What's New
Anomali Security Analytics is regularly updated with new features and enhancements. You can use this page to track recent updates and reference relevant articles in the online help center. For documentation only updates, refer to Documentation Updates.
| Update | Date |
|---|---|
|
ENHANCEMENT Log Source Update (Limited Availability): Ingest Mimecast cloud logs into Security Analytics using the updated Mimecast API 2.0 integration, instead of the previous API 1.0 integration, ensuring continued support for monitoring and analysis. See Mimecast for more information. |
Jul 9, 2026 |
|
FEATURE Expanded Resource Tagging (Limited Availability): Apply tags to Alerts and filter them by tags, as well as bulk edit tags and permissions across alerts. See Using Alerts for more information. |
May 28, 2026 |
|
ENHANCEMENT Asset Lookup Table(Limited Availability): Import asset data from supported scanners (Qualys, Rapid7, Tenable, AWS) or CSV uploads, which is then populated into the asset lookup table for monitoring. See Managing Asset Data Imports for more information. |
Mar 31, 2026 |
|
ENHANCEMENT Alert Triage (Limited Availability): Triage alerts using persistent comment history, richer side-panel context, and streamlined alert assignment and investigation workflows. See Alert Triage for more information. |
Mar 31, 2026 |
|
FEATURE Google SecOps Log Ingestion Support (Limited Availability): Anomali now supports ingestion of Google SecOps data based on both curated and custom alerts. See Google SecOps for more information. |
Jan 6, 2026 |
|
FEATURE Alert Email Attachments: Specify whether to attach a PDF or CSV of a triggered alert as well as other details to include in the email. See Using Alerts for more information. |
Sep 26, 2025 |
|
FEATURE Alert Triage Result Entries: Specify how many result entries an alert returns as its output, each time it is triggered. See Using Alerts for more information. |
Aug 26, 2025 |
|
ANNOUNCEMENT License Limits and Usage Dashboard: The Data Usage feature from the Security Analytics Settings is deprecated. All its functionality is now available in the License Limits and Usage Dashboard. |
Aug 26, 2025 |
|
ANNOUNCEMENT Event Data Retention: Added information about how Anomali Security Analytics retains event data. See Security Analytics Data Retention Policy for more information. |
Jul 15, 2025 |
|
ENHANCEMENT Log Source Management (Limited Availability): Add event telemetry data from cloud log sources using API calls. See Data Onboarding and Log Source Management for more information. |
Jul 1, 2025 |
|
ANNOUNCEMENT Retrosearch API Update: The Retrosearch API |
Jun 24, 2025 |
|
FEATURE Forward to S3: Add an action to forward alert payloads to S3 when you create an search event alert. See Using Alerts for more information. |
Jun 4, 2025 |
|
FEATURE Log Source Management (Limited Availability): Add event telemetry data from various log sources using one or more ingestion methods. See Data Onboarding and Log Source Management for more information. |
May 5, 2025 |
|
FEATURE Alert Triage: Add an alert triage when you create an search event alert. See Creating Alerts for more information. |
Feb 20, 2025 |
|
FEATURE Audit Logs for Dashboards: Audit the actions users take on dashboards. See Audit Logging (Limited Availability) for more information. |
Feb 12, 2025 |
|
FEATURE Webhook Payload Integration: Forward matched events to a third-party service as a customizable JSON payload via an HTTP POST request. See Creating Alerts for more information. |
Feb 6, 2025 |
|
FEATURE Cron Scheduling for Alerts: Use cron expressions to schedule alerts and their frequency. See Creating Alerts for more information. |
Jan 8, 2025 |
|
FEATURE Role-based Search: Org admins can map users groups to roles to control how far back in time a user can search event log data. See Managing Visibility of Event Log Data with RBAC for more information. |
Nov 14, 2024 |
|
FEATURE Audit Logging (Limited Availability): Administrators can audit the activity of users in their organization to gain crucial insight into the history of different user actions. See Audit Logging (Limited Availability) for more information. |
Nov 11, 2024 |
|
FEATURE New Log Source: Added support for MS Office 365. See Microsoft Office 365 for more information. |
Sep 23, 2024 |
|
FEATURE New Log Source: Added support for NXLog. See Using NXLog to Ship Data for more information. |
Sep 11, 2024 |
|
ANNOUNCEMENT Customers are advised to contact Anomali Customer Support to request support for backfilling of events older that 24 hours ingested via Anomali Cloud Link. See Managing Links and Log Sources for more information. |
Sep 4, 2024 |
|
FEATURE New Log Source: Added support for Cribl. See Cribl Stream for more information. |
Aug 23, 2024 |
|
FEATURE Azure Alert Forwading: Added support for forwarding all types of alerts to Azure. See Using Alerts for more information. |
Aug 20, 2024 |
|
FEATURE Alert Throttling: Now throttling can be configured for Event Search alerts. See Using Alerts for more information. |
Aug 14, 2024 |
|
FEATURE Webhook for Alert Forwading: Added support for forwarding Event Search alerts to third parties via webhooks. See Using Alerts for more information. |
Jul 24, 2024 |
|
FEATURE Lookup Tables: Added the Append to existing table feature to the CSV Import tab. The feature allows you to add rows to an existing lookup table. See Managing Lookup Tables for more information. |
Jul 18, 2024 |
|
FEATURE Event Telemetry: Added support for ingesting logs uploaded via an HTTP API Gateway. See Adding a Log Source via HTTP Upload for more information. |
Apr 29, 2024 |
|
ANNOUNCEMENT Anomali Security Analytics: Anomali Security Analytics is the new name for Anomali Match Cloud. See Anomali Security Analytics Overview for more information. |
Apr 22, 2024 |
|
ANNOUNCEMENT IOA Match Updates: IOA Match activity search index is deprecated. Use AQL Search to evaluate Sigma rules against your event log data. See Evaluating Sigma Rules for information about Sigma rules. |
Mar 18, 2024 |
|
ANNOUNCEMENT Cloud Link Updates: A recent Cloud Link software update has improved the workflow for several log sources. Customers are advised to contact Anomali Customer Support to request support for log ingestion. See Data Onboarding and Log Source Management for a matrix describing Anomali support for common log sources. Contact Anomali Customer Support for information about other log sources you want to analyze. |
Mar 1, 2024 |
|
ENHANCEMENT Scheduled Retrospective Search: Added the following action: Enable Splunk HTTP Event Collector. |
Feb 14, 2024 |
|
ANNOUNCEMENT Alerts and Lookup Table Updates: Alerts and Lookup Table configuration settings were moved from the Settings menu to the Manage menu so that non-admin users can create alert configurations and lookup table configurations. See Using Alerts for more information. |
Dec 14, 2023 |
|
FEATURE Event Telemetry Update: Added support for ingesting AWS Application Load Balancer logs. See AWS Load Balancer for more information. |
Aug 3, 2023 |
|
FEATURE Event Telemetry Update: Added support for ingesting Azure Event Hubs logs. See Azure Event Hubs for more information. |
Aug 3, 2023 |
|
ENHANCEMENT Alert Updates: Link alerts can now be configured with the following alert actions: List on Activity Page, Send Email, Add to Investigation, Forward Syslog, and Forward to Splunk HTTP Collector. See Using Alerts for more information. |
Jul 28, 2023 |
|
ENHANCEMENT Scheduled Retrospective Search: You can now delete scheduled retrospective search jobs. |
Jul 28, 2023 |
|
ENHANCEMENT Threat Model Updates: Threat Model activity search details pages now have separate tabs for IOC Matches and IOA Matches. |
Jun 28, 2023 |
|
FEATURE Asset Data Enrichment: Added support for ingesting asset data from Amazon Web Services SQS or S3 locations. See Managing AWS Asset Data Imports for more information. |
Jun 8, 2023 |
|
ENHANCEMENT Alert Updates: For alerts set to run on a continuous schedule, you can now customize the Query Delay offset. The Query Delay offset allows time for collection and correlation from log sources that run on scheduled intervals to be completed before the alert engine cycle is run. The default is 2 hours and is recommended in most cases. See Using Alerts for more information. |
Jun 8, 2023 |
|
ENHANCEMENT IOC Match Search: In the search results table, rows are now aggregated when an event log matches more than one indicator or when an indicator has multiple intel source feeds. The leftmost column shows the aggregation count and has an expander icon you can click to display individual result rows. See IOC Match Activity Searches for more information. |
Jun 1, 2023 |
|
ENHANCEMENT Alert Updates: Added support to allow you to use your organization's Preferred Tags with the Add tags to IOCs action. See Using Alerts for more information. |
May 10, 2023 |
|
FEATURE Event Telemetry: Added support for ingesting Microsoft Defender ATP alerts. See Microsoft Defender ATP for more information. |
May 10, 2023 |
|
FEATURE Event Telemetry: Updated the Microsoft Defender log source integration to include support for alert events. The log source now supports ingestion and automatic mapping for alert events, device events, and email events. See Microsoft Defender for more information. |
Apr 21, 2023 |
|
FEATURE Event Telemetry: Added support for ingesting Google Cloud Platform VPC flow and firewall logs. See Google Cloud Platform for more information. |
Apr 19, 2023 |
|
FEATURE IOA Match Updates: Add match results to and monitor visibility of ThreatStream investigations from the IOA Match, Alerts, and Forensics & Retrospective Activity search pages. |
Apr 4, 2023 |
|
FEATURE Anomali Match for IOA: Use Anomali Match to identify IOA and potential infrastructure threats based on Anomali Sigma rules. Note that IOA Match has been deprecated. |
Feb 28, 2023 |
|
FEATURE Anomali Link Alerts: Anomali Link alerts are triggered when an Anomali Link has not received events for a specified time, as well as when Link resumes receiving alerts after a period of downtime. Additionally, you can forward the matched events to a specified Splunk HEC destination. See Using Alerts for more information. |
Feb 7, 2023 |
|
ANNOUNCEMENT Event Telemetry Updates: Added support for using Cloud Link to ingest custom log sources from AWS S3 or SQS. The AWS S3/SQS log source workflow has been deprecated. Your event logs can be ingested via a different workflow. Contact Anomali support for assistance. |
Jan 19, 2023 |
|
FEATURE Event Telemetry: Added support for ingesting Kafka logs. See Kafka for more information. |
Jan 19, 2023 |
|
FEATURE Event Telemetry: Updated the Sumo Logic log source integration. Integration with this log source no longer requires use of Anomali Universal Link. See Sumo Logic for more information. |
Dec 7, 2022 |
|
ENHANCEMENT IOC Match Search: Added a Filter UI for Visibility. Visibility is based on the See IOC Match Activity Searches for more information. |
Nov 29, 2022 |
|
FEATURE Event Telemetry: Updated the Microsoft Defender log source integration. Integration with this log source no longer requires use of Anomali Universal Link. The new integration supports ingestion of device events and email events. See Microsoft Defender for more information. |
Nov 16, 2022 |
|
ENHANCEMENT Common Event Schema: Added a reference of common event schema fields. See Anomali Security Analytics eventlog schema for more information. |
Nov 16, 2022 |
|
ENHANCEMENT IOC Match Search: Added support for field-based searches based on the See IOC Match Activity Searches for more information. |
Nov 9, 2022 |
|
FEATURE Data Usage Dashboard: Added the Data Usage Dashboard, as well as email notifications, to keep you informed about your data usage and subscription limits. See Data Usage Dashboard for more information. |
Oct 13, 2022 |
|
FEATURE Threat Model Search: Added support for Attack Pattern searches. Attack Pattern refers to common methods of exploiting software reported by MITRE and other intelligence providers. See Attack Pattern Activity Searches for more information. |
Aug 31, 2022 |
|
FEATURE Cloud Link: Introduced Cloud Link, a cloud-hosted version of Universal Link. Cloud Link is used to ingest cloud-to-cloud data flows from Amazon Web Services and Microsoft Defender, among other log sources. See Managing Links and Log Sources for more information. |
Aug 26, 2022 |
|
FEATURE Scheduled Retrospective Search: Added support for scheduled retrospective search jobs. A retrospective search job is a scheduled task to evaluate historic event logs for newly reported indicators of compromise (IOCs) or updated Threat Model details. |
Aug 2, 2022 |
|
FEATURE Event Telemetry: Added support for ingesting Netskope logs. See Netskope for more information. |
Jul 25, 2022 |
|
FEATURE Asset Data Enrichment: Added support for ingesting asset data from Rapid7 InsightVM Platform. See Managing Rapid7 Scanner Imports for more information. |
Jul 8, 2022 |
|
FEATURE Alert Updates: Added support for the Add tags to IOCs action. When an alert is triggered, Anomali Security Analytics sends ThreatStream a request to add the tag to the intelligence maintained about the indicator. In turn, ThreatStream updates consumers of ThreatStream intelligence, including Anomali Security Analytics. See Using Alerts for more information. |
Jul 7, 2022 |
|
FEATURE Event Telemetry: Added support for ingesting Azure NSG flow logs. See Microsoft Azure NSG Flow for more information. |
Jun 30, 2022 |
|
FEATURE Event Telemetry: Added support for ingesting Mimecast logs. See Mimecast for more information. |
Jun 30, 2022 |
|
ENHANCEMENT Asset Details: New Asset Details page. You can drill down from the Overview dashboard Top 20 Impacted Hosts by Risk Score panel or the Activity Search Asset results table to view asset details, including Risk Score, match history timeline, match results table, and vulnerabilities. See Asset Activity Searches for more information. |
Jun 14, 2022 |
|
FEATURE Reports: Added scheduled reports. Reports are snapshots of Anomali Security Analytics dashboards filtered for a specified time range and search filter expression. See Managing Reports for more information. |
May 24, 2022 |
|
FEATURE Link or Log Source Status Indicators: Improved health status indicators for Links and log sources. See Managing Links and Log Sources for more information. |
May 24, 2022 |
|
FEATURE Event Telemetry: Added support for ingesting AWS VPC Flow and VPC DNS logs. See AWS VPC Flow for more information. |
May 10, 2022 |
|
FEATURE Event Telemetry: Added support for ingesting Carbon Black EDR logs. See Carbon Black for more information. |
Apr 29, 2022 |
|
FEATURE Asset Data Enrichment: Added support for ingesting asset data from a Tenable.io scanner. See Managing Tenable Scanner Imports for more information. |
Apr 28, 2022 |
|
FEATURE Alerts: Added support for spike and frequency detection alerts. See Using Alerts for more information. |
Apr 28, 2022 |
|
FEATURE Event Telemetry: Added support for ingesting Microsoft Defender logs. See Microsoft Defender for more information. |
Apr 22, 2022 |
|
FEATURE Dashboards: Added the Match Analysis Dashboard. The Match Analysis Dashboard provides analytics about the threat intelligence feeds, indicator types, indicators, and DGA domains that match events in your network. These analytics can be useful in determining the effectiveness or noise-level of a threat intelligence element. See Match Analysis Dashboard for more information. |
Apr 20, 2022 |
|
FEATURE Exclude Lists: Added support for two new exclude lists: Suppress Feeds and Suppress iTypes. The feed IDs and iTypes you add to these lists are excluded from correlation and activity search results. See Managing Exclude Lists for more information. |
Apr 20, 2022 |
|
FEATURE Dashboards: Added the Multi Dimensional Dashboard. The Multi Dimensional Dashboard has ten visualizations and table panels that show the occurrences of IOC matches over time. The panels bring different elements of IOC matching into focus—for example, IOC matches over time or IOC matches by source. See Multi Dimensional Dashboard for more information. |
Apr 12, 2022 |
|
FEATURE Event Telemetry: Added support for ingesting CrowdStrike logs from a CrowdStrike FDR S3 bucket. Anomali Security Analytics supports cloud-to-cloud dataflow for Microsoft Azure, CrowdStrike FDR, and Sumo Logic. See CrowdStrike FDR for more information. |
Apr 4, 2022 |