New Features
An event type field is added to data lake messages, storing API or mapping event types in metadata.
Feature Enhancements
The configuration UI for the report provisioner now supports viewing and editing full-length strings (e.g., AS, IFF, CASE) in arrays.
Entity Management update logic is enhanced to improve handling of backtrace priority, ensuring updates are applied even when before and after values are the same.
The new data source onboarded alert is changed from error to warning and updated to include the tenant name in the description.
Zeek scanner performance is improved with faster log processing and reduced memory overhead.
Timestamp parsing is improved to support additional common formats, and missing or unrecognized timestamps now automatically use the current timestamp.
Bug Fixes
The issue where Modified Time was not showing for a client application CDP is fixed.
The issue where the Applications CDP was creating multiple rows for the same application ID with active set to True is fixed.
The issue where merge history was not included in the event timeline is fixed.
The issue where dismissing a Halcyon Data Feed warning was not working and returned an error is fixed.
The issue where migration status steps (including OCSF Table Creation) were missing in the Iceberg Wizard is fixed.
The issue where newly created remediation actions were not returned in search results and pagination was not working is fixed.
The issue where an error banner came up when searching for users to add to embedded dashboard access is fixed.
The issue where the OAuth selection description was displayed in an unintended location is fixed.
The issue where configuration showed multiple mapping labels with the same name is fixed.
The issue where the json chunk scanner was failing on empty JSON arrays with an invalid character error is fixed.
Deprecations
Use of Snowpipe for writing events to Snowflake is deprecated.