Changelog¶
Release history and what's new in each version.
26h4 — Update¶
- Pattern detection and monitoring improvements
- Reliability and security enhancements
- Improved dashboard availability and stability
- Hardened web security headers across dashboard and editor
- Compliance reports now show generation time in your local timezone
26h3 — Update¶
- Scheduled maintenance release
- AWS Qualified Software
26h2 (Sep 2026) — Update¶
- MoM enhancements
- Maintain credentials used for remote subscription management
- Added support link to landing and fulfillment pages
- Change logout behavior
- Renamed OpenSearch Dashboards
26h2 (Aug 2026) — Update¶
- On stack update, address the "Could not locate index-pattern-field" errors on dashboard visualizations that required a manual index refresh
- Update OpenSearch to v2.19
- AWS FTR Approved
26h2 (July 2026) — Update¶
- Support for AWS Organizations — consolidate and centrally govern multiple AWS accounts
- Remote subscription management — browse, subscribe, and unsubscribe log groups in remote accounts directly from the Subscription Editor in the same region
- Athena dynamic account discovery — automatically detect accounts as logs flow in
- Accounts management UI — manage remote accounts in the editor; add, remove, and validate accounts with one-click role verification
- Entitlement status in FAQ — live Marketplace entitlement status displayed in the editor FAQ with a badge alert on error or expiration
- AI Monitor correlation flag — new "AI Monitor Correlate" checkbox on pattern rules to mark patterns eligible for cross-log correlation analysis
- Rollback preview — version rollback now loads into the editor for review before saving, with full undo support
- Dirty state indicators — Save, Undo, and Diff buttons are disabled when no unsaved changes exist
- iPad layout fix — subscription list footer buttons now display correctly on tablet viewports
- Deployment telemetry — active stack deployments are tracked and displayed as badges on the Marketplace fulfillment landing page
26h1 (June 2026) — Initial Release¶
Ingestion¶
- 14 built-in ingest pipelines: Lambda, JSON, Nginx, Apache, Syslog, Tomcat, Spring, VPC Flow, ALB, API Gateway, RDS Slow Query, EKS, CloudFront, RDS PostgreSQL
- Automated CloudWatch subscription filter management with regex-based log group and log stream matching
- Cross-account log ingestion via Logs Destination
- Cross-account and cross-region S3 access log ingestion
- Configurable Firehose buffering with GZIP compression to S3 datalake
- Configurable retention policies
- Configurable sizing of computational resources and disk space
Search & Analytics¶
- OpenSearch with pre-built index templates, ISM retention policies, pipelines, and dashboards
- Athena datalake with partition-projected Glue tables and pre-built queries
Pattern Detection¶
- Custom pattern rules with regex, category, and severity
- 50+ built-in pattern rules across PII, PHI, FIN, SECRET, SQL, and APP categories
- Three modes: tag (annotate), redact (replace), filter (drop)
- Per-pattern CloudWatch metrics (Advanced tier+)
Subscription Editor¶
- Browser-based editor with live validation and regex testing
- Master-detail layout with keyboard navigation
- Version history with diff preview and one-click rollback
- Auto-save drafts every 30 seconds
- Live log group matching (Matches button)
- Pattern rule import/export (JSON)
- Compliance report generation and scheduling
- Log metadata management
- Unsaved changes indicator in header (yellow dot)
- Session expiry detection with automatic notification on 401/302 responses
- Session keepalive ping every 30 seconds
- Pattern name validation (alphanumeric and underscores only)
- Paginated report list with configurable page size (5/10/15/20)
- Keyboard navigation for report list (arrow keys, Escape to close)
- Inline report preview with header and close button
- Lookback window field inline with schedule day checkboxes
- Report header shows period and generation timestamp
Operations¶
- Cognito integration for user management and SAML/OIDC in enterprise environments
- FedRAMP/HIPAA compliance
- Self-monitoring with CloudWatch dashboard and alarms for Lambda errors, SQS dead letters, and OpenSearch health
- Run more than one instance, e.g. development and production
- Sample log generators — enabled by default, toggleable via CloudFormation parameter (
SampleLoggersEnabled)
Tiers¶
- Four tiers: Basic, Essential, Advanced, Enterprise
- Entitlement-aware processing with grace period on expiry
- Role-based access control (Advanced tier+)
Cross-Account¶
- Cross-account CloudWatch Logs subscription setup script
- Cross-account S3 access log replication setup script
CrossAccountIdsparameter with conditional bucket policy in CloudFormation template