New Features
- Scheduled Reports: enable or disable a schedule directly from its card.
- Scheduled Reports: emails now link to each report with the exported time range and to the Exported Reports page.
- Dashboards: the Goal widget can display multiple incidents per page.
- Roles: added a Health Check Logs permission for user accounts on non-MSS deployments. It does not grant access to Logsign Audit logs.
Plugin & Integration Updates
- Cisco ISE: added support for continuation segments in syslog messages. Empty segments no longer produce empty events.
- CyberArk Vault: RFC 5424 headers now accept fractional seconds. The parser no longer claims messages without a CEF body.
- Krontech Single Connect: corrected ISO session timestamps, empty parameter handling, and event classification by event type.
Security
- Reports: strengthened file path validation for exports, email attachments, and expiry cleanup. Scheduled exports also reject client-supplied file paths.
- API: restricted access to the session signing secret during installation, upgrade, rotation, and cluster transfer.
- Certificates: strengthened protection of private keys during upload and cluster transfer. Invalid certificate and key pairs leave the existing pair unchanged.
- Cluster: tightened file permissions for stored credentials and configuration plans during package configuration and cluster transfer.
- Audit Logs: added records for incident assignment and closure, cluster plan operations, and SSH connections closed before authentication.
- Reports: export requests now enforce the user's access to the selected report.
Other Improvements
- System Update: the progress display now shows each upgrade stage and its logs.
- Scheduled Reports: delivery failures now show their cause on report cards and in audit logs. Generated files remain available.
- Health Check: failures in setup tasks remain visible. They do not block unrelated tasks.
- Health Check: results remain visible between scheduled checks, so a previous failure does not disappear before the next check.
- Upgrade: standard deployments retain their existing parser count. A count set by the operator takes precedence.
- SIEM package configuration: a failed UI key or Log4j repair is reported in Health Check. Remaining configuration steps continue.
Bug Fixes
- Dashboards: clicking a stacked histogram opens Search with the time range of the selected bucket.
- Reports: Correlator reports now query the selected index type, including incidents, instead of defaulting to event logs.
- Reports: a ZIP file with multiple exports now uses the schedule name and compression.
- Reports: a malformed export expiry value no longer stops the export worker from processing other jobs.
- Rules and alarm whitelists: IPv4 entries with dotted netmasks now match correctly. Invalid entries are identified in the logs.
- Cluster: NameNode services are enabled during formation and upgrade so that HDFS can return after a reboot.
- Cluster: recovery from a saved configuration no longer overwrites a valid live plan. Applying a plan also refreshes its recovery copy.
- Elasticsearch: added automatic restart after a process failure, including an out-of-memory termination.
- NATS: fixed repeated creation of stats clients after a connection failure, which could cause excessive thread growth.
- Health Check: standard Ubuntu and virtual machine services no longer trigger incorrect warnings about unexpected services.
- Package configuration: reconfiguring logsign-siem now preserves installed program files and service units.
- Indexing: new daily indexes wait for the Logsign mapping template, preventing incorrect mappings that can break Search.