# Release Notes — 2.79 Covers the **2.79** release series. Most recent patch: **2.79.1**. _Unless a subsection says otherwise, changes apply to both Monad SaaS and self-hosted._ ## New features & improvements **SaaS & self-hosted** - **Alerts name the pipeline and component they are about** — alert payloads now carry human-readable names next to the IDs: `resource_name` (the pipeline, or the component for a node alert) and `parent_name` (the pipeline a component belongs to), so Slack, PagerDuty and webhook notifications can show names instead of IDs. (2.79.1) - **Databricks Lakehouse output: much shorter flush intervals** — each write mode now has its own batch settings. ZeroBus can flush as often as every second (default 10 seconds), and Autoloader as often as every 15 seconds; both were previously limited to 5 minutes. Existing outputs were moved to the new layout automatically. [Docs →](https://app.monad.com/docs/outputs/databricks-lakehouse) (2.79.1) - *Access:* set the interval under the output's **Write mode → Batch config** (`settings.write_mode..batch_config.publish_rate` in the API and Terraform). - **Clearer setup docs for connectors that send a raw auth header** — the HTTP, OpenTelemetry and IBM QRadar outputs and the Monad GraphQL input now say which header name to set and that the full header value (including any scheme such as `Bearer`) goes in the secret. [Docs →](https://app.monad.com/docs/outputs/http) (2.79.1) **Self-hosted only** - **AWS web-identity federation docs cover the API service account** — the AWS guide now explains trusting the API's service-account subject so **Test connection** works for role-based AWS connectors. [Docs →](https://app.monad.com/docs/inputs/aws/index) (2.79.1) - **Cluster sizing guide lists the minimum Helm chart version** it applies to. [Docs →](https://app.monad.com/docs/guides/cluster-sizing) (2.79.1) ## New connectors - **Neat Pulse Audit Logs (input) — Beta** — ingests organization, device and user administrative actions from Neat Pulse, so changes across your Neat video-conferencing fleet reach your SIEM. [Docs →](https://app.monad.com/docs/inputs/neat-pulse/neat-pulse-audit-logs) (2.79.1) - **Microsoft Sentinel Threat Intelligence (output) — Beta** — uploads STIX 2.0/2.1 threat-intelligence objects (indicators, attack patterns, threat actors, identities, relationships) to a Microsoft Sentinel workspace through the Threat Intelligence Upload API, so threat feeds collected in Monad land directly in Sentinel. [Docs →](https://app.monad.com/docs/outputs/msft-sentinel-threat-intelligence) (2.79.1) ## Fixes - **Panther output no longer rejected for oversized requests** — batches now stay under Panther's 1 MB request limit, so deliveries stop failing with HTTP 413. (2.79.1) - **Google Cloud Storage input accepts base64-encoded credentials** — credentials in base64 form passed validation but were not used to authenticate; they now work. (2.79.1) - **Google inputs' synthetic test data matches real records** — test data now has the same shape as the records the live connectors emit. (2.79.1) - **CEF conversion writes to current Sentinel columns** — the CommonSecurityLog preset of the `convert_cef` transform now maps `cn1`–`cn3` and `externalId` to the live CommonSecurityLog columns instead of deprecated ones. (2.79.1) - **Pipeline configuration changes apply promptly** — an edit made while a platform update was rolling out could wait its turn behind the rollout; it now applies right away. (2.79.1) - **Pipeline node status no longer flaps** — node status stopped flickering between states. (2.79.1) ## Breaking changes - **API rejects unknown fields in component settings and secrets** — creating or updating an input, output, transform or enrichment through the API or Terraform now fails when `settings` or `secrets` contains a key that connector does not define; such keys used to be silently ignored. **Action:** remove any keys the connector does not define — the error names the field. (2.79.1) - **Terraform and API: the Microsoft Defender for Endpoint Alerts input has a new type ID** — the type ID changed from `endpoint-alerts` to `microsoft-defender-endpoint-alerts`. Existing inputs were updated automatically and keep running, and the Monad UI is unaffected. **Action:** if you manage this input with Terraform or the API, change its type to `microsoft-defender-endpoint-alerts` so plans don't show drift. (2.79.1) ## Need help? See the [Monad docs](https://app.monad.com/docs) for setup guides and reference, or reach out to Monad Customer Support at [support@monad.com](mailto:support@monad.com) or via your dedicated Slack customer channel. :::note Self-hosted deployments upgrade to a `2.79.x` release with `helm upgrade`. Review the **Breaking changes** section above before upgrading; when it says "None," the upgrade is drop-in. :::