Release History

View all app release history.

1.5.2511.0 2025-12-23 14:40
**This version might not have query working correctly when using set variable, use 1.5.2511.1 instead.** Changelog - Added support for variables in SPL query in `splunk-search` command
1.0.2512.0 2025-12-22 17:22
First release - Support alert, upload, health, rpc, audit log types - Support dedicated log parser, log schemas, logger model, datasets, dashboards, and detection rules.
1.1.2512.0 2025-12-19 18:32
Improvements - Added option to include original logs in collectors and extended commands - Fixed error message display
1.8.2512.0 2025-12-19 18:14
Added raw log inclusion option to activity log-related extended commands - Added raw option to google-workspace-admin-logs, google-workspace-drive-logs, google-workspace-login-logs, google-workspace-meet-logs, google-workspace-chat-logs commands - When enabled, raw data is included in the line field as a JSON string Added option to include raw logs in the Activity Log Collector - Added `include_event_raw` option to control whether raw logs are collected When reinstalling the app, please deactivate the Google Workspace app first before proceeding with the upgrade.
1.3.2512.0 2025-12-19 14:54
Improvements - Improved error display when API key authentication fails - Changed connect profile option to optional when executing batch commands
1.2.2512.1 2025-12-19 11:01
Improved compatibility with Sonar - Requires experimental app version 1.6.2510.0 or higher (uses log command) - Requires **Logpresso Sonar 4.0.2502.0** or higher
1.2.2512.0 2025-12-19 10:57
Support #react2shell tagging - Requires experimental app version 1.6.2510.0 or higher (uses log command) - Requires **Logpresso Sonar 4.0.2507.0** or higher
1.1.2510.1 2025-12-19 10:57
Fix false positives for #command_injection related to simple template variable references - Requires experimental app version 1.6.2510.0 or higher (uses log command) - Requires **Logpresso Sonar 4.0.2507.0** or higher
1.1.2510.0 2025-12-19 10:54
Support Beacon Traffic Detection - Requires experimental app version 1.6.2510.0 or higher (uses log command) - Added ml-beaconing-connections command - Added ml-beacon-sessions command Requires **Logpresso Sonar 4.0.2507.0** or higher
1.0.2512.0 2025-12-19 00:40
First release * apivoid-check-domain * apivoid-check-domain-batch * apivoid-check-ip * apivoid-check-ip-batch * apivoid-domain-info * apivoid-domain-info-batch * apivoid-reverse-ip
1.3.2512.1 2025-12-18 00:17
Minor modification of detection rules - Exploit Detected rule: Added exception condition for Exploit/Win.MagicLineX - CoinMiner Detected rule: Changed rule name - Phishing Detected rule: Removed unnecessary exception condition from first search command
1.9.2512.0 2025-12-17 17:31
sonar sync commands improvements - Added locale input to the sonar-sync-employees command - Fixed an NPE issue 발생 when dept_code is empty - Improved error cause reporting
1.5.2512.0 2025-12-12 18:43
Improve performance of Elastic log parser Notes - When upgrading from versions earlier than 1.4.2511.0, please review the steps below. - For proper incremental collection, follow this sequence: Disable the existing logger → Apply the app patch → Restore the index name in the logger settings → Enable the logger.
1.0.2512.0 2025-12-07 15:20
First release - Support react2shell-scan-batch query command.
1.1.2512.0 2025-12-05 10:39
Improvements - Add support for decimal values in the cpu_usage, mem_usage, disk_usage, and temperature fields for the Controller_resource and Sensor_resource log types. Bug Fixes - Fix a parsing failure that occurs when the msg field contains a comma (,) in the Admin_log, Ha_log, Controller_log, and Sensor_log log types.
1.1.2512.0 2025-12-05 02:56
New features * Added mat-threads query command and support for mat-build discard-ratio option
1.7.2504.0 2025-12-03 14:46
New feature - Google Workspace Group command and schema has been added - Google Workspace User command has new "group" option - Added support for Google Workspace playbook execution
1.6.2502.2 2025-12-03 14:45
Google Workspace drive activity collector bug patch - Missing error handling for empty list responses for Google Drive activity logs
1.6.2502.1 2025-12-03 14:45
Improvements - Added 4 detection rules * Admin Role Assigned (T1098.003) * Executable File Download (T1204.002) * New Trusted Domain Added (T1562.007) * User Unsuspended (T1078.004)
1.6.2502.0 2025-12-03 14:45
Improvements - Added originating_app_name when collecting Google Drive activity logs. - Added google-workspace-drive-apps, google-workspace-drive-app extended query commands. Grant new scope for domain-wide delegation * https://www.googleapis.com/auth/drive.apps.readonly