Skip to content

v2024.03.06-rc0

Pre-release
Pre-release

Choose a tag to compare

@n3tsurge n3tsurge released this 06 Mar 17:11
c1ef65b

Features

Detections

  • A new change tracking feature exists for Detections which will now show which attribute was changed, it’s new value, it’s only value, when and the user that changed it.
  • Detection filtering options can be further filtered by clicking the filter icon and searching for the desired item.

Enhancements

Integrations

  • Corrected the Raw Output setting for the Logstash integration to be a bool instead of a str.
  • Added support for only sending Raw Log data via a Logstash output.
  • Added support for adding custom tags to logs traversing a Logstash output.
  • Preserve Original Event is now controllable at the Agent Policy level and on a per Integration basis.

Fixes

Backend

  • The index for Search Proxy jobs was incorrectly initializing with 0 replicas and only one shard.
  • Corrected an issue where under certain conditions the /api/v2.0/detection/changelog/<uuid> endpoint would return 404 instead of an empty response object.

Observables

  • When adding custom observables to a case the underlying Event did not have a raw_log and would not render in the UI.
  • Fixed a rendering issue when an Event contained an empty or null raw_log property.

Global Admin

  • Corrected an issue where Global Admins could not see the Intel Lists for sub-tenants within the platform instnace.

Detections

  • Corrected an issue where under certain conditions where adding a single exlusion using the is operator would completely break the detection rule resulting in cascading errors across the entire detection set.

UI/UX

  • Fixed an issue where attempting to add tag_fields, tags or signature_fields to an Input where these fields we’re originally empty would prevent the addition of these attributes.
  • Fixed an issue where attempting to add tags to a Field Mapping Template that did not oringally have tags would result in failure.
  • Corrected an issue where certain User Role permissions were missing from the Permissions Editing wizard.
  • Corrected an issue where cloning a Detection rule would result in the original rule being edited with changes made to the clone.
  • Corrected several pages that were using a legacy multi-select component.
  • Corrected an issue where the Informational severity level was not rendering a proper color.