DNS: a complete record that follows a truncated record is no longer lost.
- Improved log processing performance for about 40 integrations, including Snort IPS, McAfee Email Gateway, Pulse Secure, FireEye MPS, EMC EqualLogic, GlassFish, OpManager and Atlassian.
Security
- Updated the bundled Log4j libraries to 2.25.5.
- Remote Support: updated the Teleport agent to 16.5.18 (CVE-2025-49825).
- Reports: unit conversions in report exports are no longer evaluated as code.
- Updated the KamuSM time stamp client.
Other Improvements
- Cluster: services whose configuration did not change are no longer restarted when a cluster plan is applied.
- Cluster: NATS and Redis clients now follow the cluster plan and hand over cleanly during restarts and failover.
- Cluster: alarm action rules now also run for events that another cluster node processed.
- Syslog (UDP): the collector no longer loses messages while it restarts.
- Syslog (TCP): added frame size limits, an idle timeout and a truncation marker for oversized messages.
- Elasticsearch: raised the flood-stage disk watermark to 97%.
- Health Check: configuration sections that are lost are now restored automatically.
Bug Fixes
- Login: a failure in audit forwarding no longer breaks the login response.
- Settings: an edited source keeps its stored secrets when the secret fields are left blank.
- Settings: the credentials list now loads faster.
- Threat Intelligence: hash indicators now match MD5, SHA1 and SHA256 fields and ignore letter case. Docs: Logsign USO Threat Intelligence Guide
- UEBA: each entity is now stored as a single record.
- Reports: panel filters now work in report exports.
- Reports: table reports are now paged by their row count, up to 1000 rows per page.
- MSS: the Responses by Organisations window no longer appears empty.
- Windows Event Forwarding: the source user name is now filled from the Windows Subject when the event has no mapping.
- Windows Event Forwarding: fixed a private key permission issue in the installer script.
- Certificates: fixed issues in certificate renewal.