Skip to main content

Auto Parser GeneratorSite Collector Release Notes

Table of Contents

Site Collector Features Introduced in 2022

See the following topics for features introduced by month:

December 2022

The following features were introduced in Site Collectors during December 2022 (release 1.4).

Feature

Description

UDP Support

Site Collectors now support transport of logs over UDP. UDP is a faster and less resource intensive protocol that provides a higher EPS rate than TCP. You can now select the protocol UDP in addition to the default protocol TCP while setting up the Syslog Collector.

Splunk Cloud Support

Site Collectors now extend support for the Splunk collector to include log retrieval from your Splunk Cloud. The workflows to set up log ingestion from Splunk Cloud are the same as log ingestion from the on-premises Splunk Server.

November 2022

The following feature was introduced in Site Collectors during November 2022 (release 1.3).

Feature

Description

RHEL 8 and RHEL 9 Support

You can now deploy the Site Collectors on RHEL 8 and 9.

October 2022

The following feature was introduced in Site Collectors during October 2022 (release 1.2).

Feature

Description

Monitoring and Management

Through the Site Collector app, you can now monitor the health and status of the Site Collector and collector set up on the Site Collector. Additionally, you can stop, restart, or delete a collector through user interface.

August 2022

The following features were introduced in Site Collectors during August 2022 (release 1.1).

Feature

Description

Syslog Collector

You can now collect syslog logs from various sources such as Linux OS logs, FTP, and network, and push the logs to the Exabeam Security Operations Platform for further processing. The Syslog Collector helps to enable log onboarding from various sources.

10k EPS Support

Site Collectors now accept plain text or any single-line syslog events of various protocols such as RFC 5424, 5425, 5427, 5448 from the supported port range 1024 - 49151.

15k EPS Splunk

You can now ingest up to 15k EPS per Site Collector instance.

July 2022

The following features were introduced in Site Collectors during July 2022 (release 1.0).

Feature

Description

One-node Installation Support

Site Collectors now support one-node cluster setup with docker compose.

Splunk Collector

The Splunk Collector can now ingest logs in plain text, JSON, or Windows multiline format from your Splunk server and push the logs to the Exabeam Security Operations Platform.

LDAP Collector

The LDAP Collector now pulls context data from your active directory (AD) and pushes the data to the Exabeam Security Operations Platform for contextual data processing.

7k EPS support

You can now ingest up to 7k EPS events per Site Collector instance.

Basic Management and Monitoring

Site Collectors now provide basic monitoring and management over a centralized user interface.