AI-Powered Security Operations Coming to Your EnvironmentWe're excited to announce the rollout of Devo AI Assist, a powerful new addition to the Devo platform that transforms how security teams interact with their data and streamlines operations.What is Devo AI Assist?Devo AI Assist is an intelligent assistant that enables you to interact with the Devo platform using natural language. Instead of learning complex query syntax or navigating through multiple screens, simply describe what you want to accomplish, and Devo AI Assist will execute the appropriate actions for you.Key Capabilities🔍 Natural Language Security Queries"Hunt for indicators of lateral movement in our network" "Show me authentication failures from high-risk countries" "Analyze privileged account activity for insider threats" "Generate compliance reports for our critical assets"⚡ Intelligent Workflow ExecutionAutomatically creates dashboards, Activeboards, and alerts Generates optimized LINQ queries from your descripti
The Devo Relay is a critical feature of Devo that receives inbound events from your data sources and then sends them to your Devo instance with all the tagging and processing rules that make Devo work as fast as it does. Release 2.15.1 adds automations and new OS support. The first automation added removes the additional steps to launch the relay after setup. With this next feature, all certificates will automatically renew 1.5 months before expiration. This is a huge usability improvement and greatly received! Lastly, support for Ubuntu 24, aka Noble Numbat, and support for Ubuntu 20 has been retired. Learn more below! Table of ContentsEnhancements Automatic activation Automatic renewal of Relay Certificates Support for Ubuntu 24 Removed support for Ubuntu 20 Bug Fixes Source tag capture groups EnhancementsAutomatic activationThe relay is now automatically activated after setup. No need to go to the UI to click on the activation button.Learn more in our documentation Autom
The Devo Collector team is happy to present the latest release of the Cloud Collector. Release 1.5.0 introduces significant enhancements to the Cloud Collector vertical application that provide greater visibility and control over your collector infrastructure. This release introduces unified viewing capabilities for both self-service and legacy collectors within a single interface. Now you can manage your full collector inventory, manage and plan migrations of old collectors into the new infrastructure, and directly operate your ingestion architecture. Review your collectors with the Cloud Collector app, and if you still have older collectors, plan those migrations! Geo AvailabilityRegion Status CA Released US Released EU Released APAC Released Table of ContentsNew Features Enhanced Collector Visibility Important Notes Legacy Collector Functionality Upgrade Path Benefits Improved Operational Visibility Streamlined Migration Planning Getting Started Support New Fe
The Devo Security Alerts team has published OOTB Alerts Release 36! This release delivers improvements to 577 Out-of-the-Box (OOTB) alerts, representing the entire OOTB alert catalog available to you from Devo Exchange. Release 36 focuses on 3 themes: Optimized query performance, Integration of device data, and restructuring of mm2 operations to use the new functions. These updates provide more precise, faster, and actionable alerting, improving your overall security posture. To access this content, Devo Exchange has added easy-to-navigate notifications when updates to your installed alerts are available. Changes included in this update:Rewritten Lookups & Optimized Queries: All 577 OOTB alerts now feature re-engineered lookup operations and optimized query performance (filtering before grouping). Integrated Device Data: Comprehensive device data is now included in all OOTB alerts, providing richer context for quicker and more effective investigation. Refactored mm2 Operations: Th
The Devo Parser is one of the secret spices of our unique Hyperstream technology. The Parsers organize raw events stored in tags in different columns and display them in the corresponding tables. This method completely bypasses data indexing and contributes to Devo’s amazing search speeds. Every data source is unique, so we have a great catalog of existing parsers. Our teams review parser performance, build new parsers and update parsers on a regular basis. This article covers all the updated and new parsers available this month. If you require a new parser, please open a support ticket through the support portal located here. You can also visit the new Resources Portal, a single page for all your customer resources! Table of ContentsUpdated Parsers cloud.azure auth.all ids.calyptix proxy.calyptix network.meraki cloud.meraki box.win_snare box.all.win firewall.paloalto box.vmware cloud.alibaba firewall.barracuda cspm.sysdig.secure.event edr.all.threats firewall.cisco box.
Every month, the integrations team work on new and updated collectors for you, and I collect them all in this Catalog Update. This post contains new and updated collector information as well as links to their respective pages in our Documentation portal. Be advised that some pages in Documentation may not be available at the time of posting but will be added as soon as they are available. To request new collectors or an update to an existing collector, please open a support ticket through the Support Portal. You can also visit the new Resources Portal, a single page for all your customer resources! Table of ContentsUpdated Collectors Crowdstrike Api collector v1.13.0 Snowflake Collector v3.1.0 Tencent Collector v1.2.0 OnePassword Collector v1.2.0 Cloudflare Collector v1.2.0 GCP Collector v2.3.0 Google Workspace Reports Collector v1.11.0 Google Workspace Logs Bigquery Collector v1.1.0 AWS SQS Collector v1.8.0 SentineOne Collector v1.6.0 Tenable Collector v2.1.0 Snowflake C
Join our intrepid hosts for another Devo ProdCast. This week we cover the improvements delivered in Devo Platform Release 8.16.3.
The latest release of the Devo Platform is here! Release 8.16.3 brings one new feature and a few improvements. The primary change is in Devo’s ability to empower you to search your Alerts. We’ve added Advanced Pro Filtering to the Alerts page that allows you to write queries to search your entire Alert library. You can start your filtering with the Simple Filter drop-downs, then switch to Pro filtering, and your simple filters will be automatically translated into a Pro filter query with real-time auto-complete. Check out the full details below! Remember, we also have ProdCasts so you can listen while you work! Geo AvailabilityRegion Status CA Released US Released US3 Released EU Released APAC Released Table of ContentsNew Feature Alerts Advance Search with Pro Filters Improvements Updated permissions for “Current Queries” New FeatureAlerts Advance Search with Pro FiltersA normal environment can have thousands of alerts! With this release, we introduce Pro filt
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.
Sorry, we're still checking this file's contents to make sure it's safe to download. Please try again in a few minutes.
Sorry, our virus scanner detected that this file isn't safe to download.