Skip to content

Changelog

Release history and what's new in each version.

26h4 — Update

  • Pattern detection and monitoring improvements
  • Reliability and security enhancements
  • Improved dashboard availability and stability
  • Hardened web security headers across dashboard and editor
  • Compliance reports now show generation time in your local timezone

26h3 — Update

  • Scheduled maintenance release
  • AWS Qualified Software

26h2 (Sep 2026) — Update

  • MoM enhancements
  • Maintain credentials used for remote subscription management
  • Added support link to landing and fulfillment pages
  • Change logout behavior
  • Renamed OpenSearch Dashboards

26h2 (Aug 2026) — Update

  • On stack update, address the "Could not locate index-pattern-field" errors on dashboard visualizations that required a manual index refresh
  • Update OpenSearch to v2.19
  • AWS FTR Approved

26h2 (July 2026) — Update

  • Support for AWS Organizations — consolidate and centrally govern multiple AWS accounts
  • Remote subscription management — browse, subscribe, and unsubscribe log groups in remote accounts directly from the Subscription Editor in the same region
  • Athena dynamic account discovery — automatically detect accounts as logs flow in
  • Accounts management UI — manage remote accounts in the editor; add, remove, and validate accounts with one-click role verification
  • Entitlement status in FAQ — live Marketplace entitlement status displayed in the editor FAQ with a badge alert on error or expiration
  • AI Monitor correlation flag — new "AI Monitor Correlate" checkbox on pattern rules to mark patterns eligible for cross-log correlation analysis
  • Rollback preview — version rollback now loads into the editor for review before saving, with full undo support
  • Dirty state indicators — Save, Undo, and Diff buttons are disabled when no unsaved changes exist
  • iPad layout fix — subscription list footer buttons now display correctly on tablet viewports
  • Deployment telemetry — active stack deployments are tracked and displayed as badges on the Marketplace fulfillment landing page

26h1 (June 2026) — Initial Release

Ingestion

  • 14 built-in ingest pipelines: Lambda, JSON, Nginx, Apache, Syslog, Tomcat, Spring, VPC Flow, ALB, API Gateway, RDS Slow Query, EKS, CloudFront, RDS PostgreSQL
  • Automated CloudWatch subscription filter management with regex-based log group and log stream matching
  • Cross-account log ingestion via Logs Destination
  • Cross-account and cross-region S3 access log ingestion
  • Configurable Firehose buffering with GZIP compression to S3 datalake
  • Configurable retention policies
  • Configurable sizing of computational resources and disk space

Search & Analytics

  • OpenSearch with pre-built index templates, ISM retention policies, pipelines, and dashboards
  • Athena datalake with partition-projected Glue tables and pre-built queries

Pattern Detection

  • Custom pattern rules with regex, category, and severity
  • 50+ built-in pattern rules across PII, PHI, FIN, SECRET, SQL, and APP categories
  • Three modes: tag (annotate), redact (replace), filter (drop)
  • Per-pattern CloudWatch metrics (Advanced tier+)

Subscription Editor

  • Browser-based editor with live validation and regex testing
  • Master-detail layout with keyboard navigation
  • Version history with diff preview and one-click rollback
  • Auto-save drafts every 30 seconds
  • Live log group matching (Matches button)
  • Pattern rule import/export (JSON)
  • Compliance report generation and scheduling
  • Log metadata management
  • Unsaved changes indicator in header (yellow dot)
  • Session expiry detection with automatic notification on 401/302 responses
  • Session keepalive ping every 30 seconds
  • Pattern name validation (alphanumeric and underscores only)
  • Paginated report list with configurable page size (5/10/15/20)
  • Keyboard navigation for report list (arrow keys, Escape to close)
  • Inline report preview with header and close button
  • Lookback window field inline with schedule day checkboxes
  • Report header shows period and generation timestamp

Operations

  • Cognito integration for user management and SAML/OIDC in enterprise environments
  • FedRAMP/HIPAA compliance
  • Self-monitoring with CloudWatch dashboard and alarms for Lambda errors, SQS dead letters, and OpenSearch health
  • Run more than one instance, e.g. development and production
  • Sample log generators — enabled by default, toggleable via CloudFormation parameter (SampleLoggersEnabled)

Tiers

  • Four tiers: Basic, Essential, Advanced, Enterprise
  • Entitlement-aware processing with grace period on expiry
  • Role-based access control (Advanced tier+)

Cross-Account

  • Cross-account CloudWatch Logs subscription setup script
  • Cross-account S3 access log replication setup script
  • CrossAccountIds parameter with conditional bucket policy in CloudFormation template