October 2026 Release Details
The 2026.10 release of Open Collector requires Knowledge Base version 7.1.752.0 (or above).
|
Software Component |
Version Number |
New Version? |
|---|---|---|
|
Open Collector |
6.0.0 |
Yes |
|
LRCTL Script |
6.0.1 |
|
|
LRCTL Container |
6.7.7 |
Yes |
|
LRJQ |
5.1.4 |
|
|
Metrics |
6.0.8 |
|
|
OC Pipeline |
5.1.7 |
|
|
OC-Admin |
6.0.15 |
|
|
OC-DB |
6.0.2 |
|
|
AWS S3 Beat |
6.2.6 |
Yes |
|
Azure Event Hubs Beat |
6.0.10 |
|
|
Box Beat |
6.0.0 |
|
|
Carbon Black Cloud Beat |
6.0.9 |
Yes |
|
ChatGPT Beat |
6.0.0 |
Yes |
|
Cisco AMP Beat |
6.1.6 |
|
|
Darktrace Beat |
6.0.0 |
|
|
Duo Authentication Security Beat |
6.0.5 |
|
|
Exabeam Case Beat |
6.0.1 |
Yes |
|
Generic Beat |
6.2.1 |
|
|
GitHub Enterprise Beat |
6.0.0 |
Yes |
|
Gmail Message Tracking Beat |
6.0.6 |
|
|
GSuite Beat |
6.0.5 |
|
|
Kafka Beat |
6.0.9 |
Yes |
|
Microsoft Graph API Beat |
6.1.2 |
Yes |
|
Mimecast SIEM Beat |
6.1.0 |
|
|
O365 Beat |
6.0.0 |
|
|
Okta Beat |
6.0.6 |
Yes |
|
OpenAI Beat |
6.0.0 |
Yes |
|
Prisma Cloud Beat |
6.0.2 |
|
|
Proofpoint Beat |
6.0.4 |
Yes |
|
PubSub Beat |
6.0.4 |
Yes |
|
Qualys FIM Beat |
6.0.5 |
|
|
Salesforce Beat |
6.0.2 |
|
|
SentinelOne Beat |
6.0.1 |
|
|
Sophos Central Beat |
7.0.0 |
|
|
Symantec WSS Beat |
6.0.3 |
|
|
Tenable Beat |
6.0.1 |
Yes |
|
Webhook Beat |
6.1.7 |
|
New Features/Beats
|
Feature or Beat |
Description |
Relevant Documentation Updates |
|---|---|---|
|
ChatGPT Beat |
The ChatGPT Beat allows customers to collect audit logs from the ChatGPT Enterprise API, including workspace access, authentication activity, and administrative actions taken. |
|
|
OpenAI Beat |
The OpenAI Beat allows customers to use the OpenAI API to collector audit log data from your organization’s OpenAI account, including platform activity and security data. |
|
|
GitHub Enterprise Beat |
The GitHub Enterprise Beat allows customers to collect Enterprise Audit Logs, Organization Audit Logs, and User Security Logs across 11 specialized log sources. |
Enhancements/Improvements
|
Feature or Beat |
Description |
Relevant Documentation Updates |
|---|---|---|
|
PubSub Beat |
The PubSub Beat has been updated to allow users to collect Gemini Enterprise Model Armor logs. |
|
|
Heartbeat Log Sources |
Beat setup via command line has removed the need to create a heartbeat log source to track the functionality of your beats. Instead, the existing Silent Log Source detection functionality will be used to monitor this activity. |
Resolved Issues
The following issues were resolved with a defect fix or platform enhancement in Open Collector 2026.10.
|
Bug ID # |
Description |
|---|---|
|
ENG-104237 |
The Tenable beat now emits its fully qualified beat name in the "tenablebeat_[beatname]" format so that logs can be attributed to the correct beat when multiple beats run on one Open Collector. |
|
ENG-104993 |
The Box beat JSON policy has been updated to correctly map event and file fields, parse previously unmapped fields, and correct misconfigured file hash and size values. |
Security-Related Issues
Resolved security-related issues are available for customers to review on the Community.
Notice of JQ Pipeline Deprecation
Exabeam released JSON Parsing for Open Collector and Beats along with LogRhythm SIEM version 7.13. This feature was intended to replace the JQ pipeline within Open Collector, and as a result support and maintenance for the JQ pipeline, including dependencies such as the “ocpipeline” and “metrics beat,” are coming to an end in this October 2026 release.
To ensure that your Beats remain fully supported and maintained, it is recommended that any customers still using the JQ pipeline for their beats move to the JSON Parsing method and remove all metric and OC JQ images from the system.