02/10/2026 - Version 6.4.121 Release Notes

New Features

  • Reports: table reports can now be exported as CSV with up to 1,000,000 rows.
  • Authentication: OpenID Connect single sign-on (AD FS) is now available for LDAP-synced users.
  • Incidents: the AbuseIPDB card on the incident timeline now shows whether the IP address is whitelisted.
  • Data Transfer (rsync): added optional lookback and full synchronization modes.
  • Cluster: improved the upgrade and node addition flow to prevent log loss.

Plugin & Integration Updates

Security

  • Updated the bundled Log4j libraries to 2.25.5.
  • Remote Support: updated the Teleport agent to 16.5.18 (CVE-2025-49825).
  • Reports: unit conversions in report exports are no longer evaluated as code.
  • Updated the KamuSM time stamp client.

Other Improvements

  • Cluster: services whose configuration did not change are no longer restarted when a cluster plan is applied.
  • Cluster: NATS and Redis clients now follow the cluster plan and hand over cleanly during restarts and failover.
  • Cluster: alarm action rules now also run for events that another cluster node processed.
  • Syslog (UDP): the collector no longer loses messages while it restarts.
  • Syslog (TCP): added frame size limits, an idle timeout and a truncation marker for oversized messages.
  • Elasticsearch: raised the flood-stage disk watermark to 97%.
  • Health Check: configuration sections that are lost are now restored automatically.

Bug Fixes

  • Login: a failure in audit forwarding no longer breaks the login response.
  • Settings: an edited source keeps its stored secrets when the secret fields are left blank.
  • Settings: the credentials list now loads faster.
  • Threat Intelligence: hash indicators now match MD5, SHA1 and SHA256 fields and ignore letter case. Docs: Logsign USO Threat Intelligence Guide
  • UEBA: each entity is now stored as a single record.
  • Reports: panel filters now work in report exports.
  • Reports: table reports are now paged by their row count, up to 1000 rows per page.
  • MSS: the Responses by Organisations window no longer appears empty.
  • Windows Event Forwarding: the source user name is now filled from the Windows Subject when the event has no mapping.
  • Windows Event Forwarding: fixed a private key permission issue in the installer script.
  • Certificates: fixed issues in certificate renewal.
Was this article helpful?
0 out of 0 found this helpful

Articles in this section

See more
Become a Certified Logsign User/Administrator
Sign-up for Logsign Academy and take the courses to learn about Logsign USO Platform in detail. Enjoy the courses, and get your badges and certificates. In these courses, you'll learn how to use Logsign in your work and add value to your career.
Visit Our Blog
Our Logsign USO Platform illustrate our expertise. So do the blog. Through our blog posts, deepen your knowledge on various SecOps topics or get updated about important news & modern approaches for cybersecurity. Get into the habit of reading valuable information provided by Logsign. Be a step ahead.