First release
- Support for Claude Desktop, Claude Code
First release
* TippingPoint SMS ArcSight CEF Format v4.2 parser, SMS 2.5 Syslog Format parser, logger model, log schema, dashboard
Initial Release
- Provides a dedicated parser, log schemas and logger model for F5 BIG-IP Zero Trust Access logs.
Fixed network topology view failing to display in large-scale Event IP environments
Improvements & Changes
- Added the ASM dashboard.
- Changed the standard for the severity option in the quaxar-asm-assets command (now based on risk_factor_severities).
Bug Fixes
- Fixed an issue where threat feed synchronization looped infinitely.
- Fixed an issue where normal responses were misclassified as authentication failures.
Feature Updates
• Added an option to enable/disable payload decoding upon parser execution (configurable in the Parser menu)
• Improved CPU field parsing performance
Log Specification v1.1.1 Support
* Supports the XTG log parser specification v1.1.1 format
* Added the User Event (2405) log type and the `xtg-user-event` log schema
* Added session action, floating IP, source domain, application traffic counter, and proxy session type fields to Traffic Allow (2101) and Traffic Deny (2102)
* Added floating IP fields to Blocklist (2103), Regional Block (2104), IP/MAC Control (2105), and Protocol Anomaly (2106)
* Added the `xff_ip` field carrying the original client IP from the XFF header to Website Filter (2207)
* Stores the destination domain in both the existing `domain` field and the standard `dst_domain` field to maintain backward compatibility
First release
- kipris-patent-search, kipris-patent-biblio, kipris-patent-docs commands
Akamai Guardicore Web Console UI Implementation
- 14 query commands for assets, labels, rules, revisions management
- 8 menus: Dashboard, Network Log, Explore, Saved Maps, Rules, Revisions, Assets, Labels
Parser Improvements
- Added parsing logic for MNX detection information (Playbook detection info) types.
First Release
* Provides dedicated parsers, logger model, and log schemas for logs sent by AXGATE Next-Generation Firewall (NF) over Syslog (14 types including session, IPS, application, and anti-virus)
* Provides extended commands to look up and remotely modify/apply security policies and address, service, time, and NAT objects
* Provides extended commands to manage blacklist, whitelist, and blacklist-exclude entries and to block IP/MAC addresses
* Supports block integration that blocks attacker IPs in conjunction with real-time and batch detection
Improvement of Sonar version compatibility guard for SSO feature
Improvement of sonar version compatibility guard for SSO feature
Initial Release
- Provides a dedicated parser, logger model and log schemas for FortiManager 7.0.10 logs.
- Added Microsoft Intune logger model (Devices, DeviceComplianceOrg, OperationalLogs, AuditLogs)
- Supports Entra ID `NonInteractiveUserSignInLogs`
- Fixed Azure Firewall NAT Rule routing error
ICAM 1.0.2 support
- Token issuance endpoint changed
- Event submission format changed
- `event_time` and `signature` added to the event submission query commands
Parser Improvements
- Fixed an issue where command line values were truncated if CEF extension values contained `key=value` formats (`-Xmx=..`, `PATH=${PATH}:..`).
First Release
* AlphaKey audit log parser, logger model, log schema support
* AlphaKey webhook (HTTP POST) integration method
* AlphaKey SAML 2.0 SSO authentication (Requires Logpresso Sonar version 5.0.2605.0 or higher)
Feature Improvements (**S2W Development Support**)
Added Attack Surface Management (ASM) CLI commands
- quaxar-asm-assets: Retrieve the attack surface asset list
- quaxar-asm-asset: Retrieve detailed information on a single asset
- quaxar-asm-certificates: Retrieve the certificate list
- quaxar-asm-certificate: Retrieve detailed information on a single certificate
- quaxar-asm-vulnerabilities: Retrieve the vulnerability list
- quaxar-asm-vulnerability: Retrieve detailed information on a single vulnerability
- quaxar-asm-seeds: Retrieve the monitoring seed list
- quaxar-asm-seed-add-batch: Add seeds based on input rows (Batch)
- quaxar-asm-seed-remove-batch: Remove seeds based on input rows (Batch)
API Migration & Connection Profile Option Expansion
- Added timeout configuration to connection profile
- Changed incremental sync criteria for Feed feature (now based on 'modified' value)
- Migrated IoC lookup API
※ Due to an API migration, older versions of the QUAXAR app are no longer supported. Please update to version 1.4.2607.0 or higher.
Bug Fixes
- Fixed installation failure on Sonar 4.0.2502.0 caused by a dependency version mismatch