What's New

Note: Limited Availability denotes a feature that is not available to all Anomali customers. Contact your Anomali Sales representative if you want to enable it for your organization.

Anomali Query Language (AQL) Search is regularly updated with new features and enhancements. You can use this page to track recent updates and reference relevant articles in the online help center. For documentation only updates, refer to Documentation Updates.

Update Date

ENHANCEMENT

OCSF Field Panel Update (Limited Availability): The Field Summary panel in Search now shows all OCSF fields for the relevant event categories when querying OCSF-normalized data.

See OCSF Field Panel for more information.

Jul 23, 2026

FEATURE

OCSF Field Panel (Limited Availability): Browse OCSF Version 1.2.0 schema fields by category in Event Search and view how many events in your current result set have each field populated, and add include or exclude filters to your active query by clicking a field.

See OCSF Field Panel for more information.

Jun 24, 2026

ENHANCEMENT

OCSF Schema Support for Views (Limited Availability): Create views using the OCSF schema by selecting OCSF as the schema type during view creation.

See Views for more information.

Jun 10, 2026

FEATURE

Expanded Resource Tagging (Limited Availability): Apply tags to Saved Searches, Alerts, Views, Macros, and Lookup Tables and filter them by tags, as well as bulk edit tags and permissions across these resources.

See Resource Tags for more information.

May 28, 2026

FEATURE

Role-Based Access Control for Schemas (Limited Availability): Organization administrators can now configure role-based access controls using OCSF schema fields, in addition to the standard eventlog schema, and grant appropriate user permissions for specific use cases.

See Role-Based Access Control for Schemas for more information.

May 28, 2026

ENHANCEMENT

Expanded OCSF Feature Support (Limited Availability): Use the OCSF schema to perform full-text indexing, correlations, as well as turbosearch-based AQL querying.

See OCSF Schema Overview for more information.

May 28, 2026

ENHANCEMENT

Customizable Export Timestamp (Limited Availability): Choose either a human-readable or UNIX timestamp when exporting search results.

See Exporting Search Results for more information.

May 28, 2026

ENHANCEMENT

Expanded Support for OCSF (Limited Availability): Use the OCSF Schema to perform searches based on natural language prompts.

See Search with Anomali Copilot for more information.

May 13, 2026

FEATURE

Search Tabs (Limited Availability): Launch one or more searches using multiple search tabs on the Search homepage.

See Using Search Modes for more information.

Apr 29, 2026

ENHANCEMENT

whois Operator Update (Limited Availability): Use parsed=true to filter, aggregate, and query WHOIS results without manually parsing the raw JSON.

See whois for more information.

Apr 29, 2026

FEATURE

Resource Tags for Dashboards (Limited Availability): Create and manage an organization-wide tag catalog that lets you locate and organize dashboards by applying multiple tags with appropriate user permissions.

See Resource Tags for more information.

Apr 15, 2026

ENHANCEMENT

Geo Map Visualization Update (Limited Availability): Split geographic data by categorical fields to display it as a pie chart and compare multiple categories on a single geographic view.

See About the Geo Map Visualization Type for more information.

Apr 15, 2026

ENHANCEMENT

calc Operator Update (Limited Availability): Use the new shannon_entropy information theory function to calculate an entropy score for any string field and identify unusual patterns in your event data.

See calc for more information.

Apr 15, 2026

ENHANCEMENT

timechart Operator Update (Limited Availability): Use addtotals=true to view a summary across all groups and time periods based on event counts across all groups and time buckets grouped by a field.

See timechart for more information.

Apr 15, 2026

FEATURE

OCSF Schema Support (Limited Availability): Use the Open Cybersecurity Schema Framework (OCSF) Version 1.2 schema and leverage OCSF-normalized event telemetry on the Anomali platform, alongside continued support for eventlog.

See OCSF Schema Overview for more information.

Mar 31, 2026

ENHANCEMENT

Visualization Type (Limited Availability): Use the frequency view in MITRE ATT&CK heatmaps to color techniques by how often they occur, with configurable gradients and tooltips.

See About the MITRE ATT&CK Heatmap Visualization Type for more information.

Mar 31, 2026

FEATURE

Lookup Tables (Limited Availability): Use the asset and investigation_elements lookup tables to display asset data populated from vulnerability scanners and perform consistent investigation querying and reporting.

See asset and investigation_elements for more information.

Mar 31, 2026

ENHANCEMENT

ARIMA Operator Update (Limited Availability): The updated ARIMA machine learning operator offers support for seasonal ARIMA that enables you to model and forecast daily, weekly, and other recurring patterns in security time‑series data.

See fit ARIMA for more information.

Mar 4, 2026

FEATURE

New Operator (Limited Availability): Use the Google Threat Intelligence (gti) operator to to enrich your observables with the latest Google Threat Intelligence verdicts and metadata.

See gti for more information.

Mar 4, 2026

FEATURE

Reports (Limited Availability): Export dashboard reports to turn your operational dashboards into repeatable, shareable outputs.

See Reports for more information.

Feb 19, 2026

ENHANCEMENT

CrowdStrike Operator Updates (Limited Availability): Use updated CrowdStrike operators that work with the new API replacing the now-decommissioned CrowdStrike Detects API.

See the CrowdStrike Operators documentation for more information.

Feb 19, 2026

ENHANCEMENT

ML Algorithm Updates (Limited Availability): Use the updated StandardScaler, DensityFunction, and OrdinalEncoder machine learning algorithms to leverage richer preserved context, improved downstream analysis, and reliable model interpretation.

See fit for more information.

Feb 18, 2026

ENHANCEMENT

Operator Updates (Limited Availability): The updated ml_model_summary machine learning operator offers an improved search results display for enhanced readability and usability.

See ml_model_summary for more information.

Feb 18, 2026

FEATURE

Visualization Type (Limited Availability): Use the Linear Regression visualization to explore how one or more independent variables relate to dependent variables across complex datasets.

See About the Linear Regression Visualization Type for more information.

Feb 4, 2026

FEATURE

Trigonometric Function (Limited Availability): Use the haversine function to identify geographically improbable logins by calculating the distance between sequential login events using geographical latitude-longitude pairs.

See calc Trigonometric functions for more information.

Jan 7, 2026

ENHANCEMENT

Automatic CEF, Key-Value Extractions: Automatically parse and extract JSON, Common Event Format, and key-value field pairs on-the-fly using dotted notation.

See Dotted notation for more information.

Jan 7, 2026

FEATURE

Role Based Access Control (Limited Availability): Access to user-created lookup tables can now be controlled through role-based access.

See Using Lookup Tables for more information.

Dec 10, 2025

FEATURE

New Operator: Use the IsolationForest operator to isolate anomalies in high-volume event data, based on an unsupervised anomaly-detection algorithm.

See fit IsolationForest for more information.

Dec 10, 2025

FEATURE

Role Based Access Control (Limited Availability): You can now access and control user-created macros through role-based access.

See Using Macros for more information.

Dec 10, 2025

FEATURE

Visualization Type (Limited Availability): Use the Decision Tree visualization to explore and interpret tree-based machine learning models as well as their results and better understand model logic, validate outcomes, and communicate insights to stakeholders .

See About the Decision Tree Visualization Type for more information.

Dec 10, 2025

ENHANCEMENT

Automatic JSON Field Extractions: Rapidly and flexibly view and use extracted fields in AQL queries to conduct downstream analysis without requiring the fields to be mapped to the standard Anomali eventlog schema.

See Extracted Fields for more information.

Dec 3, 2025

FEATURE

Visualization Type (Limited Availability): Use the Bubble Chart visualization to represent three dimensions of data and identify patterns or relationships across complex datasets.

See About the Bubble Chart Visualization Type for more information.

Nov 19, 2025

FEATURE

CrowdStrike Operators Update (Limited Availability): Use CrowdStrike operators to ensure CrowdStrike integration with the Anomali platform and interact with CrowdStrike data and services within the Anomali platform.

See the CrowdStrike Operators documentation for more information on the new CrowdStrike operators.

Oct 17, 2025

FEATURE

Full-Text Log Indexing (Limited Availability): Anomali Search now allows you to directly perform a keyword search on the raw message and ensures faster search results, while reducing the AVC units you consume.

See Full-Text Log Indexing for more information.

Oct 8, 2025

ENHANCEMENT

join Operator Update (Limited Availability): Compare string fields in joins for wildcard-based matching when joining data with dynamic lookup tables.

See join for more information.

Sep 24, 2025

FEATURE

Federated Search (Limited Availability): As an MSSP org admin, you can query and retrieve data across multiple managed organizations in a multi-tenancy fashion, while maintaining data isolation between them.

See Federated Search for more information.

Sep 10, 2025

FEATURE

Visualization Type (Limited Availability): You can now define and use system or custom variables in the text widget to dynamically populate its values based on AQL data or user-defined inputs.

See the About the Text Visualization Type for more information.

Sep 10, 2025

ENHANCEMENT

Bar Chart Visualization Update: You can now select or hide specific columns for plotting bar charts.

See About the Bar Chart Visualization Type for more information.

Sep 4, 2025

FEATURE

Visualization Type: Use the Timeline visualization type to visualize user and entity behavior in a timeline view in your dashboards.

See About the Timeline Visualization Type for more information.

Sep 4, 2025

FEATURE

Visualization Type: Use the MITRE ATT&CK Heatmap visualization type to add MITRE ATT&CK heatmaps to your dashboards.

See About the MITRE ATT&CK Heatmap Visualization Type for more information.

Sep 4, 2025

FEATURE

Visualization Type: Use the MITRE ATT&CK Flow visualization type to add panels with attack flows to your dashboards.

See About the MITRE ATT&CK Flow Visualization Type for more information.

Sep 4, 2025

FEATURE

Saved Search (Limited Availability): Using a new UI, save a search query for future use or leverage existing saved searches, including your history of searches, to issue a search.

See Using Saved Searches for more information.

Aug 26, 2025

FEATURE

Structured Search (Limited Availability): Use the structured query builder to create AQL Search queries by selecting different search components, without any prior knowledge of the AQL syntax.

See Anomali Search for more information.

Aug 26, 2025

FEATURE

Search Auto-Complete: Leverage the auto-complete suggestions to easily construct AQL Search queries.

See Anomali Search for more information.

Jul 29, 2025

ANNOUNCEMENT

Best Practice: Follow Anomali's recommendations to avoid wildcard matching on sourcetypes.

See Resolving error: "To optimize your experience and reduce your AVC usage, Anomali recommends reducing the time range to 24h to proceed." for more information.

Jul 29, 2025

FEATURE

New Operator: Use the superapi operator to perform GET, POST, PATCH, and DELETE requests to internal ThreatStream API endpoints directly from the AQL Search interface.

See superapi for more information.

Jul 16, 2025

ANNOUNCEMENT

Event Data Retention: Review the latest Anomali Search Data Retention Policy.

See Search Data Retention Policy for more information.

Jul 15, 2025

FEATURE

Copilot Widget (Limited Availability): Derive AI-powered insights on threat hunting, enrichments, threat actors, integrators, and more, using the Copilot widget in a dashboard containing multiple panels.

See About the Copilot Widget for more information.

Jul 2, 2025

ENHANCEMENT

timechart Operator Update: timechart operator now provides the makecontinuous flag to help you create empty buckets for time periods with no data.

See timechart for more information.

Jun 18, 2025

ANNOUNCEMENT

Best Practice: Follow Anomali's recommendations to optimize your search as well as reduce AVC usage for searches on the message field.

See Resolving error: "To optimize your experience and reduce your AVC usage, Anomali recommends reducing the time range to 24h to proceed." for more information.

Jun 16, 2025

FEATURE

Subsearch: Embed a search query within the main search that enable you to filter, manipulate, or correlate search results across multiple tables.

See Subsearch for more information.

Jun 16, 2025

FEATURE

Job Tracking: Monitor background jobs that you trigger by using turbosearch to search for more than 20 IOCs in your data.

See Job Tracking for more information.

Jun 13, 2025

FEATURE

Search: Use turbosearch to search for a list of indicators in your data, including historic and incoming data.

See turbosearch for more information.

Jun 13, 2025

FEATURE

Search Event Inspector: Use the search event inspector to inspect the details of the results of a search query.

See Exploring Results and Refining Queries for more information.

Mar 26, 2025

FEATURE

Views: Views allow you to create aliases for fields, enabling you to reference them directly in your search queries, just like regular fields.

See Views for more information.

Mar 17, 2025

FEATURE

Lookup Tables: View or search for ThreatStream observables and threat models from within AQL Search.

See observables and threat_models for more information.

Mar 13, 2025

ANNOUNCEMENT

Best Practice: Efficiently use the rex operator and json_extract of the calc operator to process large volumes of records following the steps Anomali recommends.

See AQL Best Practices for more information.

Mar 7, 2025

ENHANCEMENT

turbosearch Operator Update: turbosearch operator now supports six new fields, helping you search on more indicator types.

See turbosearch for more information.

Feb 20, 2025

ENHANCEMENT

riskiq_ssl Operator Update: riskiq_ssl operator is now rebranded to the mdti_ssl operator that enriches results related to an IP address or domain name using the ThreatStream MDTI enrichment.

See mdti_ssl for more information.

Feb 4, 2025

ENHANCEMENT

appendtable Operator Update: Perform a subsearch and append the results from both the searches together.

See appendtable for more information.

Jan 28, 2025

FEATURE

Anomali Virtual Compute: Anomali Virtual Compute (AVC) is a computing framework that measures your usage of virtualized infrastructure whenever you perform a compute operation.

See Anomali Virtual Compute for more information.

Jan 24, 2025

ANNOUNCEMENT

Best practice: Efficiently use the array_agg operator through data filtering and transformation by following the steps Anomali recommends.

See AQL Best Practices for more information.

Jan 23, 2025

ENHANCEMENT

convert Operator Update: Rotate a table such that the rows and column values are swapped, including the ability to specify the field to be used as a header.

See convert for more information.

Jan 17, 2025

ENHANCEMENT

aggr Operator Update: (Optional) Drill down into aggregated values obtained using the aggr operator to launch a new search with these values.

See aggr for more information.

Jan 8, 2025

ANNOUNCEMENT

Best Practice: Anomali recommends not using the join operator between eventlog data and system lookup tables such as iocmatch, since the join operation is not supported.

See join for more information.

Jan 3, 2025

ANNOUNCEMENT

Best Practice: Stagger any task that you can schedule to avoid overloading the system with too many scheduled jobs.

See AQL Best Practices for more information.

Jan 3, 2025

ENHANCEMENT

fields Operator Update: Optionally add a plus (+) or minus (-) sign to respectively include or exclude a comma-separated list of additional fields in the result table.

See fields for more information.

Jan 2, 2025

ENHANCEMENT

listinv Operator Update: Retrieve a list of ThreatStream investigations.

See listinv for more information.

Jan 2, 2025

ENHANCEMENT

fromjson Operator Update: Extract the top level keys from the JSON object and create a table with keys as column names and values as field values.

See fromjson for more information.

Jan 2, 2025

ENHANCEMENT

Dotted Notation Update: Operate on JSON fields to expedite its use other different operators, including JSON arrays using positional indexing.

See Dotted notation for more information.

Dec 19, 2024

ENHANCEMENT

streamstats Operator Update: Generate cumulative statistics for each event in your data, streaming up to the current event.

See streamstats for more information.

Dec 6, 2024

ENHANCEMENT

listindest Operator Update: List the configured Integrator destinations by integrator instance.

See lstintdest for more information.

Dec 6, 2024

ENHANCEMENT

loadjob Operator Update: Load events or results of a previously completed search job query.

See loadjob for more information.

Dec 6, 2024

ENHANCEMENT

inlist Operator Update: Check if a field value is present in a lookup table column.

See inlist for more information.

Dec 5, 2024

FEATURE

Visualization Type: Use the Gantt Time Series visualization type to analyze data based on date information and gain intelligence about events across specific timeframes.

See About the Gantt Time Series Visualization Type for more information.

Nov 5, 2024

FEATURE

Visualization Type: Use the Text visualization type to add Markdown-formatted text panels to your dashboards.

See About the Text Visualization Type for more information.

Nov 5, 2024

FEATURE

Macros: Use out-of-the-box macros to fetch and analyze ThreatStream data without building complex search queries.

See Using Macros (Classic UI)for more information.

Nov 5, 2024

FEATURE

Lookup Tables: Lookup tables are now generally available from the Search menu.

See Using Lookup Tables (Classic UI) for more information.

Oct 25, 2024

FEATURE

Macros: Create custom macros to avoid manually constructing lengthy strings of parameters for running complex search queries.

See Using Macros (Classic UI)for more information.

Oct 25, 2024

ENHANCEMENT

turbosearch Operator Update: Rapidly search through large datasets to identify threats in your events logged in the past using turbosearch. Note that the retrosearch operator is an alias of turbosearch and has the same behavior.

See Forensic and Retrospective Search for more information.

Oct 25, 2024

FEATURE

New Search APIs: Leverage AQL Search APIs to issue a new search, monitor its status, and receive the search results.

See the Using the Search RESTful API for more information.

Oct 16, 2024

ENHANCEMENT

calc Operator Update: Search for an event with any IP address using insubnet (*).

See calc for more information.

Oct 4, 2024

ENHANCEMENT

where Operator Update: Search for an event by checking multiple string values in a single field. Also, you can search for an event that contains any value in a field.

See where for more information.

Oct 4, 2024

FEATURE

Visualization Type: Use the Base64 visualization type to add images, video, audio, and PDF files to your dashboards.

See About Base64 Visualization Type for more information.

Oct 3, 2024

ANNOUNCEMENT

Best Practice: Follow new best practices for query optimization: Specify the smallest possible time range and use targeted search tables.

See AQL Best Practices for more information.

Sep 27, 2024

ENHANCEMENT

lookup Operator Update: Specify multiple lookup conditions. Also, now you can check whether an event matches the pattern specified in the lookup field.

See lookup for more information.

Sep 9, 2024

FEATURE

New Operators: Use the first and last aggregation functions to return first and last entry in a result set.

See calc for more information.

Sep 6, 2024

FEATURE

New Operator: Use the set operator to generate a table from two subsearches with a set operation applied to search results.

See set for more information.

Sep 6, 2024

ANNOUNCEMENT

Best Practice: Follow our recommendations on how to use the limit operator for better result accuracy.

See AQL Best Practices for more information.

Sep 5, 2024

FEATURE

New Operator: Use the fieldsummary operator to generate a summary of the output fields from the AQL.

See fieldsummary for more information.

Sep 5, 2024

FEATURE

New Operator: Use the snowincident operator to create an incident in ServiceNow.

See snowincident for more information.

Sep 5, 2024

FEATURE

New Operator: Use the anomalousvalue operator to compute an anomaly score for each field of each event, relative to the values of this field across other events.

See anomalousvalue for more information.

Sep 3, 2024

FEATURE

New Operator: Use the cluster operator to generate clusters of data based on similarity.

See cluster for more information.

Sep 3, 2024

FEATURE

New operator: Use the predict operator to make predictions for time series data.

See predict for more information.

Sep 3, 2024

ENHANCEMENT

calc Operator Update: The examples for the json_extract function have been updated.

See calc for more information.

Sep 2, 2024

ANNOUNCEMENT

Best Practice: Follow our recommendations on how to make your queries more efficient and save computing resources.

See AQL Best Practices for more information.

Aug 29, 2024

FEATURE

concurrency Operator: Use the concurrency operator to count the number of events with the spans that overlap with the start of each event.

See concurrency for more information.

Aug 22, 2024

FEATURE

Visualization Type: Use the Sankey diagram visualization type to display flows where the width of the lines is proportional to the flow rate.

See About the Sankey Diagram Visualization Type for more information.

Aug 16, 2024

FEATURE

Visualization Type: Use the Heatmap visualization type to quickly identify patterns, trends, and anomalies by displaying the data in a form of a matrix, where values are represented by varying colors.

See About the Heatmap Visualization Type for more information.

Aug 15, 2024

FEATURE

New Operator:Use the addinv operator to add elements to an existing ThreatStream investigation.

See addinv for more information.

Aug 15, 2024

FEATURE

New Operator: Use the outlier operator to modify numeric outputs for given input fields that contain outliers.

See outlier for more information.

Aug 15, 2024

FEATURE

New Operator: Use the transpose operator to create a pivot table for further use in visualizations.

See transpose for more information.

Aug 15, 2024

ENHANCEMENT

New Operator Update: The examples for the foreach operator have been updated.

See foreach for more information.

Aug 13, 2024

ANNOUNCEMENT

Visualization Type: When configuring any type of visualization, you can add relative URLs and URLs in ThreatStream and Security Analytics domains to its parts.

See Field Settings dedicated to a specific visualization type that supports adding URLs for more information.

Aug 13, 2024

FEATURE

New Operator: Use the anomalydetection operator to find outliers in numeric fields.

See anomalydetection for more information.

Aug 9, 2024

FEATURE

New Function: Use the mvzip function with the calc operator to create a new multivalue field with concatenated values from two other multivalue fields.

See calc for more information.

Aug 9, 2024

ENHANCEMENT

calc Operator Update: All timestamps are now calculated in milliseconds.

See calc for more information.

Aug 6, 2024

FEATURE

calc Operator Update: Use the uuid function with the calc operator to generate UUIDs.

See calc for more information.

July 29, 2024

FEATURE

New Operator: Use the contingency operator to generate a cross table to find the number of occurrences for the values of two fields.

See contingency (alias: ctable) for more information.

July 24, 2024

FEATURE

IOC Match Dashboard: The IOC Match Dashboard comprises a group of panels that threat hunters can use to get visibility into critical and trending IOC detections.

Feb 1, 2024

FEATURE

Ignite Dashboard: The Ignite Dashboard comprises a group of endpoint analytics panels that threat hunters can use to find what is happening around source hosts.

Feb 1, 2024

FEATURE

SOAR: Use alerts to add tags to ThreatStream observables or to send AQL results to a preferred destination. You can also use AQL operators to get or post columnar data.

Refer to AQL Operators by Use Case for an index of SOAR operators.

Feb 1, 2024

FEATURE

UEIBA: Anomali supports a rich set of algorithms including ARIMA (Autoregressive Integrated Moving Average, DBSCAN (Density-Based Spatial Clustering of Applications with Noise), k-means clustering, LinearRegression, LocalOutlierFactor, LogisticRegression, StandardScaler, and more.

Refer to AQL Operators by Use Case for an index of UEIBA operators.

Feb 1, 2024

FEATURE

AQL Search: Use AQL Search to perform searches and analytic functions on enterprise IT operations and security event logs, as well as lookup tables provided by Anomali or generated by analysts on your team.

See Anomali Search to understand how you can search event logs, system tables, and lookup tables, as well as create saved searches, dashboards, and alerts based on searches.

Feb 1, 2024