# Release Notes — 2.85 Covers the **2.85** release series. Most recent patch: **2.85.1**. _Unless a subsection says otherwise, changes apply to both Monad SaaS and self-hosted._ ## New features & improvements **SaaS & self-hosted** - **Component settings shown as a structured tree** — the configuration panel on input, output, transform and enrichment detail pages now lays settings out as an expandable tree, with secrets and nested fields clearly marked. (2.85.1) - **Clearer Elasticsearch connection errors** — when Test connection or pipeline startup can't reach the cluster, the error now includes the HTTP status and response, so bad credentials, a missing cluster privilege and a proxy block are easy to tell apart. (2.85.1) - **Least-privilege IAM policies for the SQS S3 inputs** — the SQS S3, SQS S3 CloudTrail and SQS S3 GuardDuty pages now list only the four AWS actions the connectors call, with a copy-paste trust policy scoped to your queue and bucket. [Docs →](https://app.monad.com/docs/inputs/aws/aws-sqs-s3) (2.85.1) - **Alert scope clarified** — the alert docs now state that pipeline-scoped rules cover enabled pipelines only, and that a threshold rule treats a pipeline with no data in the window as 0, so it can catch a source that stopped sending. [Docs →](https://app.monad.com/docs/alerts) (2.85.1) - **Organization Logs contents defined** — the Organization Logs input page now spells out what API Logs and Pipeline Logs contain. [Docs →](https://app.monad.com/docs/inputs/monad/monad-logs) (2.85.1) - **Security guide: AWS access and buffered data** — the security guide now explains how Monad assumes and handles your cross-account AWS role, and how records are buffered until they are delivered or purged. [Docs →](https://app.monad.com/docs/guides/security) (2.85.1) - **Panther HTTP output: batching and size limits documented** — covers Panther's 1 MB request limit and what a 413 response means. [Docs →](https://app.monad.com/docs/outputs/panther-http) (2.85.1) **Self-hosted only** - **AWS web-identity federation is a one-time hand-off** — the AWS guide now shows that Monad needs your web-identity role ARN once, and that new target roles and AWS accounts are then yours to add without involving Monad. [Docs →](https://app.monad.com/docs/inputs/aws/index) (2.85.1) ## New connectors None. ## Fixes - **Elasticsearch output no longer loses records on failed bulk writes** — write failures that were missed are now caught and retried, and an invalid index name is rejected when you save the output instead of failing on write. (2.85.1) - **CrowdStrike inputs with cloud autodiscover reach the right region** — data requests now go to your tenant's regional API, and bad credentials are reported when the input starts. (2.85.1) - **Snyk Issues input no longer skips issues** — issues updated within a second of the previous poll were missed; they are now collected. (2.85.1) - **Dialpad Change Log input receives webhook events** — events sent to the input's webhook now reach the pipeline. (2.85.1) - **MCP server image patched** — critical and high container vulnerabilities in the Monad MCP server image are resolved. (2.85.1) ## Breaking changes None. ## Need help? See the [Monad docs](https://app.monad.com/docs) for setup guides and reference, or reach out to Monad Customer Support at [support@monad.com](mailto:support@monad.com) or via your dedicated Slack customer channel. :::note Self-hosted deployments upgrade to a `2.85.x` release with `helm upgrade`. Review the **Breaking changes** section above before upgrading; when it says "None," the upgrade is drop-in. :::