Skip to content Skip to main navigation Skip to footer

Release Notes

V9.4.0.a Release Notes for Cyfin

Enhancements

  • Interactive Reports
    • Added option to disable password requirement for viewing interactive reports.
  • Hit/Visits
    • Enhanced hit/visit Algorithm
    • For log configurations with 3rd party categories, now still looking at Wavecrest categorization for hit/visit calculation.
  • Data Management – Log Data Source – SetupUpdated the syslog test page for better clarity when syslog server is accepting messages.

Corrections

  • AD Import by Field
    • Corrected the order of the nested fields as this was inverted.
    • Filter is now case insensitive
    • Filter is applied to entire AD import path. eg. If you had a group called Wavecrest with a subgroup of Development and you filtered on Development, the Wavecrest parent group would be missing.
  • Encoding
    • Fixed library to proper handle unicode characters in json encodings.
  • Logon Accounts
    • Fixed the manner in which the logon accounts modifications where being submitted from the interface to prevent browser size limitation.

V9.4.0 Release Notes for CyBlock Virtual Appliance

  • Enhancements
    • Report Templates
      • Ability to create a custom report using report templates
      • Ability to save custom report in CSV format
    • Reports
      • Running reports on a group will now include all the users in the subgroups as well. Previously only the users directly under the group were reported on.
      • Default URL format now Full URLs instead of single line.
    • Dashboard
      • Filtering dashboard data on a specific group will now include all the users in the subgroups as well. Previously only the users directly under the group were displayed.
    • PDF Writer
      • Updated PDF library
    • Active Directory
      • Added filter to importing by fields. Filtered data must be present in at least 1 of the fields for the user to be imported.
    • List
      • Optimized performance by reducing the number of timers it creates during basic lookup.
    • SSL Certs
      • Added ability to parse PEMKeyPair certificate data.
    • Blocking file extensions
      • Now checking content-disposition for actual filename when checking filename extensions
  • Corrections
    • Reports
      •  Corrected “Full URL” format not wrapping long URLs in IE and Firefox.
    • Report Timeframes
      • Corrected custom timeframe selection when editing report or creating new report in browser that is in different timezone than application server.
    • Dashboard
      • Removed duplicate data set for traffic when denied traffic is empty or only 1 series in data set.
      • Trend Charts not applying proper filter for the Enterprise group for Categories, Classifications and Traffic.
      • Color assignment for classifications when all 3 classifications are not present.
      • Updated x legend label for 24 hour time period that ends in the future to add the hour and minute of the current time.
      • Changed title when group filter is applied to be (Groupname) instead of – Groupname
      • Added Update Chart button when timeframe set to “Today”
      • Now showing group widget for additional top and trend charts.
      • Drilldown audit reports now default to Visits Only unless dashboard metric is hits.
    • PAC File
      • Removed invalid unprintable characters from PAC file template. This prevented the PAC file from matching entries accordingly.
      • Removed local copy of PAC file since PAC file content is stored in memory only.
    • Fixed typo in Monthly rotation selection in  Kiosk.

V9.4.0 Release Notes for Cyfin

Enhancements

  • Report Templates
    • Ability to create a custom report using report templates
    • Ability to save custom report in CSV format
  • Reports
    • Running reports on a group will now include all the users in the subgroups as well. Previously only the users directly under the group were reported on.
    • Default URL format now Full URLs instead of single line.
  • Dashboard
    • Filtering dashboard data on a specific group will now include all the users in the subgroups as well. Previously only the users directly under the group were displayed.
  • PDF Writer
    • Updated PDF library
  • Active Directory
    • Added filter to importing by fields. Filtered data must be present in at least 1 of the fields for the user to be imported.
  • List
    • Optimized performance by reducing the number of timers it creates during basic lookup.
  • SSL Certs
    • Added ability to parse PEMKeyPair certificate data.
  • Log formats
    • Updated Cisco Firepower logs to handle different username fields
      • Cisco FirePower
      • Cisco FirePower 6.3.0
    • Added Sophos XG
    • Added Juniper SRX
    • Updated help link for Forefront TMG (SQL Server Express)
    • Updated Syslog r80.10
      • alternate to parse both regular id and email address in user id field.
      • trim username field to remove extra spaces
  • Log
    • Ability to download log data
  • Log Parser
    • Fixed add current year flag to take into account possible
    • MT time which could lead to incorrect year being set.

Corrections

  • Reports
    •  Corrected “Full URL” format not wrapping long URLs in IE and Firefox.
  • Report Timeframes
    • Corrected custom timeframe selection when editing report or creating new report in browser that is in different timezone than application server.
  • Dashboard
    • Removed duplicate data set for traffic when denied traffic is empty or only 1 series in data set.
    • Trend Charts not applying proper filter for the Enterprise group for Categories, Classifications and Traffic.
    • Color assignment for classifications when all 3 classifications are not present.
    • Updated x legend label for 24 hour time period that ends in the future to add the hour and minute of the current time.
    • Changed title when group filter is applied to be (Groupname) instead of – Groupname
    • Added Update Chart button when timeframe set to “Today”
    • Now showing group widget for additional top and trend charts.
    • Drilldown audit reports now default to Visits Only unless dashboard metric is hits.
  • Syslog
    • Updated decoder method used to decode syslog filter which corrects the filter not being set properly.
  • Fixed typo in Monthly rotation selection in  Kiosk.

v9.3.3.a Release Notes for Cyfin

Enhancements

  • Log Configurations. Updated Sophos (Astaro Security Legacy) log configuration to include useragent and referer.
  • Syslog Status. Added proper name for direct import handler and palo alto firewall handler. Previously these were just illegible object references.
  • Syslog Daemon. Replaced syslog library used when running syslog servers to a newer more advanced library. This new library increases the amount of data our syslog server can handle and can also be scaled.
  • Hits Visits Calculation. The reporter will now check the list for entries that are from known content providers and thus should always be considered hits.
  • Disk Usage Monitor. Added task to monitor disk usage on both product and metric server and email administrator if any disk usage exceeds 90%.
  • Logfile Configuration Wizard. Increased the efficiency of the log record analyzer when configuring logs which leads to quicker results.
  • Server Information screen
    • Replaced Product Disk Usage and Disk Space Available entries with single Product Root Disk Usage entry. The value for the new entry is listed as dd% (n.n free out of mm) where dd is used percentage.
    • Added Metric server disk usage section (Data Disk Usage) where we list the disk usage by the product as well as all configured metric servers. The entries are listed as key value pairs where the key is name(ip) and the value is listed as dd% (n.n free out of mm) where dd is used percentage.

Corrections

  • Hits Visits Calculation. Fixed issue with direct import of syslog data that was making all web requests hit instead of properly assessing visit probability. This was because the supplemental category was not being set properly.
  • Syslog Daemon. Line breaks are now removed from incoming syslog messages. The breaks were causing problems with regex in the log parser.

9.3.4 Release Notes for CyBlock Software & Virtual Appliance

Enhancements

  • Secure Interface. Added ability to configure custom SSL Certificate or re-new Wavecrest certificate. When Wavecrest certificate is used, a link is now provided to install the root certificate authority in order for browsers to show certificate as valid.
  • Live Chat. Renamed the “Live Support” tab in the top bar to “Live Chat”. This tab was only visible to licensed products, but is now available to all products and licenses. The chat widget that loads on each page is now visible for normal evaluation keys as well as full evaluation keys.
  • Time Frame Selection. Added new “Today” option for Time Frame Date Range selection in reports and dashboard charts. This option will include data for the entire current day. eg: Mar 24 00:00:00 to Mar 24 23:59:59.

v9.3.4 Release Notes for Cyfin

Enhancements

  • Log Configurations Wizard. When configuring a syslog data source, the product will now wait for data to start flowing through the syslog server, before attempting to analyze the records against known configurations. This will prevent the product incorrectly informing the user that the syslog data did not match any configurations.
  • Support – Patch. Created new screen to add custom log configurations provided by support to the product.
  • Syslog. Updated the syslog daemon to make use of multiple threads instead of single thread when running with protocol UDP. This should improve the performance and capabilities of the UDP syslog engine.
  • Syslog Status. Updated the syslog status information screen to reflect the number of threads that are listening (IsAlive)
  • Secure Interface. Added ability to configure custom SSL Certificate or re-new Wavecrest certificate. When Wavecrest certificate is used, a link is now provided to install the root certificate authority in order for browsers to show certificate as valid.
  • Live Chat. Renamed the “Live Support” tab in the top bar to “Live Chat”. This tab was only visible to licensed products, but is now available to all products and licenses. The chat widget that loads on each page is now visible for normal evaluation keys as well as full evaluation keys.
  • Time Frame Selection. Added new “Today” option for Time Frame Date Range selection in reports and dashboard charts. This option will include data for the entire current day. eg: Mar 24 00:00:00 to Mar 24 23:59:59.

Corrections

  • Server Information. Corrected the Data Disk Usage information to reflect the data drive for the product instead of root. This changed was also applied to the disk usage monitor.
  • Audit Summary Reports. Adjusted the report query to not include entries that are hit only.
  • Submitting Reports. Removed raw log file check when submitting reports. This check relied on log file data that may not be current and was incorrectly preventing reports from being submitted.