Skip to content

Release Notes

Known Issues

Auto State Apply detects configuration changes saved in Administration --> Configuration and rule updates on the manager node. Files that you create or edit directly under /opt/so/saltstack/local/salt/ are not detected. After adding or changing any of the following, apply the relevant state from the manager or wait for the next scheduled highstate (see Highstate Interval):

  • Zeek intel in /opt/so/saltstack/local/salt/zeek/policy/intel/
  • Zeek custom packages in /opt/so/saltstack/local/salt/zeek/zkg/
  • Elasticsearch custom ingest parsers in /opt/so/saltstack/local/salt/elasticsearch/files/ingest/
  • RBAC custom Elastic stack role files in /opt/so/saltstack/local/salt/elasticsearch/roles/
  • Logstash custom pipeline configuration files in /opt/so/saltstack/local/salt/logstash/pipelines/config/custom/

For all other known issues, please see https://github.com/Security-Onion-Solutions/securityonion/issues.

Release History

3.2.0 [20260729] Changes

  • FEATURE: Initial implementation of agentic framework
  • FEATURE: Autodetect salt apply state from SOC config audit history
  • FEATURE: Config audit history w/ restore
  • FEATURE: Datastream Lifecycle Management
  • FEATURE: Guided Analysis Progressive Loading #16091
  • FEATURE: Limit certain config settings to specific node types #15972
  • FEATURE: Map Antivirus Sigma rules to Elastic Defend #14468
  • FEATURE: Sigma Playbooks - Initial Set #16090
  • FEATURE: Support ES|QL in Sigma detections
  • FEATURE: Support Suricata Transactional rule dir #15948
  • FEATURE: Updated default Hunt query #16026
  • FIX: Allow manager to run two full highstates during soup #15986
  • FIX: Allow periods in NIC names #16060
  • FIX: Disable Zeek icsnpp-modbus script #16110
  • FIX: Do not allow login redirects to API URLs #16065
  • FIX: Elastic Defend incompatible with linux 7+ kernels
  • FIX: Elastic Fleet server state persistence #16051
  • FIX: Elasticfleet: server urls auto updating when opted out #15960
  • FIX: Elasticsearch GC log rotate #16034
  • FIX: Elasticsearch: index template partial duplicate #15959
  • FIX: Ensure so-yaml.py updated during soup #16066
  • FIX: Import/Eval error in elasticsearch configuration script #16025
  • FIX: Improve elastic agent install outcome to check that the installation is healthy
  • FIX: Improve Elasticsearch scripts runtime #15987
  • FIX: Improve Group Metrics Layout on Alert Page
  • FIX: Improve Hunt Query Box UI on Smaller Screens
  • FIX: Improve logging when Alerts fail to Ack #15999
  • FIX: Missing esheap pillar value breaks highstate on Elasticsearch nodes #16108
  • FIX: Nav Bar Hover Misalignment
  • FIX: Refreshing browser while in hunt drops index filters #15331
  • FIX: Rename Connect API to Security Onion API #15921
  • Fix: Rework soup postupgrade_changes #15946
  • FIX: Run Elastic Agent regenerate installers script
  • FIX: Salt: server restart and highstate issues
  • FIX: so-start | so-stop | so-restart utilities #16014
  • FIX: Soup should run so-config-backup script #15901
  • FIX: Soup verify an upgrade is available prior to running elasticsearch upgrade compatibility check
  • FIX: Suricata rule reload should not report failure if a reload is already in progress #16016
  • UPGRADE: alpine base images to 3.24.1 #15992
  • UPGRADE: Axios to 1.18.1 #15950
  • UPGRADE: CyberChef to 11.2.0 #15997
  • UPGRADE: Dompurify to 3.4.12 #15977
  • UPGRADE: Elasticsearch 9.3.7 #16063
  • UPGRADE: golang to 1.26.4 #15988
  • UPGRADE: InfluxDB to 2.9.1 (UI to 2.9.0) #15993
  • UPGRADE: js-yaml to 4.3.0 #15976
  • UPGRADE: Kafka to 4.3.1 #16001
  • UPGRADE: Kratos and Hydra google/x/net Go deps #16048
  • UPGRADE: Migration of more images to UBI 9.7 #16010
  • UPGRADE: nginx to 1.31.2 #15996
  • UPGRADE: node to 26.3.1 #15990
  • UPGRADE: OpenCanary to 0.9.8 #16003
  • UPGRADE: Oracle UEK8 Kernel
  • UPGRADE: Postgres to 17.10 #15998
  • UPGRADE: pySigma & sigma-cli #15616
  • UPGRADE: Redis to 7.4.9 #15994
  • UPGRADE: registry to 3.1.1 #15991
  • UPGRADE: SOC Go dependencies #16032
  • UPGRADE: Suricata to 8.0.6 #16042
  • UPGRADE: Telegraf to 1.39.0 #15995
  • UPGRADE: Zeek to 8.0.9 #16040

3.1.0 Hotfix [20260528] Changes

  • FIX: Grids with multiple heavy nodes fail Elasticsearch upgrade verification for 3.1.0
  • FIX: Grids using custom logstash pipeline(s) may have stale pillar entries #15932

3.1.0 [20260521] Changes

  • FEATURE: Add Postgres support for future features
  • FEATURE: Add bonded NIC support for management interfaces #15548
  • FEATURE: Add ingest latency metric
  • FEATURE: Allow the setup of bond1 for management for ISO installs #15865
  • FEATURE: Elastic Fleet continuously validate output policy
  • FEATURE: RAID monitoring for hypervisor VMs #15809
  • FEATURE: Restore Suricata Overrides from backup #15881
  • FEATURE: Sigma mappings - M365 & Fortigate #15882
  • FEATURE: Simplified Onion AI setup for regions outside US #15773
  • FEATURE: Support Azure OpenAI endpoints #15841
  • FIX: 'Investigate' using inaccessible local model shows "insufficient credits"
  • FIX: Add options selection to annotations #15744
  • FIX: Appliance images in SOC grid misaligned #15713
  • FIX: Consider setting Elastic Agent output level to warning only #15431
  • FIX: Deterministically sort threshold.conf #15815
  • FIX: Improve elastic agent install outcome to check that the installation is healthy
  • FIX: Improve lucene and elastic query param validation #15860
  • FIX: Improve reverse DNS lookups success rate #15760
  • FIX: Improve usability for visually impaired users
  • FIX: JA4+ license hyperlink #15717
  • FIX: Make SOC and Kratos enabled annoations readonly #15827
  • FIX: Modifying detection templates in config causes SOC to crash loop #15798
  • FIX: Need better user feedback when attaching assistant chat to a case #15689
  • FIX: Node descriptions containing both spaces and numbers prevent pillar creation #15540
  • FIX: Prevent excessive OnionAI query length
  • FIX: Reactor sominion_setup #15834
  • FIX: Refactor Detections backup #14992
  • FIX: Reinstall #15811
  • FIX: SOUP verify all Elasticsearch nodes are compatible with the next Elasticsearch version #15908
  • FIX: Suricata pcap-log max-files rounds to 0 when calculated value is between 0 and 1 #15740
  • FIX: UI should show the name of the current Dashboard #15703
  • FIX: Use hunt action link for case observable hunt pivots #15752
  • FIX: Use safeload for loading filecheck config #15859
  • FIX: Zeek ingest pipeline for JA4d.log #15886
  • UPGRADE: Axios to 1.15.0 in SOC #15774
  • UPGRADE: CyberChef to 11.0.0 #15890
  • UPGRADE: Elasticsearch to 9.3.3
  • UPGRADE: Kratos and Hydra 26.2.0+pgx #15796
  • UPGRADE: SOC Go dependencies #15795
  • UPGRADE: SOC frontend dependency libs #15848
  • UPGRADE: Suricata to 8.0.5 #15903
  • UPGRADE: Zeek to 8.0.8 #15794
  • UPGRADE: nginx to 1.30.1 #15891

3.0.0 [20260331] Changes

  • FEATURE: Configurable Elasticsearch vm.max_map_count setting
  • FEATURE: Dynamically load Zeek plugins on zeek startup #15546
  • FEATURE: Enable JA4+ License Acceptance #15560
  • FEATURE: Parsing for Zeek websockets logs #15657
  • FEATURE: Refresh login page with updated look
  • FEATURE: Refresh SOC UI with updated look
  • FEATURE: Support additional alt names in web cert
  • FEATURE: Support docker ulimit customization #15581
  • FEATURE: Suricata PCAP replacing Stenographer
  • FIX: API 401 errors will no longer redirect #15611
  • FIX: Cleanup file.absent and cron.absent
  • FIX: Detections - Intermittent "error closing scroll" #14216
  • FIX: Duplicated user roles when refreshing frontend at Administration > Users #15688
  • FIX: Enabled / Disabled Buttons for SOC Grid Configuration Options #15649
  • FIX: Fix rule validators in SOC #15533
  • FIX: Global override configs should not apply to certain indices #15601
  • FIX: Network Transport for suricata alerts should be lowercase #15668
  • FIX: Sensors are not checking in while processing long jobs #15650
  • FIX: so-suricata-testrule script #15396
  • FIX: STIG V1R3
  • FIX: Suricata address-groups vars allow negation #15664
  • FIX: Unable to create detections via Security Onion API #15673
  • UPGRADE: All frontend 3rd party deps
  • UPGRADE: ATTACK Navigator to 5.3.0 #15680
  • UPGRADE: CyberChef to 10.22.1 #15681
  • UPGRADE: ElastAlert2 to 2.28.0 #15685
  • UPGRADE: Golang 3rd party deps #15647
  • UPGRADE: Golang to 1.26.1 #15580
  • UPGRADE: Hydra to 25.4.0 #15678
  • UPGRADE: Kafka to 3.9.2 #15684
  • UPGRADE: Kratos to 25.4.0 #15677
  • UPGRADE: Nginx to 1.29.6 #15686
  • UPGRADE: OpenCanary to 0.9.7 #15679
  • UPGRADE: Redis to 7.2.13 #15682
  • UPGRADE: Suricata to 8.0.4 #15625
  • UPGRADE: Telegraf to 1.38.0 #15683
  • UPGRADE: Update Docker base images