The security data pipeline engine that collects security telemetry, normalizes events to OCSF, and offers an open data lake for storage.
GitHub- v5.23.0
This release introduces centralized node-level TLS configuration, allowing you to configure TLS settings once in tenzir.yaml instead of passing options to each operator individually. It also adds support for event-timestamp-based compaction rules and a count field in the deduplicate operator.
- v5.22.2
This release fixes a performance regression when parsing lists with mixed-type elements, where batch processing was inadvertently broken. It also resolves an assertion failure that could crash Tenzir when encountering events with duplicate keys.
- v5.22.1
This release fixes a bug where the
publishoperator could drop events. - v5.22.0
This release introduces support for arguments in user-defined operators, letting operators declare positional and named parameters with optional default values and use them just like built-in operators. It also enhances parser behavior for duplicate keys and includes several important stability, ...
- v5.21.2
This is a bugfix release that fixes timestamp handling in the python operator and the backpressure handling in publish and subscribe.
- v5.21.1
This release features new and improved hash functions as well as a couple of bugfixes.
- v5.21.0
This release improves the stability of pipelines by applying backpressure more effectively, ensuring upstream components slow down before overwhelming subscribers. It also enhances daily operations by improving parquet reliability, adding Base58 support, and extending the built-in OCSF operators ...
- v5.20.2
This release backports the changes made in v5.21.1 to v5.20.1.
- v5.20.1
This patch release comes with a few new experimental memory metrics. Furthermore, it resolves an issue where the memory usage would grow without bounds on some systems.
- v5.20.0
We continue our quest for better memory usage by switching out the memory allocator to the battle-tested
mimalloc, as well as adding metrics collecting for memory usage. - v5.19.0
This release introduces the
ocsf::castoperator to streamline schema transformations for OCSF events and adds support for one-level recursion in OCSF objects, enabling recursive relations such asprocess.parent_processandanalytic.related_analytics. - v5.18.0
This release focuses on improving performance and memory usage. Pipelines are now faster, especially when using if conditions or parsing highly heterogeneous events. Memory usage has also been substantially reduced.
- v5.17.0
This release introduces user-defined operators in packages, allowing you to extend Tenzir with custom operators defined in TQL files. It also adds list manipulation functions, a recursive search function, and improved memory management.
- v5.16.0
This release brings forth stability improvements under high load that could cause platform unresponsiveness, fixes API request isolation problems, better kafka diagnostics and more.
- v5.15.0
This release enhances TQL's data transformation capabilities with lambda expressions that can capture surrounding fields in
mapandwherefunctions, plus grouped enumeration for separate event counting. We've also improved operator composability with enhancedto_splunkparameters, added oct... - v5.14.0
This release introduces an integration fo SentinelOne Singularity™ Data Lake and a new message based
to_kafkaoperator that features a one to one event to message relation. - v5.13.2
This release adds a new S3 operator and fixes a bug within the
forkoperator. - v5.13.1
This release adds a new Azure Blob Storage operator with account key authentication and improves Google Security Operations retry handling. It also contains various small fixes and improvements.
- v5.13.0
This release enhances UDP ingestion with the new
from_udpoperator that produces structured events with sender metadata. We also improved the execution model foreveryandcronsubpipelines, added DNS lookup capabilities, and made the Syslog parser more flexible. - v5.12.1
We fixed two bugs in the
to_google_secopsandto_amazon_security_lakeoperators. - v5.12.0
This release adds support for OCSF 1.6.0 and introduces the
replaceoperator. - v5.11.1
This release introduces payload compression for Azure Log Analytics to reduce bandwidth usage, as well as an important fix for a
from_httpbug that was introduced with the previous release. - v5.11.0
This release delivers significant performance improvements for situations with many concurrent pipelines, making Tenzir more robust under high-load scenarios. New features include AWS role assumption support, enhanced string trimming functionality, and improved HTTP error handling capabilities. A...
- v5.10.0
This release introduces two new powerful OCSF operators that automate enum derivation and provide intelligent field trimming. The update also includes string padding functions, better HTTP requests, IP categorization and much more!
- v5.9.0
This release brings a family of UUID functions to TQL, making it easier to generate random numbers for a variety of use cases.
- v5.8.0
This release introduces format and compression inference from URLs for HTTP data sources, streamlining data loading workflows. It also includes bug fixes for secret resolution and HTTP server mode.
- v5.7.0
Tenzir Node v5.7.0 introduces a new secret type that keeps its sensitive content hidden while enabling flexible secret retrieval. This release also adds support for OCSF extensions and brings several improvements to the operator.
- v5.6.1
This release restores an aggregation function that was accidentally made unavailable in Tenzir Node v5.6.0.
- v5.6.0
The operator now supports event-dependent topics, making routing between pipelines more flexible. Additionally, new and operators make taking apart custom logs easier than before.
- v5.5.0
Built-in support for normalizing OCSF events to their upstream schema makes normalizations easier than ever with Tenzir Node v5.5.
- v5.4.1
This release fixes a bug within the JSON printer that could lead to invalid JSON being produced, and also led to response timeouts when using the Tenzir Platform.
- v5.4.0
With the introduction of format strings to TQL, this release makes string construction from multiple parts easier than ever before.
- v5.3.4
This release fixes a bug that caused package installation outside of the Tenzir Library to fail, which caused Demo Nodes in the Tenzir Platform to not have any packages installed.
- v5.3.3
The from_http and http operators now support response sizes upto 2GiB
- v5.3.2
Tenzir Node v5.3.1 updated the pyproject version but did not actually commit it, causing the Python operator to fail to start. This release fixes the issue.
- v5.3.0
This release brings forth improvements to HTTP support in Tenzir, supporting requests as transformations and paginating APIs.
- v5.2.0
- v5.1.8
- v5.1.7
- v5.1.6
- v5.1.5
- v5.1.4
- v5.1.3
- v5.1.2
- v5.1.1
- v5.1.0
- v5.0.1
- v5.0.0
- v4.32.1
- v4.32.0
- v4.31.2
- v4.31.0
- v4.30.3
- v4.30.2
- v4.30.1
- v4.30.0
- v4.29.2
- v4.29.1
- v4.29.0
- v4.28.2
- v4.28.0
- v4.27.0
- v4.26.0
- v4.25.0
- v4.24.1
- v4.24.0
- v4.23.1
- v4.23.0
- v4.22.2
- v4.22.1
- v4.22.0
- v4.21.1
- v4.21.0
- v4.20.3
- v4.20.2
- v4.20.1
- v4.20.0
- v4.19.6
- v4.19.5
- v4.19.4
- v4.19.3
- v4.19.2
- v4.19.1
- v4.19.0
- v4.18.5
- v4.18.4
- v4.18.3
- v4.18.2
- v4.18.1
- v4.18.0
- v4.17.4
- v4.17.3
- v4.17.2
- v4.17.1
- v4.17.0
- v4.16.0
- v4.15.2
- v4.15.1
- v4.15.0
- v4.14.0
- v4.13.1
- v4.13.0
- v4.12.2
- v4.12.1
- v4.12.0
- v4.11.2
- v4.11.0
- v4.10.4
- v4.10.3
- v4.10.1
- v4.10.0
- v4.9.0
- v4.8.2
- v4.8.1
- v4.8.0
- v4.7.1
- v4.7.0
- v4.6.4
- v4.6.3
- v4.6.0
- v4.5.0
- v4.4.0
- v4.3.0
- v4.2.0
- v4.1.0
- v4.0.1
- v4.0.0
- v3.1.0
- v3.0.4
- v3.0.3
- v3.0.2
- v3.0.1
- v3.0.0
- v2.4.2
- v2.4.1
- v2.4.0
- v2.3.1
- v2.3.0
- v2.2.0
- v2.1.0
- v2.0.0
- v1.1.2
- v1.1.1
- v1.1.0
- v1.0.0