New Features
Zero Networks feed is added to DataBee, enabling ingestion of network micro-segmentation and access control data via the Zero Networks API.
AWS Identity Center feed is added to DataBee, enabling ingestion and normalization of user inventory data from AWS IAM Identity Center.
Google Apigee feed is added to DataBee, enabling ingestion of API gateway activity, usage metrics, abnormal activity detection, and advanced API security events.
Feature Enhancements
Fortinet FortiManager feed syslog integration is updated with improved normalization of security events from on-premises Fortinet FortiManager deployments.
Qualys Policy Compliance feed API integration is updated to improve ingestion of policy compliance posture data across managed assets.
Xensam Software Asset Management feed is updated with API collection support, configurable authentication, and scheduling.
Netskope cloud security feed is updated with deployment validation improvements and consistent event and alert mapping.
Mimecast Email Security feed is updated to cache schema 2.0 and it supports the Test Connection button, allowing users to validate feed credentials before deployment.
Mimecast Awareness Training feed is updated to cache schema version 2.0 and it supports the Test Connection button, allowing users to validate feed credentials before deployment.
Mimecast Audit and Authentication feed is updated to cache schema version 2.0 and it supports the Test Connection button, allowing users to validate feed credentials before deployment.
CyberArk Privilege Cloud feed is updated with improved privileged account and session data mapping.
ReliaQuest GreyMatter feed incident finding mapping is updated with improved security incident data normalization.
Connection name validation is added to the data source configuration wizard, preventing invalid names from being submitted.
User Access Review application list displays description, App URL, and an enabled/disabled status column for each application, allowing reviewers to distinguish between applications with identical names and identify dormant access.
User Access Review campaign progress statistics returned to approver-only users are scoped to that approver's own assigned items, consistent with the review items list.
User Access Review justification text fields enforce a maximum character limit, and Audit Trail rows have a maximum height to prevent arbitrarily tall rows from disrupting the review interface.
Users can share saved searches with other users in their tenant, with shared searches appearing as read-only entries in each recipient's Saved Searches list.
Office location coordinates are included in the User and Person Core Data Product tables, enabling accurate user geolocation visualizations in the DataBee console.
ServiceNow workflow configuration provides a Table dropdown that fetches available tables directly from your ServiceNow instance, replacing the manual JSON additional-fields input.
Data feeds can be cloned from any editable state — Disabled, Deployed, Error, or In Progress — in addition to the previously supported enabled state.
RiskFlow SQL query download uses the last executed query rather than the current editor content, which may have been modified after execution.
RiskFlow responses include contextual descriptions for data schema tables, improving the relevance and accuracy of AI-generated answers about your data.
RiskFlow can explain its own capabilities when asked what questions and topics it can help with.
RiskFlow Ask-A-Question responses are delivered via streaming, reducing the wait time before the first response appears.
RiskFlow chat page performance is improved by eliminating unnecessary full component re-renders while composing messages.
Delete feed confirmation dialog displays the name of the feed being deleted.
Data feed count on the Data Feeds page excludes feeds in Deleting state, matching the feeds visible in the feed list.
Feed record ingestion and mapping counts are formatted with locale-aware number separators, making large counts easier to read.
Iceberg Data Lake wizard S3 region field label is updated from "AwsRegionEnum" to "Region".
Xensam Software Asset Management feed mapping is extended to include additional software inventory fields (total installs, used installs, first/last used, license requirements, EOL dates, category, family) and to link software records to associated hardware records.
ServiceNow Vulnerability, Cybeready, Cybsafe, and Onetrust Third Party Management feeds are updated to cache schema version 2.0, improving ingestion stability and pipeline reliability.
Training simulation event action enumeration is extended to include a Teachable Moment Sent value, enabling accurate classification of security awareness simulation events.
Cloud asset data feeds are updated to populate resource identifiers in event records, enabling cloud resource entity correlation in the Core Data Products.
Storage, database, and table resource feed mappings are updated to populate Cloud Resource Core Data Product records.
Vulnerability feeds support a custom severity rating field as an alternative to CVSS score, allowing tenants with custom vulnerability scoring models to use their own rating in compliance views.
Bug Fixes
The issue where editing a data feed authentication type showed key errors from the previously configured auth type is fixed.
The issue where the User Inventory table displayed Status ID and Severity ID values as "Unknown" when navigating from the Azure AD Data Quality Summary page is fixed.
The issue where the User Access Review Create-Campaign Applications picker displayed duplicate Microsoft Entra service principal entries is fixed.
The issue where the Data Feeds page did not render immediately visible loading placeholders while feed cards loaded is fixed.
The issue where duplicate data feed names could be created within a tenant is fixed.
The issue where device encryption status (
is_encrypted) was not populated correctly from Microsoft Intune managed device events is fixed.The issue where Azure and Microsoft feeds failed on HTTP 410 (Gone) when skip tokens expired is fixed by resuming pagination from the beginning.
The issue where NIST CVE feed authentication and mapping behavior caused excess fallback to the base event class is fixed.
The issue where ServiceNow CMDB feed
end_timewas not set correctly during initial cache initialization is fixed.The issue where resetting the Device column layout to its default configuration returned the error "Column layout does not exist for Device on OCSF" is fixed.
The issue where device entity detail pages failed to render, displaying a generic render error, is fixed.
The issue where buttons on the cluster management page and feed data quality summary page were displayed with incorrect CSS styling is fixed.
The issue where CFD AWS feed cloud resources inventory records were rejected during schema validation due to an invalid
resources[].ownerfield when contact email was absent is fixed.The issue where the KB4 account subscription feed was not pulling data for an extended period due to a configuration error is fixed.
The issue where ServiceNow CMDB business application records were incorrectly routed away from the target table is fixed.
The issue where creating a user account returned a "user already exists" error even when the user was not present in the user list is fixed.
The issue where the Sailpoint IdentityNow feed experienced elevated data ingestion latency is fixed.
The issue where asset cache key lookups produced errors in the feed ingestion pipeline is fixed.
The issue where RiskFlow generated inconsistent answers to repeated follow-up questions is fixed.
The issue where RiskFlow agent names were displayed in all-caps instead of standard capitalization is fixed.
The issue where the
captionfield was not displayed in CYBER and CDP schema field search results is fixed.The issue where refreshing the browser on a deep-linked page redirected the user to Data > Overview instead of remaining on the navigated page is fixed.
The issue where the User Access Review snapshot did not process access data for Okta identity sources with application role event codes is fixed.
The issue where certain cloud resource inventory feed records were incorrectly routed to the base event class due to field mapping failures is fixed.
The issue where external Iceberg catalog deletion failed due to a nested namespace structure is fixed.