Release History

View all app release history.

1.8.2510.0 2025-10-28 17:51
Add query commands and functions - Add top and rare commands - Add filter function
1.6.2510.0 2025-10-23 16:45
Changelog * Supports CEF format for AUDIT, INTRUSION, SYSTEM logs
1.2.2503.1 2025-10-22 17:23
Changelog * Fixed issue where data was missing when the signature field was null * Removed data size limit (2048 bytes) * Added support for collecting the raw_data field * Fixed error message "version is not a supported option" when executing the webfront-block-ip command
1.7.2510.1 2025-10-20 23:50
Query Optimization Bug Fixes - Support for wildcards during table and full-text conversion - Ensuring semantic equivalence when converting null comparison using the fulltext command - Compatibility ensured up to Logpresso Sonar version 4.0.2409.0
1.0.2309.2 2025-10-14 17:16
Changelog - Fix to output error code instead of command failure if no virustotal-file-report search results are found or if hash value is invalid
1.7.2510.0 2025-10-14 17:01
Query Optimization - Automatically converts table | search commands to a fulltext command - Automatically converts log | search commands to a single log command Misc. - Renames the query_string field in sonar-stream-rules output fields to query field - Requires **Logpresso Sonar 4.0.2507.0** or higher
1.5.2510.0 2025-10-13 11:05
Changelog - Added syslog logger model - Added query command genian-nac-node-apps, genian-nac-node-apps-batch - Added ip option to query command genian-nac-remove-tag - Improved parser - parse rows with log_id 100, with pipe(|) character delimiter, Node Up/Down log types
1.1.2307.2 2025-10-09 21:44
Changelog * Time filter can be applied to dashboard * Relaxed dependency requirements for app bundle compatibility
1.6.2510.0 2025-10-09 15:28
##### Added Log Schema and Collector Management Commands * **log**: Search logs based on schema, model, or collector (supports raw search, aliasing, and subqueries) * **sonar-log-schemas**: Retrieve a list of log schemas * **sonar-log-schema-fields**: Retrieve log schema fields * **sonar-loggers**: Retrieve a list of collectors * **sonar-logger-models**: Retrieve a list of collection models ##### Added SSL Certificate Management Commands * **sonar-check-cert-batch**: Batch verification of SSL certificates ##### Added Address Group and Blocking Integration Management Commands * **sonar-address-groups**: Retrieve a list of address groups * **sonar-address-objects**: Retrieve address objects * **sonar-remove-address-batch**: Batch deletion of address objects * **sonar-response-targets**: Retrieve a list of response targets * **sonar-response-models**: Retrieve a list of response models ##### Added Detection Rule Management Commands * **sonar-stream-rules**: Enumerate real-time detection rules * **sonar-batch-rules**: Enumerate batch detection rules * **sonar-add-stream-rule-command-batch**: Batch addition of real-time rule commands * **sonar-update-stream-rule-command-batch**: Batch modification of real-time rule commands * **sonar-delete-stream-rule-command-batch**: Batch deletion of real-time rule commands * **sonar-update-batch-rule-query-batch**: Batch modification of batch rule queries ##### Added App Management Commands * **sonar-apps**: Retrieve a list of apps
1.1.2402.1 2025-09-25 14:28
Bug Fixes * Modified to parse logs even when the PRI field is missing.
1.1.2509.0 2025-09-24 23:56
Added support for Apache Kafka TLS integration
1.2.2509.0 2025-09-24 15:16
SNIPER ONE v3.3 Support - Updated parsers for Detect, VipsProtocol, VipsService, and tcpCPSTraffic events - Added 5 new log schemas for the following events - Malware Detection - System Information - System Status - System Sub Information - URL Log Bug Fixes - Modified to load dashboard data from all nodes when running in a cluster configuration - Fixed an issue where the time filter in dashboard filters was not applied
1.0.2509.0 2025-09-07 16:23
First release - Support login and query log collectors. - Support query usage and login dashboards.
1.4.2509.0 2025-09-02 00:12
Support for Basic Authentication in the Splunk HEC Collector
3.14.4 2025-08-27 01:46
Snowflake JDBC driver 3.14.4 version
1.0.2508.0 2025-08-27 01:37
First release
1.0.2508.0 2025-08-23 23:17
Firest release - Tested on v3.1.21_250823
1.5.2508.0 2025-08-17 17:54
Support 2 detection rules - ML rule app is required. - High-Risk Web Exploit Detection (T1190) - Web Scanning Detection (T1595.002)
1.1.2508.0 2025-08-16 00:02
Added chatgpt-audit-logs query command.
1.2.2405.2 2025-08-13 22:52
Changelog - Fixed an issue where, if the last character in a custom parser format string was a separator, it was incorrectly included in the parse result. - Enabled time filtering for eWalker SWG widgets. - Added support for unknown schemas in the eWalker SWG logger model.