New integrations in GA 🎉

✅ The following intakes are now officially available in GA:

⚠️ Mimecast Email Security important change

To prevent IP blocking issues with Mimecast APIs due to repeated authentication errors, we are modifying the following behavior with these 2 intakes:

  • Before: Authentication errors were considered as ERROR level
  • After: Authentication errors will be considered as CRITICAL level

This modification signifies that after 5 failed authentication attempt, the intake will be automatically stopped.
A grace period of 30 minutes is applied meaning that after 30 minutes, the error counter is resetted to zero if no new errors occured.

🗓️ This update will be applied on January 14th around 12:00 CET.

⚠️ Fortinet Fortigate important change

A timezone issue has been identified with certain Fortigate events (specifically those containing a timestamp field), which may cause events to be incorrectly dated in the future.

To resolve this issue, we are implementing two fixes:

  • Events with a timestamp field will now use their native timezone for timestamp calculations
  • When available, the eventtime field will be prioritized as the primary timestamp source

Please note: These corrections may affect the chronological distribution of events on the timeline, as some event timestamps will be adjusted to their accurate times.

🗓️ This corrective update will be applied on January 21th around 12:00 CET.

What do you think about this update?