Skip to content

Dec 19, 2023 · @Dakostu · #3731

The new geoip context is a built-in that reads MaxMind DB files and uses IP values in events to enrich them with the MaxMind DB geolocation data.

Add support for macOS-style syslog messages

Section titled “Add support for macOS-style syslog messages”

Dec 18, 2023 · @eliaskosunen · #3692

The syslog parser now supports macOS-style syslog messages.

Dec 14, 2023 · @mavam · #3727

The tcp connector is now also a saver in addition to a loader.

Dec 13, 2023 · @jachris · #3646

The kv parser splits strings into key-value pairs.

Dec 12, 2023 · @eliaskosunen · #3683

The grok parser, for use with the parse operator, enables powerful regex-based string dissection.

Dec 12, 2023 · @mavam · #3521

With the new processes and sockets source operators, you can now get a snapshot of the operating system processes and sockets as pipeline input.

Dec 12, 2023 · @tobim · #3675

show partitions now contains location and size of the store, index, and sketch files of a partition, as well the aggregate size at diskusage.

Dec 8, 2023 · @dominiklohmann · #3723

show operators now shows user-defined operators in addition to operators that ship with Tenzir or as plugins.

Dec 7, 2023 · @dominiklohmann · #3703

The slice operator keeps a range of events within a half-closed interval. Begin and end of the interval can be specified relative to the first or last event.

Add support for macOS-style syslog messages

Section titled “Add support for macOS-style syslog messages”

Dec 18, 2023 · @eliaskosunen · #3692

The events created by the RFC 3164 syslog parser no longer has a tag field, but app_name and process_id.

Dec 18, 2023 · @jachris · #3742

Records can now have fields where the name is empty.

Dec 12, 2023 · @mavam · #3521

The show operator now always connects to and runs at a node. Consequently, the version and nics aspects moved into operators of their own.

Dec 18, 2023 · @dominiklohmann · #3743

Pipeline operators blocking in their execution sometimes caused results to be delayed. This is no longer the case. This bug fix also reduces the time to first result for pipelines with many operators.