Release Notes
Release Notes — 2.79
Covers the 2.79 release series. Most recent patch: 2.79.1.
Unless a subsection says otherwise, changes apply to both Monad SaaS and self-hosted.
New features & improvements
SaaS & self-hosted
- Alerts name the pipeline and component they are about — alert payloads now carry human-readable names next to the IDs:
resource_name(the pipeline, or the component for a node alert) andparent_name(the pipeline a component belongs to), so Slack, PagerDuty and webhook notifications can show names instead of IDs. (2.79.1) - Databricks Lakehouse output: much shorter flush intervals — each write mode now has its own batch settings. ZeroBus can flush as often as every second (default 10 seconds), and Autoloader as often as every 15 seconds; both were previously limited to 5 minutes. Existing outputs were moved to the new layout automatically. Docs → (2.79.1)
- Access: set the interval under the output's Write mode → Batch config (
settings.write_mode.<mode>.batch_config.publish_ratein the API and Terraform).
- Access: set the interval under the output's Write mode → Batch config (
- Clearer setup docs for connectors that send a raw auth header — the HTTP, OpenTelemetry and IBM QRadar outputs and the Monad GraphQL input now say which header name to set and that the full header value (including any scheme such as
Bearer) goes in the secret. Docs → (2.79.1)
Self-hosted only
- AWS web-identity federation docs cover the API service account — the AWS guide now explains trusting the API's service-account subject so Test connection works for role-based AWS connectors. Docs → (2.79.1)
- Cluster sizing guide lists the minimum Helm chart version it applies to. Docs → (2.79.1)
New connectors
- Neat Pulse Audit Logs (input) — Beta — ingests organization, device and user administrative actions from Neat Pulse, so changes across your Neat video-conferencing fleet reach your SIEM. Docs → (2.79.1)
- Microsoft Sentinel Threat Intelligence (output) — Beta — uploads STIX 2.0/2.1 threat-intelligence objects (indicators, attack patterns, threat actors, identities, relationships) to a Microsoft Sentinel workspace through the Threat Intelligence Upload API, so threat feeds collected in Monad land directly in Sentinel. Docs → (2.79.1)
Fixes
- Panther output no longer rejected for oversized requests — batches now stay under Panther's 1 MB request limit, so deliveries stop failing with HTTP 413. (2.79.1)
- Google Cloud Storage input accepts base64-encoded credentials — credentials in base64 form passed validation but were not used to authenticate; they now work. (2.79.1)
- Google inputs' synthetic test data matches real records — test data now has the same shape as the records the live connectors emit. (2.79.1)
- CEF conversion writes to current Sentinel columns — the CommonSecurityLog preset of the
convert_ceftransform now mapscn1–cn3andexternalIdto the live CommonSecurityLog columns instead of deprecated ones. (2.79.1) - Pipeline configuration changes apply promptly — an edit made while a platform update was rolling out could wait its turn behind the rollout; it now applies right away. (2.79.1)
- Pipeline node status no longer flaps — node status stopped flickering between states. (2.79.1)
Breaking changes
- API rejects unknown fields in component settings and secrets — creating or updating an input, output, transform or enrichment through the API or Terraform now fails when
settingsorsecretscontains a key that connector does not define; such keys used to be silently ignored. Action: remove any keys the connector does not define — the error names the field. (2.79.1) - Terraform and API: the Microsoft Defender for Endpoint Alerts input has a new type ID — the type ID changed from
endpoint-alertstomicrosoft-defender-endpoint-alerts. Existing inputs were updated automatically and keep running, and the Monad UI is unaffected. Action: if you manage this input with Terraform or the API, change its type tomicrosoft-defender-endpoint-alertsso plans don't show drift. (2.79.1)
Need help?
See the Monad docs for setup guides and reference, or reach out to Monad Customer Support at support@monad.com or via your dedicated Slack customer channel.
Self-hosted deployments upgrade to a 2.79.x release with
helm upgrade. Review the Breaking changes section above before upgrading;
when it says "None," the upgrade is drop-in.
Last modified on