Falcon LogScale 1.258.1 LTS (2026-10-07)

Version?Type?Release Date?Availability?End of SupportSecurity UpdatesUpgrades From?Downgrades To?Config. Changes?
1.258.1LTS2026-10-07

Cloud

On-Prem

2027-10-31Yes1.177.01.177.0No

Hide file download links

Show file download links

Hide file hashes

Show file hashes

These notes include entries from the following previous releases: 1.258.0, 1.257.0, 1.256.0, 1.255.0, 1.254.0, 1.253.0

Bug fixes and updates.

Breaking Changes

The following items create a breaking change in the behavior, response or operation of this release.

  • Functions

    • LogScale LTS version 1.258 will include a breaking change to subquery semantics for the worldMap() and sankey() functions. Result fields will no longer be automatically detected, and results must be assigned to a specific field - magnitude for worldMap() and weight for sankey() respectively.

      This change avoids unpredictable behavior in sub-queries, and allows further development on related systems. The following is an example of a query that is impacted by this change:

      logscale
      worldMap(lat=lat,lon=lon,magnitude={ w_squared := w*w | sum(w_squared) | magnitude := math:sqrt(_sum) })

      Currently, the query will be interpreted as:

      logscale
      worldMap(lat=lat,lon=lon,magnitude={ w_squared := w*w | magnitude := sum(w_squared) })

      From version 1.258, the math:sqrt part of the query will no longer be discarded.

      Imported from 1.253.0

Advance Warning

The following items are due to change in a future release.

  • Documentation

    • Our documentation homepage, functionality, and content will undergo a series of improvements before the end of August 2026. As the volume of content on the site has grown significantly, we recognize that finding the right information can be challenging. These changes are designed to improve navigation, make content easier to find, and provide clearer distinctions between content areas.

      Functionality and Navigation

      • New Default Homepage — Improved navigation and organization to help you find information more quickly. The existing legacy homepage will remain available.

      • Curated Content Pages — Topic-specific pages that provide key resources tailored to different areas of the documentation. Each page includes:

        • Search scoped to that specific content area

        • Highlights of new and recently updated pages

      • Guided Workflow Pages — Step-by-step, page-by-page guides to help you learn about specific areas of LogScale.

      • Bookmark Groups — Organize bookmarks into custom groups to create your own categorized link collections.

      • Page Watching and Notifications — Monitor pages and content for changes, so you're always aware of updates to the content you use most.

      • Custom Homepage — Set a Curated Content page as your homepage, so visiting library.humio.com takes you directly to your preferred content area.

      Content Improvements

      • New CrowdStrike Query Language (CQL) Manual — A standalone manual covering:

        • Query structure and execution context

        • Internal data representation

        • Datatypes used in queries and functions

        • Function types, input and output values, and related functions

        • Common query patterns organized by use case and challenge

        • Guides for translating SQL to CQL

      • New Getting Data Out Manual — Covers the different ways to extract information from LogScale, including APIs, the search interface, dashboards, and automation.

      • New Getting Data In Manual — Covers the methods, tools, and integrations available for ingesting data into LogScale.

      • New Administration Manuals — Separate, dedicated manuals for Self-Hosted and Cloud customers.

      We will provide updates as each improvement becomes available — we welcome your feedback as the changes roll out.

      Imported from 1.253.0

  • GraphQL API

  • API

    • Starting in version 1.258, the queryjobs endpoint will always use pagination, even when no pagination arguments have been given. When no arguments are provided, the endpoint will return the maximum page size and an offset of 0. Unless the dynamic configuration parameter QueryResultRowCountLimit has been raised from its default value, this will initially be the entire result.

      All clients should begin transitioning to use the paginated polling method ahead of version 1.258.

      Imported from 1.253.0

Removed

Items that have been removed as of this release.

GraphQL API

  • The GraphQL field remoteServerCompatVersion has been removed from the datatype RemoteClusterConnectionStatus in the GraphQL API. This field has been deprecated for some time, and marked for deletion after version 1.207.0.

    Imported from 1.254.0

Configuration

  • The feature flag NewTableCoordinator has been removed. The feature is now enabled by default, and the ability to disable it has now been removed.

    Imported from 1.258.0

Metrics and Monitoring

  • The metrics segment-fetch-requested-but-already-in-progress and segment-fetch-requested-but-upstream-has-been-deleted for the database humio-metrics have been removed due to disuse.

    Imported from 1.258.0

Deprecation

Items that have been deprecated and may be removed in a future release.

  • The GraphQL field meta has been deprecated and now requires authentication. It will be completely removed in LogScale 1.304. To achieve similar results, use the loginInfo and clusterConfig fields instead.

    To temporarily opt out of the authentication requirement, the feature flag UnauthenticatedMeta can be enabled.

    Imported from 1.253.0

  • The GraphQL mutation deleteFeatureFlag has been deprecated and a new mutation, resetFeature, has been introduced with similar behavior and a clearer name.

    Imported from 1.254.0

  • The userId parameter for the updateDashboardToken GraphQL mutation has been deprecated and will be removed in version 1.273.

    Imported from 1.253.0

Behavior Changes

Scripts or environment which make use of these tools should be checked and updated for the new configuration:

  • Administration and Management

    • For organizations that have been deleted, LogScale now internally "soft-deletes" the organization briefly to allow for recovery without data loss. Once an organization is soft-deleted, only the GraphQL mutations dealing with recovery and rollback (recoverOrganization and rollbackOrganization) are permitted on that organization. All other mutations will fail.

      Imported from 1.258.0

  • GraphQL API

    • After an organization is soft deleted using the removeOrganization mutation, you can now only call the following mutations on that organization:

      Previously, you could call any mutation on a soft-deleted organization.

      Imported from 1.253.0

  • Fleet Management

    • Fleet Management groups no longer query collectors running versions below 1.5.0. Collectors below version 1.5.0 that are part of a group will subsequently be removed from that group.

      Imported from 1.257.0

  • Auditing and Monitoring

    • Deleting the humio-audit repository is now prohibited.

      Imported from 1.258.0

Upgrades

Changes that may occur or be required during an upgrade.

  • Security

    • Apache Log4j has been updated to version 2.25.5 to address a medium severity Common Vulnerabilities and Exposures (CVE) item.

      Imported from 1.253.0

    • LogScale has upgraded the following packages to address open CVEs:

      • io.projectreactor.netty:reactor-netty-http from version 1.3.6 to version 1.3.7

      • org.apache.qpid:proton-j from version 0.34.1 to version 0.35.0

      • io.projectreactor:reactor-core from version 3.8.6 to version 3.8.7

      Imported from 1.257.0

    • Bouncy Castle Java dependencies have been upgraded to version 1.85.

      Imported from 1.253.0

    • LogScale has upgraded the Netty package to version 4.2.17.Final to address open CVEs. See Netty project for more information.

      Imported from 1.256.0

  • Installation and Deployment

    • LogScale's bundled Java Development Kit (JDK) has been upgraded to version 25.0.4.1.

      Imported from 1.258.0

New features and improvements

  • Security

  • User Interface

    • A sync icon button is now available in the Table tab header on the Search page. When running a live query that uses defineTable() or remoteTable(), table data updates in the background. When new data is available, select the sync button to reload the tab without switching tabs.

      Imported from 1.255.0

  • Documentation

    • Our documentation homepage, functionality, and content will undergo a series of improvements before the end of August 2026. As the volume of content on the site has grown significantly, we recognize that finding the right information can be challenging. These changes are designed to improve navigation, make content easier to find, and provide clearer distinctions between content areas.

      Functionality and Navigation

      • New Default Homepage — Improved navigation and organization to help you find information more quickly. The existing legacy homepage will remain available.

      • Curated Content Pages — Topic-specific pages that provide key resources tailored to different areas of the documentation. Each page includes:

        • Search scoped to that specific content area

        • Highlights of new and recently updated pages

      • Guided Workflow Pages — Step-by-step, page-by-page guides to help you learn about specific areas of LogScale.

      • Bookmark Groups — Organize bookmarks into custom groups to create your own categorized link collections.

      • Page Watching and Notifications — Monitor pages and content for changes, so you're always aware of updates to the content you use most.

      • Custom Homepage — Set a Curated Content page as your homepage, so visiting library.humio.com takes you directly to your preferred content area.

      Content Improvements

      • New CrowdStrike Query Language (CQL) Manual — A standalone manual covering:

        • Query structure and execution context

        • Internal data representation

        • Datatypes used in queries and functions

        • Function types, input and output values, and related functions

        • Common query patterns organized by use case and challenge

        • Guides for translating SQL to CQL

      • New Getting Data Out Manual — Covers the different ways to extract information from LogScale, including APIs, the search interface, dashboards, and automation.

        See CrowdStrike Query Language (CQL)

      • New Getting Data In Manual — Covers the methods, tools, and integrations available for ingesting data into LogScale.

        See Getting Data In

      • New Administration Manuals — Separate, dedicated manuals for Self-Hosted and Cloud customers.

        See Getting Data Out

      Imported from 1.255.0

      For more information, see How to Read the Documentation.

  • Automation and Triggers

  • GraphQL API

    • The following dynamic configuration parameters have been added to the GraphQL enum DynamicConfig:

      • RawSegmentSearchEnabled - the default value is false.

      • RawSegmentSearchMaxSegments - the default value is 10,000,000.

      Imported from 1.258.0

  • Dashboards and Widgets

    • Dashboards now have an Update from template action in the â‹® menu. It opens a dialog where a YAML template can be dragged and dropped (or browsed for) to replace the dashboard's content in place.

      The dashboard retains its existing ID and URL, so any links, bookmarks, or references to it continue to work. The action is available for any dashboard with edit permission, regardless of whether it was installed from a package.

      Imported from 1.254.0

      For more information, see Manage individual dashboards.

    • Shared dashboard links now support specifying a time zone, allowing recipients to view data in the intended time zone rather than their own local time.

      Imported from 1.253.0

      For more information, see Time Zone Options for Shared Dashboards.

  • Log Collector

    • A system-managed sensor deployment token has been added to enroll Log Collector by sensor. This is similar to the existing default collector install token.

      The following changes have also been made to installation token management:

      • The ability to regenerate installation tokens has been added.

      • Newly created system tokens now have a 30-day expiry. Existing system tokens without an expiry remain unchanged.

      Imported from 1.255.0

  • Queries

    • For Self-Hosted users only. The feature flag AllowQuerySchedulerToBailOnSlowChunks has been removed. The functionality previously controlled by this flag is now enabled by default.

      Imported from 1.255.0

  • Fleet Management

    • Log Collector configurations can now be built using the new Configuration Wizard, which walks users through sources, destinations, and their parameters. Manual configuration editing is still supported- the Wizard appears alongside the YAML editor, and stays in sync as the user completes work.

      Imported from 1.258.0

    • Falcon LogScale Collector Fleet Management now supports exporting the Fleet Overview as a .CSV file. The export includes all visible columns for collectors matching the active filters. To export, users should locate the Export button in the Overview table toolbar.

      Imported from 1.258.0

    • Fleet Management groups can now be exported as a CSV file. The export option is available in the â‹® menu for each group.

      Imported from 1.257.0

Fixed in this release

  • User Interface

    • Fixed an issue where the LogScale UI was using the incorrect name for lookup file actions in the Filter menu located in the Actions view under Automation, causing an incorrect number of results.

      Imported from 1.254.0

    • Rows in the Table widget could not be selected while a query was in a stopped state. This issue has been fixed and row selection now works for stopped queries, matching the existing behavior for completed and live queries.

      Imported from 1.257.0

    • Two issues regarding the Fields panel have been fixed:

      • The cardinality value now matches the top values when in a view after selecting the Sample more button.

      • The total number of events after selecting the Sample more button is now reported correctly. The Showing fields from latest N events label displays the correct count and the percentages column is enabled when possible.

      Imported from 1.257.0

    • Fixed an issue with the GraphQL API Explorer where a user's session would not be refreshed by the UI due to credential timeout.

      Imported from 1.257.0

  • Automation and Triggers

    • Two issues related to saved searches have been resolved:

      • Saved searches grouped by Last Modified are now bucketed according to the user's configured time zone instead of Coordinated Universal Time (UTC). Previously, searches had the potential to appear under the the wrong day for users outside UTC.

      • The Saved searches list now updates immediately following the creation of a new saved search. Previously, the new search did not populate until the user navigated away from and then returned to the Saved searches tab.

      Imported from 1.257.0

  • Storage

    • An issue has been fixed where the environment variable GCP_STORAGE_ENDPOINT_BASE was not being used for requests to Google Cloud Storage (GCS).

      Note

      With this release, configured clusters will begin using this value for all GCS storage requests.

      Imported from 1.253.0

    • Fixed an issue where cancelled queries requiring segment downloads from bucket storage could lead to concurrent segment downloads above configured limits.

      Imported from 1.254.0

    • Fixed an issue where query segment fetches could potentially starve segment fetches required for bucket storage upload during rolling cluster upgrades due to deprioritization.

      Imported from 1.254.0

    • Fixed an issue where segment and auxiliary file downloads could leak files in a temporary directory.

      Imported from 1.253.0

  • Ingestion

    • Fixed an issue where parsers with a zero-length/empty test case could be saved successfully, resulting in a non-specific error when queried using LogScale's GraphQL API via the LogScale GUI (v1.219.1).

      In the event this occurs, the user will be notified with the error Test case #X has no text or consists only of white spaces, with X defining which test case contains the error.

      Imported from 1.253.0

  • Queries

    • Fixed an issue with queries using defineTable(), where the percentage value of the GraphQL parameter workDone could decrease if a subquery was restarted while the main query was still running.

      Imported from 1.254.0

    • Fixed an issue where queries containing the functions defineTable() or remotetable() would receive an initial estimated cost of 0. The main query will now have a cost of 2 KB per subquery defined.

      Imported from 1.254.0

    • An issue has been fixed where long-running live queries using the function remoteTable() would sometimes be unprepared to complete the handover process after more than 24 hours of run-time.

      Imported from 1.258.0

    • An issue has been fixed regarding query migration for queries that referenced the same table twice while matching on different columns, such as the following example:

      logscale
      match(file=foo, column=a, ...) | match(file=foo, column=b, ...)

      Previously this issue caused migration to fail and restart, losing progress. Migrated queries now continue with the progress already made.

      Imported from 1.258.0

    • An issue has been fixed where queries containing the function defineTable() would not finish if it was started in a multi-cluster search view that had only a local connection and no remote connections.

      Imported from 1.258.0

    • An issue has been fixed where queries using the functions defineTable() or remoteTable() would sometimes continue running even when a subquery encountered a fatal error. Now, primary queries are prevented from presenting results if one or more dependencies have stopped updating.

      Imported from 1.258.0

    • Persisted aggregations with a backfill window longer than the source or destination repository's retention period will now skip intervals where data is unavailable or where it will expire imminently.

      The effective backfill start is now computed as max(configuredStart, now - mostRestrictiveRetention), so persisted aggregations no longer waste execution cycles querying for data that no longer exists.

      Imported from 1.255.0

    • An issue has been fixed where multi-cluster search queries using the correlate() function could fail to complete if changes occurred while the query was running, such as an update to a view's connections. These queries are now stopped with a warning and are allowed to rerun.

      Imported from 1.256.0

    • Fixed an issue where queries with large state could cause a receiving node to crash during query handover.

      Imported from 1.255.0

    • Fixed an issue in the query scheduler that could cause starvation of organization or user queries for extended periods.

      Imported from 1.257.0

    • Fixed an issue where the query scheduler may prioritize an organization or user unfairly.

      Imported from 1.257.0

    • Fixed a number of issues in the query scheduler which would cause unfair prioritization. These issues could lead to queries being deprioritized or taking significantly longer than expected to complete.

      Imported from 1.257.0

  • Fleet Management

    • An issue has been fixed with YAML validation in the Fleet Management configuration editor that prevented configurations from having more than one type of transform per source.

      Imported from 1.258.0

  • Metrics and Monitoring

    • Fixed an issue where the metric temp-disk-usage-bytes would sometimes spuriously report a 0 value.

      Imported from 1.254.0

    • The metric time-parsing for the repository humio-metrics has been reverted to the behavior where it measures per-batch parsing time.

      Imported from 1.256.0

  • Functions

    • Fixed an issue with the function selfJoinFilter() where an incorrect field order was reported when determining columns for widgets such as the Table widget.

      Imported from 1.255.0

    • An issue has been fixed that caused the function correlate() to miss matches in instances where a non-final query contained two link operator instances linking to the same target, such as in the following example:

      logscale
      correlate(
        A: { ... | x <=> B.z | y <=> B.z },
        B: { ...}
      )

      Imported from 1.258.0

    • Fixed an issue where the groupby() function would return inconsistent results when the number of distinct groups reached the configured limit.

      Imported from 1.255.0

  • Packages

    • Fixed an issue where package exports containing saved queries and/or dashboards using a fixed start time and a relative end time such as now would incorrectly fix the end time to the moment of export, breaking the export/install.

      Imported from 1.254.0

Known Issues

  • Storage

    • For clusters using secondary storage where the primary storage on some nodes in the cluster may be getting filled (that is, the storage usage on the primary disk is halfway between PRIMARY_STORAGE_PERCENTAGE and PRIMARY_STORAGE_MAX_FILL_PERCENTAGE), those nodes may fail to transfer segments from other nodes. The failure will be indicated by the error java.nio.file.AtomicMoveNotSupportedException with message "Invalid cross-device link".

      This does not corrupt data or cause data loss, but will prevent the cluster from being fully healthy, and could also prevent data from reaching adequate replication.

      Imported from 1.253.0

Improvement

  • Administration and Management

    • The Customer ID (CID) responsible for loading or fetching a table or lookup file is now logged when the information is available.

      Imported from 1.258.0

  • User Interface

    • The selected event panel in the Parser Editor is now resizable, allowing users to adjust its height by clicking and dragging.

      Imported from 1.253.0

    • The Query Editor now highlights specific characters in a malformed regular expression instead of the entire expression. Running an erroneous query no longer garbles the error message in the Results tab.

      Imported from 1.257.0

  • Automation and Triggers

    • The scheduled search logs for the repository humio-activity labeled Scheduled search successfully triggered at least one action and Scheduled search found no results and will not trigger now include the field nextExecutionTime, which contains the next scheduled run time.

      Imported from 1.258.0

  • Storage

    • Amazon S3 bucket storage now honors the Retry-After header from S3 responses, and will now wait the server-requested duration before retrying. Furthermore, the internal retry policy has changed from linear retry to exponential retry, with jitter to address cases that involve server overload.

      This behavior is controlled by the environment variable BUCKET_STORAGE_HONOR_RETRY_AFTER_HEADER, whose default value is set to true. To disable honoring the Retry-After header, set the environment variable to false. Exponential backoff with jitter remains active regardless of this setting.

      Imported from 1.258.0

    • The timeout for uploading CSV/JSON files to bucket storage has been removed, and upload operations are now queued and run concurrently instead of each operation runnning sequentially.

      Imported from 1.257.0

    • The node-to-node fetcher has been improved in several ways:

      • Prioritization for node-to-node fetching has been reduced in cases where the segment is already well-replicated and the fetch is intended for rebalancing, not data safety.

      • The code related to node-to-node segment fetching in the correct priority order has been improved. Previously, it was impossible for high-priority fetches to skip ahead of low-priority fetches when many fetches of both types were pending.

      Imported from 1.258.0

    • Persisted aggregations with a backfill window longer than the source or destination retention period will now correctly skip intervals where data is unavailable, including when the source is a view connected to multiple repositories. In that case, the longest retention across all connected repositories is used.

      Imported from 1.256.0

  • GraphQL API

    • The GraphQL datatype ScheduledReport now exposes the field createdInfo, which contains structured creation metadata. Data points include author and timestamp, which is consistent with other asset types such as filter alerts, dashboards, and parsers.

      The existing fields createdBy and creationDate are now deprecated and will be removed in version 1.306. Migration to the createdInfo field is recommended, as it provides richer author information (user, token, and/or system) alongside the creation timestamp.

      Existing scheduled reports are automatically migrated, no action is required.

      Imported from 1.253.0

  • Configuration

    • The maximum number of scheduled reports per view is now configurable. Previously, the limit was hard-coded to 20 scheduled reports per view. It can now be adjusted using two dynamic configurations, set with the GraphQL mutation setDynamicConfig. This process (requires root-level access; LogScale Cloud customers should contact Support to have the limit changed):

      The default limit is unchanged at 20, so there is no change in behavior unless one of these configurations is set.

      The format of MaxScheduledReportsPerViewPerOrgOverride is semicolon-separated CID:LIMIT entries. For example: CID_X:50;CID_Y:60. Spaces and trailing semicolons must not be included - if the value cannot be parsed, the entire override is ignored (a warning is logged) and MaxScheduledReportsPerView applies to all organizations.

      Lowering the limit below the number of reports a view already has does not delete or disable those reports. Existing reports can still be edited, but no new ones can be created until the count is below the limit.

      Either configuration can be reverted to the default with the mutation unsetDynamicConfig.

      Imported from 1.254.0

    • A minimum limit of 4 GB has been added for the default value of the dynamic configuration parameter MaxTableForQuerySizeBytes.

      Imported from 1.253.0

    • When a configuration file contains invalid YAML, the Publish button on the configuration editor page is now disabled to prevent publishing invalid configurations.

      Imported from 1.253.0

  • Ingestion

    • The User and Entity Behavior Analytics (UEBA) file difference update functionality now stops polling after 30 consecutive fetches. This protects against excessive memory use when the Sync API is not performing baseline updates for Lookup Files.

      Imported from 1.258.0

  • Log Collector

    • LogScale now displays all available versions of Log Collector from the download server, instead of the three newest major versions and their latest patches.

      Imported from 1.255.0

  • Queries

    • The full set of nested dependencies for a query is now sent as part of the query result, and is located in the filesUsed field. This enables nested dependences to appear as table tabs in the UI.

      Imported from 1.253.0

    • An optimization has been added to the Regular Expression Engine V2 where alternations of single character predicates are compiled as character classes. For example, alternations like a|b are compiled to the equivalent character class [ab].

      This improvement provides up to 20% better performance and helps prevent stack overflows during execution.

      Imported from 1.256.0

    • Introduced a limit for the format() function that checks the total length of the result at submission/compilation. If the calculated length is above the limit, the query will fail. At this time, the limit is 10 MB.

      For example, if you write a query using format() like the following example, it will fail, because the calculated length is above the limit:

      (format="%.1048575s %<1048575s")

      However, if you write the query like the following example instead, the query will not fail, because we do not statically know whether the length is above the limit:

      format(format="%.s %<s")

      Imported from 1.254.0

    • Improved query caching and reuse by introducing a canonical sort order to the internal representation of filter queries. For example, the queries A AND B AND C and B AND A AND C can now share cached results.

      Imported from 1.257.0

    • Cost estimates that are used by the query scheduler have been improved, and are now biased toward recent work in order to improve scheduling fairness.

      Imported from 1.258.0

  • Fleet Management

    • The Fleet Groups page now displays a warning when collectors in a group have conflicting target versions due to multiple group membership with different version targets. The warning indicates which groups have conflicting versions.

      Imported from 1.255.0

  • Metrics and Monitoring

    • Log events for usage are now routed to the humio repository via the logger with the tag #kind=usage instead of the previous #kind=logs.

      Imported from 1.255.0

      For more information, see The humio-usage Repository.

  • Other

    • Just-In-Time (JIT) logs from the Java Virtual Machine (JVM) have been disabled by default due to disuse and cost. LogScale will now run without them.

      To continue including them, users can add the following JVM option using the environment variable JVM_LOG_DIR if defining a custom log path:

      java
      Xlog:jit*=debug:file=$JVM_LOG_DIR/jit_humio.log:time,tags:filecount=5,filesize=1024000

      If not defining a custom log path, use the default path logs.

      Imported from 1.253.0

    • To assist with diagnostics, non-sensitive logging has been added to the Linux file /proc/vmstat. For example:

      logscale
      #kind=nonsensitive | name="vmstat"
      | timeChart(#vhost, function=[counterAsRate("numa_miss", as="miss"), counterAsRate("numa_hit", as="hit")], minSpan=2m, limit=100)

      Imported from 1.255.0

Recent Package Updates

The following LogScale packages have been updated within the last month.

  • Package Changes

    • zscaler/private-access has been updated to v1.5.2.

      • Refactored user field handling into a unified post-processing block applied across all log types

      • User identity fields (user.email, user.name, user.domain) are now resolved from a consolidated coalesce of Vendor.User, Vendor.NameID, Vendor.Username, and Vendor.suser

      • When the resolved username contains @, user.email is set and user.name and user.domain are extracted via regex

      • user.id is now assigned using coalesce([Vendor.ModifiedBy, user.email]) for all log types

      • Removed per-dataset inline user field assignments from audit, browser-access, user-activity, and user-status log type handlers

      • Updated ECS version to 9.4.0

      • Updated CPS version to 1.2.0

      Imported from 1.253.0

      For more information, see Package zscaler/private-access Release Notes.

    • everpure/flashblade has been updated to v1.2.2.

      • Added threat detection rules for critical FlashBlade administrative operations (pass-through detections to NG-SIEM):

        • PURE-FB-SYSLOG-CHANGE: Detects syslog target additions, modifications, or deletions (purelog setattr/create/delete)

        • PURE-FB-NTP-CHANGE: Detects NTP server configuration changes (purearray setattr --ntpserver)

        • PURE-FB-FS-DESTROY: Detects file system destruction (purefs destroy)

        • PURE-FB-EXPORT-DELETE: Detects SMB/NFS export deletions (purefs export delete)

        • PURE-FB-FS-PROTOCOL-REMOVE: Detects protocol/export removal from file systems (purefs remove)

        • PURE-FB-S3-BUCKET-DESTROY: Detects S3 bucket destruction (purebucket destroy)

        • PURE-FB-DNS-CHANGE: Detects DNS nameserver configuration changes (puredns setattr --nameservers)

      • Updated event.action to use coalesce([Vendor.Action, Vendor.Subcommand]) instead of lower(Vendor.Action)

      • Added event.provider field mapped from Vendor.UI

      • Updated process.command_line to include full command string formatted as Command Subcommand Arguments

      • Removed process.args[] array field (previously split from Vendor.Arguments)

      • Simplified host.hostname assignment to use inline lower() within coalesce()

      • Added network.protocol field for export/protocol-related detections

      • Added rule.id, rule.name, rule.category, and rule.description fields for threat detections

      • Updated ECS version to 9.4.0

      Imported from 1.254.0

      For more information, see Package everpure/flashblade Release Notes.

    • cisco/firepower has been updated to v2.0.1.

      • Enhanced regex patterns for event codes 302020 and 302021 to support optional user domain and username extraction from ICMP connection messages

      • Added support for parsing user domain (destination.user.domain, source.user.domain) and username (destination.user.name, source.user.name) fields in ICMP built/teardown connection messages

      • Added new test cases for ICMP connection events with user information (302020 outbound/inbound and 302021 teardown with domain\user format)

      Imported from 1.253.0

      For more information, see Package cisco/firepower Release Notes.

    • cisco/ios has been updated to v1.11.0.

      • Added support for AireOS/WLC (Wireless LAN Controller) style log headers with new regex pattern

      • Added parsing for DISC_INTF_ERR2 events for AP discovery request failures on wrong VLANs

      • Added parsing for DISC_AP_MGR_ERR1 events for AP manager discovery failures

      • Added parsing for MOBILESTATION_NOT_FOUND events for mobile station database lookup failures

      • Added parsing for Q_IND events for association request failures with client limit reached

      • Enhanced MAC address normalization to convert colon-separated format to dash-separated uppercase format

      • Reverted recent timezone handling change to ensure event timezone is prioritized over data connector timezone selection

      • Updated ECS version to 9.4.0

      • Updated CPS version to 1.2.0

      Imported from 1.253.0

      For more information, see Package cisco/ios Release Notes.

    • microsoft/windows-dns-debug has been updated to v1.5.2.

      • Refactored timestamp parsing logic into a unified post-case __timestamp match block supporting five distinct timestamp formats

      • Added support for new timestamp format: d-M-yyyy H:mm:ss (e.g., 04-08-2026 19:55:33)

      • Simplified regex patterns in case statement to use generic .*? timestamp capture group for broader format compatibility

      • Removed inline parseTimestamp and drop calls from individual case branches

      • Updated ECS version to 9.4.0 and CPS version to 1.2.0

      Imported from 1.255.0

      For more information, see Package microsoft/windows-dns-debug Release Notes.

    • everpure/flasharray has been updated to v1.1.0.

      • Added threat detection logic (pass-through detections) for high-risk FlashArray operations including volume eradication, volume destruction, file system destruction, protection group snapshot destruction, syslog target modification, eradication delay modification, NTP configuration modification, and DNS configuration modification

      • Removed event.id field mapping from Vendor.MessageID

      • Updated ECS version to 9.4.0

      • Updated parser version to 2.1.0

      Imported from 1.254.0

      For more information, see Package everpure/flasharray Release Notes.

    • infoblox/nios has been updated to v1.5.0.

      • Extended audit log parsing to support additional service names: python, sshd, and -serial_console in addition to httpd

      • Added client.address mapping from Vendor.audit.ip for login events

      • Enhanced created, modified and called events with object type/name extraction via regex and kvParse

      • Extended RestartService match to include ClearRestartFlags and NodeAdminOperation

      • Extended TransferTrafficCapture match to include CSV

      • Added process.id extraction from syslog priority format messages

      • Added BOOTREQUEST outcome handling: failure when message contains no dynamic leases, success otherwise

      • Added bind update event parsing with client.address, Vendor.action_blocked, and Vendor.reject_reason fields

      • Added r-l-e (Renewed/Issued/Freed) lease event parsing with client.ip, client.mac, host.name, DHCP state, time, vendor class, option tag, and network fields

      • Extended DNS service name match to include idns_healthd in addition to named

      • Added ICMP monitor event parsing for DNS dataset with client.domain, client.address, and ICMP status fields

      • Added cloud_dns_task_executor_overlay_ctl service handling mapped to nios.dns dataset

      Imported from 1.254.0

      For more information, see Package infoblox/nios Release Notes.

    • zscaler/internet-access has been updated to v2.1.4.

      • Consolidated user field handling into a unified post-processing block after all sourcetype-specific logic, replacing per-sourcetype user field extraction

      • Added user.id field assignment set equal to user.email when a valid email is detected

      • Removed per-sourcetype user field case blocks from zscalernss-dns, zscalernss-fw, zscalernss-web, zscalernss-tunnel, and zscalernss-casb sections

      • User resolution now uses coalesce([Vendor.elogin, Vendor.login, Vendor.user, Vendor.adminid]) across all sourcetypes

      • Updated ECS version to 9.4.0

      • Updated parser version to 4.0.4

      Imported from 1.253.0

      For more information, see Package zscaler/internet-access Release Notes.

    • cisco/umbrella has been updated to v1.4.4.

      • Updated ECS version to 9.4.0

      • Updated CPS version to 1.2.0

      • Added web to event.category[] for proxylogs events

      • Added access to event.type[] for proxylogs allow and block actions

      Imported from 1.254.0

      For more information, see Package cisco/umbrella Release Notes.

    • cisco/meraki has been updated to v2.0.3.

      • Fixed content_filtering_block parsing to use flexible key-value extraction instead of a rigid positional regex, allowing optional fields such as category0 between url= and server= to be handled without breaking the match

      • Updated server.ip and server.port extraction for content_filtering_block to split from the combined Vendor.server value produced by kvParse

      • Added user.name mapping from Vendor.user for content_filtering_block events

      • Added host.name mapping from Vendor.clientName for File Scanned events

      Imported from 1.253.0

      For more information, see Package cisco/meraki Release Notes.