Falcon LogScale 1.209.0 GA (2025-10-07)

Version?Type?Release Date?Availability?End of SupportSecurity UpdatesUpgrades From?Downgrades To?Config. Changes?
1.209.0GA2025-10-07

Cloud

2026-12-31No1.150.01.177.0No

Hide file download links

Show file download links

Bug fixes and updates

Deprecation

Items that have been deprecated and may be removed in a future release.

  • The EXTRA_KAFKA_CONFIGS_FILE configuration variable has been deprecated and planned to be removed no earlier than version 1.225.0. For more information, see RN Issue.

  • rdns() has been deprecated and will be removed in version 1.249. Use reverseDns() as an alternative function.

Behavior Changes

Scripts or environment which make use of these tools should be checked and updated for the new configuration:

  • User Interface

  • GraphQL API

    • GraphQL mutations used for updating actions will now preserve existing label values when the labels argument is omitted. Users who want to remove labels from an action will need to specifically assign the labels argument to an empty list, by entering a pair of brackets with nothing between them (i.e., labels: []).

Known Issues

  • Storage

    • For clusters using secondary storage where the primary storage on some nodes in the cluster may be getting filled (that is, the storage usage on the primary disk is halfway between PRIMARY_STORAGE_PERCENTAGE and PRIMARY_STORAGE_MAX_FILL_PERCENTAGE), those nodes may fail to transfer segments from other nodes. The failure will be indicated by the error java.nio.file.AtomicMoveNotSupportedException with message "Invalid cross-device link".

      This does not corrupt data or cause data loss, but will prevent the cluster from being fully healthy, and could also prevent data from reaching adequate replication.

Improvement

  • User Interface

    • Updated the series formatting color picker for widgets and dashboards to support color selection from predefined color palettes.

  • Queries

    • Query cost/work calculation no longer includes time the query spends waiting for work.

      For more information, see Query stats.

Recent Package Updates

The following LogScale packages have been updated within the last month.

  • Package Changes

    • zscaler/internet-access has been updated to v1.5.1.

      • Enhanced user email field handling to only set user.email when a valid email format is detected

      • Improved MD5 hash field processing for file.hash.md5

      • Fixed conditional logic for user field extraction across all dataset types

      • Updated parser version to 2.5.1

      For more information, see Package zscaler/internet-access Release Notes.

    • aruba/clearpass has been updated to v1.3.0.

      • Enhanced System category event handling with improved regex patterns for cleanup operations

      • Improved data integrity by using temporary field for rawstring processing

      • Updated parser version to 2.1.0 and CPS version to 1.1.0

      For more information, see Package aruba/clearpass Release Notes.

    • okta/sso has been updated to v1.4.5.

      • Updated ECS version to 9.1.0

      • Enhanced user.name field handling to automatically populate user.email when user.name contains @ symbol

      • Improved code formatting and consistency

      For more information, see Package okta/sso Release Notes.

    • cisco/firepower has been updated to v1.7.2.

      • Updated parser version to 3.3.2

      • Enhanced regex pattern for event code 106015 to better capture flags field with multiple values

      For more information, see Package cisco/firepower Release Notes.

    • checkpoint/ngfw has been updated to v2.3.1.

      • Fixed regex pattern for numerical action values to prevent backtracking issues

      • Updated parser version to 3.3.1

      For more information, see Package checkpoint/ngfw Release Notes.

    • cisco/ise has been updated to v1.4.0.

      • Added support for CISE_TACACS_Accounting events (codes 3300, 3301, 3302)

      • Added comprehensive TACACS+ diagnostics parsing for CISE_TACACS_Diagnostics category

      • Enhanced event categorization for TACACS+ authentication, authorization, and accounting events

      • Added support for TACACS+ network access control and user management events

      • Updated parser version to 2.1.0

      For more information, see Package cisco/ise Release Notes.

    • checkpoint/ngfw has been updated to v2.3.2.

      • Enhanced IP address validation using CIDR function for source and destination fields

      • Improved handling of source.address and destination.address fields with proper IP validation

      • Updated parser version to 3.3.2

      For more information, see Package checkpoint/ngfw Release Notes.

    • fortinet/fortigate has been updated to v1.4.0.

      • Updated parser version to 3.0.0

      • Enhanced event outcome determination for traffic and UTM events with expanded action mappings

      • Improved TLS certificate field handling using array:append for proper array construction

      • Fixed vulnerability category field mapping to use array:append

      • Added new test cases for VPN, IPS, and traffic events

      • Updated field assignments to use array operations for ECS compliance

      For more information, see Package fortinet/fortigate Release Notes.