Release Notes¶
Known Issues¶
Auto State Apply detects configuration changes saved in Administration --> Configuration and rule updates on the manager node. Files that you create or edit directly under /opt/so/saltstack/local/salt/ are not detected. After adding or changing any of the following, apply the relevant state from the manager or wait for the next scheduled highstate (see Highstate Interval):
- Zeek intel in
/opt/so/saltstack/local/salt/zeek/policy/intel/ - Zeek custom packages in
/opt/so/saltstack/local/salt/zeek/zkg/ - Elasticsearch custom ingest parsers in
/opt/so/saltstack/local/salt/elasticsearch/files/ingest/ - RBAC custom Elastic stack role files in
/opt/so/saltstack/local/salt/elasticsearch/roles/ - Logstash custom pipeline configuration files in
/opt/so/saltstack/local/salt/logstash/pipelines/config/custom/
For all other known issues, please see https://github.com/Security-Onion-Solutions/securityonion/issues.
Release History¶
3.2.0 [20260729] Changes¶
- FEATURE: Initial implementation of agentic framework
- FEATURE: Autodetect salt apply state from SOC config audit history
- FEATURE: Config audit history w/ restore
- FEATURE: Datastream Lifecycle Management
- FEATURE: Guided Analysis Progressive Loading #16091
- FEATURE: Limit certain config settings to specific node types #15972
- FEATURE: Map Antivirus Sigma rules to Elastic Defend #14468
- FEATURE: Sigma Playbooks - Initial Set #16090
- FEATURE: Support ES|QL in Sigma detections
- FEATURE: Support Suricata Transactional rule dir #15948
- FEATURE: Updated default Hunt query #16026
- FIX: Allow manager to run two full highstates during soup #15986
- FIX: Allow periods in NIC names #16060
- FIX: Disable Zeek icsnpp-modbus script #16110
- FIX: Do not allow login redirects to API URLs #16065
- FIX: Elastic Defend incompatible with linux 7+ kernels
- FIX: Elastic Fleet server state persistence #16051
- FIX: Elasticfleet: server urls auto updating when opted out #15960
- FIX: Elasticsearch GC log rotate #16034
- FIX: Elasticsearch: index template partial duplicate #15959
- FIX: Ensure so-yaml.py updated during soup #16066
- FIX: Import/Eval error in elasticsearch configuration script #16025
- FIX: Improve elastic agent install outcome to check that the installation is healthy
- FIX: Improve Elasticsearch scripts runtime #15987
- FIX: Improve Group Metrics Layout on Alert Page
- FIX: Improve Hunt Query Box UI on Smaller Screens
- FIX: Improve logging when Alerts fail to Ack #15999
- FIX: Missing esheap pillar value breaks highstate on Elasticsearch nodes #16108
- FIX: Nav Bar Hover Misalignment
- FIX: Refreshing browser while in hunt drops index filters #15331
- FIX: Rename Connect API to Security Onion API #15921
- Fix: Rework soup postupgrade_changes #15946
- FIX: Run Elastic Agent regenerate installers script
- FIX: Salt: server restart and highstate issues
- FIX: so-start | so-stop | so-restart utilities #16014
- FIX: Soup should run so-config-backup script #15901
- FIX: Soup verify an upgrade is available prior to running elasticsearch upgrade compatibility check
- FIX: Suricata rule reload should not report failure if a reload is already in progress #16016
- UPGRADE: alpine base images to 3.24.1 #15992
- UPGRADE: Axios to 1.18.1 #15950
- UPGRADE: CyberChef to 11.2.0 #15997
- UPGRADE: Dompurify to 3.4.12 #15977
- UPGRADE: Elasticsearch 9.3.7 #16063
- UPGRADE: golang to 1.26.4 #15988
- UPGRADE: InfluxDB to 2.9.1 (UI to 2.9.0) #15993
- UPGRADE: js-yaml to 4.3.0 #15976
- UPGRADE: Kafka to 4.3.1 #16001
- UPGRADE: Kratos and Hydra google/x/net Go deps #16048
- UPGRADE: Migration of more images to UBI 9.7 #16010
- UPGRADE: nginx to 1.31.2 #15996
- UPGRADE: node to 26.3.1 #15990
- UPGRADE: OpenCanary to 0.9.8 #16003
- UPGRADE: Oracle UEK8 Kernel
- UPGRADE: Postgres to 17.10 #15998
- UPGRADE: pySigma & sigma-cli #15616
- UPGRADE: Redis to 7.4.9 #15994
- UPGRADE: registry to 3.1.1 #15991
- UPGRADE: SOC Go dependencies #16032
- UPGRADE: Suricata to 8.0.6 #16042
- UPGRADE: Telegraf to 1.39.0 #15995
- UPGRADE: Zeek to 8.0.9 #16040
3.1.0 Hotfix [20260528] Changes¶
- FIX: Grids with multiple heavy nodes fail Elasticsearch upgrade verification for 3.1.0
- FIX: Grids using custom logstash pipeline(s) may have stale pillar entries #15932
3.1.0 [20260521] Changes¶
- FEATURE: Add Postgres support for future features
- FEATURE: Add bonded NIC support for management interfaces #15548
- FEATURE: Add ingest latency metric
- FEATURE: Allow the setup of bond1 for management for ISO installs #15865
- FEATURE: Elastic Fleet continuously validate output policy
- FEATURE: RAID monitoring for hypervisor VMs #15809
- FEATURE: Restore Suricata Overrides from backup #15881
- FEATURE: Sigma mappings - M365 & Fortigate #15882
- FEATURE: Simplified Onion AI setup for regions outside US #15773
- FEATURE: Support Azure OpenAI endpoints #15841
- FIX: 'Investigate' using inaccessible local model shows "insufficient credits"
- FIX: Add options selection to annotations #15744
- FIX: Appliance images in SOC grid misaligned #15713
- FIX: Consider setting Elastic Agent output level to warning only #15431
- FIX: Deterministically sort threshold.conf #15815
- FIX: Improve elastic agent install outcome to check that the installation is healthy
- FIX: Improve lucene and elastic query param validation #15860
- FIX: Improve reverse DNS lookups success rate #15760
- FIX: Improve usability for visually impaired users
- FIX: JA4+ license hyperlink #15717
- FIX: Make SOC and Kratos enabled annoations readonly #15827
- FIX: Modifying detection templates in config causes SOC to crash loop #15798
- FIX: Need better user feedback when attaching assistant chat to a case #15689
- FIX: Node descriptions containing both spaces and numbers prevent pillar creation #15540
- FIX: Prevent excessive OnionAI query length
- FIX: Reactor sominion_setup #15834
- FIX: Refactor Detections backup #14992
- FIX: Reinstall #15811
- FIX: SOUP verify all Elasticsearch nodes are compatible with the next Elasticsearch version #15908
- FIX: Suricata pcap-log max-files rounds to 0 when calculated value is between 0 and 1 #15740
- FIX: UI should show the name of the current Dashboard #15703
- FIX: Use hunt action link for case observable hunt pivots #15752
- FIX: Use safeload for loading filecheck config #15859
- FIX: Zeek ingest pipeline for JA4d.log #15886
- UPGRADE: Axios to 1.15.0 in SOC #15774
- UPGRADE: CyberChef to 11.0.0 #15890
- UPGRADE: Elasticsearch to 9.3.3
- UPGRADE: Kratos and Hydra 26.2.0+pgx #15796
- UPGRADE: SOC Go dependencies #15795
- UPGRADE: SOC frontend dependency libs #15848
- UPGRADE: Suricata to 8.0.5 #15903
- UPGRADE: Zeek to 8.0.8 #15794
- UPGRADE: nginx to 1.30.1 #15891
3.0.0 [20260331] Changes¶
- FEATURE: Configurable Elasticsearch vm.max_map_count setting
- FEATURE: Dynamically load Zeek plugins on zeek startup #15546
- FEATURE: Enable JA4+ License Acceptance #15560
- FEATURE: Parsing for Zeek websockets logs #15657
- FEATURE: Refresh login page with updated look
- FEATURE: Refresh SOC UI with updated look
- FEATURE: Support additional alt names in web cert
- FEATURE: Support docker ulimit customization #15581
- FEATURE: Suricata PCAP replacing Stenographer
- FIX: API 401 errors will no longer redirect #15611
- FIX: Cleanup file.absent and cron.absent
- FIX: Detections - Intermittent "error closing scroll" #14216
- FIX: Duplicated user roles when refreshing frontend at Administration > Users #15688
- FIX: Enabled / Disabled Buttons for SOC Grid Configuration Options #15649
- FIX: Fix rule validators in SOC #15533
- FIX: Global override configs should not apply to certain indices #15601
- FIX: Network Transport for suricata alerts should be lowercase #15668
- FIX: Sensors are not checking in while processing long jobs #15650
- FIX: so-suricata-testrule script #15396
- FIX: STIG V1R3
- FIX: Suricata address-groups vars allow negation #15664
- FIX: Unable to create detections via Security Onion API #15673
- UPGRADE: All frontend 3rd party deps
- UPGRADE: ATTACK Navigator to 5.3.0 #15680
- UPGRADE: CyberChef to 10.22.1 #15681
- UPGRADE: ElastAlert2 to 2.28.0 #15685
- UPGRADE: Golang 3rd party deps #15647
- UPGRADE: Golang to 1.26.1 #15580
- UPGRADE: Hydra to 25.4.0 #15678
- UPGRADE: Kafka to 3.9.2 #15684
- UPGRADE: Kratos to 25.4.0 #15677
- UPGRADE: Nginx to 1.29.6 #15686
- UPGRADE: OpenCanary to 0.9.7 #15679
- UPGRADE: Redis to 7.2.13 #15682
- UPGRADE: Suricata to 8.0.4 #15625
- UPGRADE: Telegraf to 1.38.0 #15683
- UPGRADE: Update Docker base images