Tenable VM: Vulnerability Data Checkpoint Field Update

Changed vulnerability export checkpoint field from last_found to indexed_at for customer enhancement. Read More →

ExtraHop RevealX: Azure Monitor Logs Ingestion API Replaces Legacy HTTP Data Collector

Added Log Ingestion API support with OAuth 2.0 authentication — modernizes data ingestion from legacy HTTP Data Collector API. Read More →

Abnormal Security: New CCF Push Connector Adds Multi-Table Email Security Event Routing

Added CCF Push connector with OAuth 2.0 authentication and dedicated tables for 9 event types — modern replacement for Azure Functions ingestion. Read More →

Cisco Umbrella ASIM Parser: Fixing Variable Scope Bug in IP Filter Logic

Moves critical IP filtering variables inside parser function to prevent incorrect filtering and potential data loss. Read More →

Palo Alto GlobalProtect: New ASIM Authentication Parser for VPN Monitoring

New ASIM parser normalizes GlobalProtect VPN authentication events from CommonSecurityLog table, enabling unified monitoring of gateway and portal authentication across Palo Alto PAN-OS deployments. Read More →

Trend Micro Vision One Connector: South Africa Region Support Added

Added South Africa (za) regional API endpoint support, expanding global deployment coverage for Trend Micro Vision One data ingestion. Read More →

Island Enterprise Browser V2 Connector: Documentation Clarity Improvements

Updated Island connector titles and descriptions to reduce confusion between legacy V1 and current V2 connectors. Read More →

Visa Threat Intelligence Solution: Package Artifacts Regenerated After Template Validation Failure

Template validation failure fixed through package regeneration for Visa Threat Intelligence solution v3.0.2. Read More →

Data Connector 64 KB Field Truncation: Silent Data Loss Risk Documented

Microsoft Sentinel now documents a critical platform limitation where individual fields exceeding 64 KB are silently truncated during ingestion, creating blind spots in large payload analysis. Read More →

ASIM Parser Validation: Critical Schemas Added to CI Pipeline

Four ASIM schemas missing from KQL validation pipeline now included, preventing unvalidated parser deployments. Read More →

Atlassian Confluence Audit: Critical DCR Fix Restores Data Ingestion After Stream Declaration Error

CCF connector repair resolves stream naming mismatch that prevented audit data ingestion in affected deployments. Read More →

SOC Prime CCF: Three New Detection Rules for Platform Security Events

SOC Prime solution adds Analytic Rules detecting platform administration events including tenant deletion and successful logins from malicious IPs. Read More →

Citrix Analytics: New CCF Push Connector Enables Security Analytics Visibility

New Citrix Analytics CCF solution provides push-based ingestion for SPA and CVAD security events via Azure Monitor Logs Ingestion API. Read More →

SAP Agentless Connector: Reduced Permission Model for Enhanced Security

SAP Reader role permissions significantly reduced for agentless connector, implementing least-privilege access while maintaining monitoring capabilities. Read More →

TheHive Connector: ARM Template Validation Fix

Removed redundant configuration field from TheHive CCF connector to resolve ARM-TTK validation warnings and ensure clean deployment. Read More →

Azure Resource Graph: Table Name Standardization for Query Consistency

Azure Resource Graph connector updated table labels to align with Table Management naming conventions, ensuring consistent query references. Read More →

SAP Solutions: Production-Ready Status After Preview Removal

Two SAP solutions transitioned from preview to production-ready status, unlocking stable SAP audit and infrastructure log ingestion. Read More →

ASIM Authentication Schema: VMware vCenter Parser Enables Authentication Monitoring for On-Premises and Azure VMware Environments

New ASIM parser normalizes VMware vCenter authentication events from syslog streams to enable detection coverage across vSphere environments. Read More →

Cyren-SentinelOne Connector: Restoring Threat Intelligence Deployment After ARM Template Failure

Critical deployment fix for Cyren-SentinelOne connector that was failing ARM template validation in Content Hub, preventing threat intelligence data ingestion. Read More →

D3 Smart SOAR: New Content Hub Solution Template Deployment Model

D3 Security migrates from Managed Application to Solution Template plan type, requiring new offer ID and deployment procedures. Read More →