Feature Improvements
- New commands: sonar-create-stream-rule-batch, sonar-create-batch-rule-batch, sonar-update-stream-rule-batch, sonar-update-batch-rule-batch, sonar-update-rule-mitre-batch, sonar-stream-rule-command-templates, sonar-insert-stream-rule-command-batch, sonar-update-stream-rule-command-batch, sonar-delete-stream-rule-command-batch, sonar-update-batch-rule-query-batch
- Renamed commands: sonar-clone-dashboard-batch, sonar-clone-dataset-batch, sonar-clone-widget-batch
- Support for MITRE ATT&CK fields: sonar-stream-rules, sonar-batch-rules
Note: Stop the logger before upgrading the app
Improvements
- Logger bug fixes (failure reporting, automatic reconnection, connect profile change detection)
- Query command fixes
- `gcp-pubsub-pull` added — reads a subscription without consuming messages
- `gcp-pubsub-publish` — publish failures reported, integer field input and empty message handling fixed, `msg_id` added to output
- `gcp-pubsub-messages` — connect profile errors reported
Compatibility
- Requires Logpresso Sonar 4.0.2308.0 or later
First release
- pdf-info, pdf-pages, pdf-search, pdf-images commands
Feature Improvements
- Added the `playwright-credentials` command
Feature Improvements
- `action` field normalization for Correlation Event logs
Feature Improvements
- Added the `system-open-files` command required for file leak detection
- Requires araqne-core-4.2.0-package.jar or later
Feature Improvements
- Added HTTP proxy option to the connect profile
- **Note: Stop the logger before upgrading the app**
First release
First release
- Support 21 query commands for browser control
New Features
- Replay batch detection at a past point in time using the `sonar-replay-batch-rules` command
Feature Removal
- Migrated remote file streaming interface to the File Store app
Initial Release
- Provides a logger model, parser, log schema for Privacy-i device logs.
Fix parser bug
- handle dump_id values exceeding integer limits
Bug Fixes
- Fixed a bug where the `sonar-verify-query` command failed to validate commands with multiple subqueries (e.g., the `fulltext` command)
- Improved the `log` command so that it explicitly returns an error for non-existent schemas
Initial Release
- Provides a logger model, parser, log schema, and dashboard for payShield HSM device logs.
* Renamed the APPLICATION log type to CONTENTS-FILTER to follow the AXGATE Syslog specification
* Changed the log schema code from axgate-ngfw-nf-application to axgate-ngfw-nf-contents-filter
**When upgrading from an earlier version, the contents filter rule in the logger model may keep its previous log schema. Delete the rule and reinstall the app to restore the correct schema binding**
Fixed bugs
- Fixed an issue where the dashboard time filter was not applied
- Fixed an issue where unknown logs were included in dashboard aggregation
First release
- Support for Claude Desktop, Claude Code
First release
* TippingPoint SMS ArcSight CEF Format v4.2 parser, SMS 2.5 Syslog Format parser, logger model, log schema, dashboard
Initial Release
- Provides a dedicated parser, log schemas and logger model for F5 BIG-IP Zero Trust Access logs.