New Features
Azure Event Hub is added as a new ingest method in the data feed configuration flow.
A detection link based on the OSINT Inventory Info table allows users to filter detection chains based on any OSINT metafield.
Feature Enhancements
Warning messages for newly onboarded feeds will only appear after a 24-hour period without data ingestion.
Disabling the 'ask an owner' subservice in DataBee BeeKeeper now prevents all Azure communications.
DataBee BeeKeeper configuration is updated with the following changes:
The email domain allow list is exposed in Beekeeper settings for easier control of who Beekeeper can contact.
UI messaging is updated to clarify that contact times are interpreted as UTC instead of local time.
The unused conversation initiation interval minutes configuration is removed as it is deprecated.
The data collector ingest type previously labelled as Script Ingest is now renamed to Dynamic Ingest.
The descriptions of some OCSF tables and key columns are updated to provide a more detailed and informative context.
Performance improvements are made to the Device by Discovery console widget.
The widgets on the Device, User and Application pages are improved to apply filters when clicked.
The ServiceNow CMDB class filter options are sorted for easier selection.
The feed health widget is updated with improved alignment of the percentage change arrow.
A version column is added to Applications with Most Vulnerabilities widget on the Exposure dashboard.
Bug Fixes
The issue where array fields in the raw data response on the search page were not properly deserialized is fixed.
The issue where users without an existing Salesforce contact were unable to comment on support tickets is fixed.
The issue where adding a watcher to a support ticket did not provide them access, is fixed.
The issue where the data feed status remained Healthy after initiating a delete action and did not reflect Deleting status before removal, is fixed.
The issue where the data page time filter was misaligned, is fixed.
The issue where the SQS URL was missing for the HTTP Collector is fixed.
The issue where data source deployment sometimes stopped responding during processing, is fixed.
The issue where Splunk SOAR events were sometimes not correctly processed and displayed is fixed.
The issue where snowflake writer alerts were not delivered properly, is fixed.