Abnormal Security: New CCF Push Connector Adds Multi-Table Email Security Event Routing

Added CCF Push connector with OAuth 2.0 authentication and dedicated tables for 9 event types — modern replacement for Azure Functions ingestion. Read More →

Cisco Umbrella ASIM Parser: Fixing Variable Scope Bug in IP Filter Logic

Moves critical IP filtering variables inside parser function to prevent incorrect filtering and potential data loss. Read More →

Palo Alto GlobalProtect: New ASIM Authentication Parser for VPN Monitoring

New ASIM parser normalizes GlobalProtect VPN authentication events from CommonSecurityLog table, enabling unified monitoring of gateway and portal authentication across Palo Alto PAN-OS deployments. Read More →

Trend Micro Vision One Connector: South Africa Region Support Added

Added South Africa (za) regional API endpoint support, expanding global deployment coverage for Trend Micro Vision One data ingestion. Read More →

Island Enterprise Browser V2 Connector: Documentation Clarity Improvements

Updated Island connector titles and descriptions to reduce confusion between legacy V1 and current V2 connectors. Read More →

Visa Threat Intelligence Solution: Package Artifacts Regenerated After Template Validation Failure

Template validation failure fixed through package regeneration for Visa Threat Intelligence solution v3.0.2. Read More →

Data Connector 64 KB Field Truncation: Silent Data Loss Risk Documented

Microsoft Sentinel now documents a critical platform limitation where individual fields exceeding 64 KB are silently truncated during ingestion, creating blind spots in large payload analysis. Read More →

ASIM Parser Validation: Critical Schemas Added to CI Pipeline

Four ASIM schemas missing from KQL validation pipeline now included, preventing unvalidated parser deployments. Read More →

Atlassian Confluence Audit: Critical DCR Fix Restores Data Ingestion After Stream Declaration Error

CCF connector repair resolves stream naming mismatch that prevented audit data ingestion in affected deployments. Read More →

SOC Prime CCF: Three New Detection Rules for Platform Security Events

SOC Prime solution adds Analytic Rules detecting platform administration events including tenant deletion and successful logins from malicious IPs. Read More →

Citrix Analytics: New CCF Push Connector Enables Security Analytics Visibility

New Citrix Analytics CCF solution provides push-based ingestion for SPA and CVAD security events via Azure Monitor Logs Ingestion API. Read More →

SAP Agentless Connector: Reduced Permission Model for Enhanced Security

SAP Reader role permissions significantly reduced for agentless connector, implementing least-privilege access while maintaining monitoring capabilities. Read More →

TheHive Connector: ARM Template Validation Fix

Removed redundant configuration field from TheHive CCF connector to resolve ARM-TTK validation warnings and ensure clean deployment. Read More →

Azure Resource Graph: Table Name Standardization for Query Consistency

Azure Resource Graph connector updated table labels to align with Table Management naming conventions, ensuring consistent query references. Read More →

SAP Solutions: Production-Ready Status After Preview Removal

Two SAP solutions transitioned from preview to production-ready status, unlocking stable SAP audit and infrastructure log ingestion. Read More →

ASIM Authentication Schema: VMware vCenter Parser Enables Authentication Monitoring for On-Premises and Azure VMware Environments

New ASIM parser normalizes VMware vCenter authentication events from syslog streams to enable detection coverage across vSphere environments. Read More →

Cyren-SentinelOne Connector: Restoring Threat Intelligence Deployment After ARM Template Failure

Critical deployment fix for Cyren-SentinelOne connector that was failing ARM template validation in Content Hub, preventing threat intelligence data ingestion. Read More →

D3 Smart SOAR: New Content Hub Solution Template Deployment Model

D3 Security migrates from Managed Application to Solution Template plan type, requiring new offer ID and deployment procedures. Read More →

ASIM Schema: Enhanced EntitySource Coverage for Data Platform Assets

ASimTester validation schema adds Snowflake, Databricks, and Salesforce to AssetEntity EntitySource enumeration for broader data platform asset tracking. Read More →

Cisco IOS: New ASIM Authentication Parser for Network Device Login Monitoring

ASIM authentication parser for Cisco IOS enables normalized monitoring of login, logout, and failed authentication events from network infrastructure devices. Read More →