Skip to content

Changelog

Update: 2026/07/17

FeaturesView latest logs and errors: With this release, users can now see latest logs flowing through the fabric for any given source. Often as a user, you want to see the actual logs as a way to visually confirm that the logs were received and are being parsed in the expected format. This release also adds the ability to view errors for any input feed from the console with the one click.

Integrations

  • New Source: Forcepoint Firewall Realm now supports ingesting Forcepoint Firewall logs in CEF format.
  • New Source: Corelight NDR Realm now supports ingesting Corelight Network Detection and Response (NDR) logs.
  • New Source: Custom CSV A flexible Custom CSV source is now available, allowing ingestion of arbitrary CSV-formatted log data.
  • New Destination: Google SecOps Realm can now forward logs to Google SecOps (formerly Chronicle),

Enhancements

  • Automatically appends the required suffix to Azure Event Hub namespaces when not specified by the user.
  • Fixed API validation errors when adding or editing top DNS entries in the UI.

Update: 2026/07/10

Features

  • Live metrics : When you select an input feed, the left panel now shows metrics in near real time as the data is flowing through the fabric, without needing to refresh the page.

Integrations

  • New Source: Salesforce Event Monitoring Realm now supports ingesting Salesforce Event Monitoring logs, enabling security teams to detect threats and audit activity across their Salesforce environment using Realm's detection and enrichment capabilities.
  • New Destination: Azure Blob Storage Realm now supports forwarding data to Azure blob storage.

Enhancements/Bug Fixes

  • Log optimization page now allows you to view total/average numbers over different time intervals.
  • Updated the Event Capture default to 1,000 events, providing broader diagnostic coverage out of the box.
  • Outbound email notifications now display "Realm.Security, Inc" as the sender name for better deliverability.
  • Fixed an issue where rules with unsaved changes could not be evaluated.

Update: 2026/06/30

Features

File Upload Users can now use the File upload feature to upload detection rules from their SIEM and share it securely with us. Realm uses the detection rules to ensure that the recommended volume reduction rules do not impact configured detections.

Enhancements

  • Fixed issues with Rule evaluations not showing the field values as columns and not highlighting the fields + values in the JSON event.

Update: 2026/06/24

Features

Enrichment: Greynoise: Greynoise threat intelligence is now available as an enrichment dataset within Realm, enabling IP reputation lookups directly inside the pipeline to surface context on known malicious or noisy internet activity.

Enhancements

  • Fixed an issue where the Azure Event Hub client could get stuck indefinitely after management or CBS connection failures.
  • Fixed Palo Alto CEF parser missing newline stripping, which caused malformed log entries in certain formats.
  • Fixed Fortigate logs not setting a source type when forwarding to Splunk, causing incorrect log classification.

Update: 2026/06/19

Enhancements

  • Fix Trim Field rule Charts inconsistencies
  • Fix to prevent Hex values from incorrectly getting converted to an int
  • Add Rule type and last updated columns to the log optimization table
  • Fix unnecessary re-rendering of rule side panel
  • Separate ingest volume and trend to a separate column on log optimization page

Update: 2026/06/18

Integrations

  • New Source: SentinelOne Standard Visibility Users can now ingest SentinelOne Standard visibility logs (in addition to Deep visibiity).
  • New Destination: Securonix SIEM Users can now configure and send data to Securonix from Realm.
  • New Destination: Databricks Users can configure and send data to Databricks from Realm. Data gets forwarded in Realm Data Lake format using Zerobus ingestion approach, which significantly reduces the steps a user needs to perform to enable the integration. By forwarding the data in Realm Data Lake format, we make the data instantly queryable/usable within Databricks saving a significant amount of data engineering time & effort a user needs to spend getting the data ready.

Enhancements

  • Log Optimizations UX Refactor: Major refactor of the Destination pages to improve usability and make it easier for customers to see savings per source and the rules that contribute to the savings.
  • Fixed trim and redact rules failing for raw XML field replacement.
  • Fixed parsing issue with custom syslog source.
  • Fixed Azure Event Hub client getting stuck after management/CBS authentication failures.

Update: 2026/06/12

Enhancements

  • Added additional Cisco FTD parsers for more event IDs, expanding coverage for Cisco Firepower Threat Defense log types.
  • Fixed serialized rules missing special field display for redact, dedupe, and trim rule types.
  • New Realm users are now automatically opted in to feed notification emails by default.
  • Exposed the compression field on S3 and Azure Blob Storage input feeds for easier configuration.
  • Added Forticlient event-type parsing support.

Update: 2026/06/02

Integrations

  • Ingesting on-premise custom application logs (JSON, CEF) via Collector
  • Ingesting Windows Event Logs (XML) over TCP via Collector
  • Documentation updates: Docs for various supported transport methods & dedicated docs for various AWS products.

Fixes & Enhancements

  • Crowdstrike NGSIEM: allow sending raw events to NGSIEM to leverage built in parsers and schema normalization
  • Collector UDP streams: allow configuring UDP streams on the collector

Update: 2026/05/22

Features

  • Data Composition: Users can now explore field-level data across their log sources directly within Realm. The Data Composition view surfaces top field keys and values, volume ratios by event type, and interactive filtering.
  • Event Schema: Along with showing the top field values and data distribution, a big part of Data composition is showing user the schema (field name, data types) of each of the sources all derived from observed data.

Update: 2026/04/19

Integrations

  • New Source: Proofpoint is now available as a log source in Realm.
  • New Destination: Rapid7 Insight IDR is now available as a destination in Realm.

Update: 2026/04/10

Features

  • In-product AI Risk Assessment: Realm's AI-generated risk assessments are now more deeply integrated into the product experience accessible via the Reduction tab for a given Destination. Going forwards every new Realm recommended rule will include a Rule Assessment section describing Risk and Considerations for the rule.
  • Trim Field Values: A new Metrics Chart view lets users track the impact of each trim rule over time.

Integrations

  • New Source: Mimecast Mimecast is now available as a log source in Realm.
  • New Source: GCP Logs Google Cloud Platform Logs can now be ingested into Realm via a GCP PubSub input feed. GCP Logs source supports numerous types of logs including Audit, Identity etc.

Enhancements

  • Smaller and consistent destination type icons on destination cards, toned-down background shades for a more refined look, and tooltip support for truncated source names on source cards.

Update: 2026/03/27

Features

  • Email Notifications: Product supports sending email notifications for Data Haven requests as well as Feed availability issues. For Data Haven, an email notification will be sent to the user that submitted the Resupply request when the data has been Gathered and also after the data has been Sent to the destination. For feed availability notifications, users will need to opt in from user settings page. An email notification will be sent when a feed transitions from being Healthy to Unhealthy and also from being Unhealthy to Healthy.
  • Trim Field Values: A new log reduction rule type that lets you trim field values before forwarding data to your destinations. Destination-level metrics now properly track reduction impact for trim and redact operations.

Integrations

  • New Source: Abnormal AI: Realm now support ingesting Abnormal AI logs into the product.
  • New Destination: Exabeam SIEM Customers can now configure and send their logs to Exabeam.

Enhancements/Bug fixes

  • Fixed a page crash when using custom date ranges in Fabric Health.
  • Fixed stream input feeds not updating the timezone when the setting was changed.
  • Fixed the home page time picker not displaying all active states correctly.
  • Azure Event Hub Resolved an issue where events from Azure Event Hub were not being de-batched correctly, ensuring reliable and complete ingestion of event streams.
  • Zscaler Cloud NSS — ZIA Adjust JSON parser.

Update: 2026/03/19

Integrations

  • Elastic & OpenSearch: Realm now supports sending data to Elastic & OpenSearch.
  • Zscaler NSS Cloud: Realm supports ingesting logs directly from Zscaler NSS Cloud. This approach simplifies log ingestion for Zscaler for customers that have a license for Zscaler NSS Cloud by removing the need to manage an intermediary VM.
  • Fortigate CEF format: Add support for ingesting Fortigate logs in CEF format.

Update: 2026/03/14

  • Enhancement: Volume reduction page will no longer show disabled rules. If you want to see disabled rules, you can use the new toggle to show disabled rules.

Update: 2026/03/02

  • Enhancement: Timezone support for collector streams.
  • Bugfix: "Top DNS Discard" rule only shows for compatible sources.
  • Enhancement: Collect host metrics for collector VM for observability.

Update: 2026/02/27

  • Enhancement: Enrichments - Preview enriched events before enabling an enrichment dataset for a source.
  • Enhancement: Event Captures - Cleanup expired event captures from the Event capture drop down to remove clutter.
  • Enhancement: Destination page redesign for usability.
  • Enhancement: Cisco FTD: Add support for DNS Majestic Million rule
  • New Integration: AWS Cloudtrail: Allow parsing of non-native Cloudtrail logs that are forwarded via a SIEM for example.

Update: 2026/02/20

  • New Integration: Hydrolix - Enable customers to send their security logs to Hydrolix Data Lake. Hydrolix is a datalake that allows customers to easily search and analyze their security data.
  • New Integration: Azure Event Hub: Allow customers to send logs from Azure Event Hub to Realm.
  • Enhancement: Event captures: Event captures should now be ready in seconds instead of minutes and more reliable even for sporadic data.

Update: 2026/02/17

  • New Feature: Enrichments: Allow customers to enrich log data with third party datasets to provide additional context such as Geolocation, IP Info etc. The log data is enriched in real time and the enriched data is available to be forwarded to all configured destinations including the archive. Forwarding enriched data to the archive is beneficial as a lot of the enrichment datasets are point in time and cannot be done retroactively. Enrichments is a fully managed feature, where Realm handles configuration, licensing and periodic refresh of the datasets.
  • New Integration: Akamai: Customers can send Akamai logs to Realm via SIEM Connector.
  • New Integration: Cloudflare: Customers can now send Cloudflare logs to Realm via Http log push.

Update: 2026/02/06

  • New Integration: Forticlient EMS: Allow customers to send Forticlient EMS logs to Realm via a collector.

Update: 2026/01/30

  • New Integration: Forticlient EMS: Allow customers to send Forticlient EMS logs to Realm via a collector.
  • New Integration: Cisco FTD: Update Cisco FTD source format enum & add parsers for EMBLEM format.
  • Bug Fix: Volume reduction round down to 0 on the landing page instead of showing -ve reduction.- Bug Fix: When selecting a different rule in the table on the Transforms page, the metrics panel does not refresh to show its metricsError writing metrics for new fabric nodes

Update: 2026/01/30

  • New Integration: Cloud HTTP Input feed: Support pushed based data ingest via HTTP web hookAzure Event Hub Source: Support ingesting
  • New Integration: Azure Event Hub events using AWS S3 as the input feed.
  • Bug Fix: Umbrella Scraper: improve efficiency of S3 list object iteration
  • Bug Fix: Rule preview segfaults when > 10 conditions exist
  • Bug Fix: MS Sentinel: Bad credentials should not crash the fabric

Update: 2026/01/23

  • Enhancement: Add Option for "View Health" in all Sources and Destinations pages
  • Enhancement: UX improvements for new theme and collapsible Main nav.
  • Enhancement: Insert "Unavailable only" toggle into Feed Availability header.
  • Enhancement: Add Observables for Windows Event Log during Data Haven resupply.
  • Bug Fix: Umbrella scraper pods unable to process data after being active for 30d.
  • Bug Fix: Do not set meta timestamp when sending events to Splunk.
  • Bug Fix: Several fixes around Event Capture workflow to prevent unintentional page refreshing/resetting.
  • Bug Fix: Ensure Redaction Rules do not show up in Log Reduction Page.
  • Bug Fix: Page becomes unresponsive after selecting a different time range on the feed availability page.

Update: 2026/01/13

  • Feature: Privacy Guard: Allows customers to redact field values in events before forwarding the events to a destination. The redaction rules are configured at the destination, so an un-redacted copy of the same event could be sent to an archive for instance if necessary.
  • Bug fixes: Small improvements/bug fixes.