2026.10 2026.08 2026.07 2026.06 2026.05 2026.04 2026.02 2026.01
2026.10 2026.08 2026.07 2026.06 2026.05 2026.04 2026.02 2026.01

Open Collector 2026.10 Release Notes - 1 October 2026

October 2026 Release Details

The 2026.10 release of Open Collector requires Knowledge Base version 7.1.752.0 (or above).

Software Component

Version Number

New Version?

Open Collector

6.0.0

Yes

LRCTL Script

6.0.1


LRCTL Container

6.7.7

Yes

LRJQ

5.1.4


Metrics

6.0.8


OC Pipeline

5.1.7


OC-Admin

6.0.15


OC-DB

6.0.2


AWS S3 Beat

6.2.6

Yes

Azure Event Hubs Beat

6.0.10


Box Beat

6.0.0


Carbon Black Cloud Beat

6.0.9

Yes

ChatGPT Beat

6.0.0

Yes

Cisco AMP Beat

6.1.6


Darktrace Beat

6.0.0


Duo Authentication Security Beat

6.0.5


Exabeam Case Beat

6.0.1

Yes

Generic Beat

6.2.1


GitHub Enterprise Beat

6.0.0

Yes

Gmail Message Tracking Beat

6.0.6


GSuite Beat

6.0.5


Kafka Beat

6.0.9

Yes

Microsoft Graph API Beat

6.1.2

Yes

Mimecast SIEM Beat

6.1.0


O365 Beat

6.0.0


Okta Beat

6.0.6

Yes

OpenAI Beat

6.0.0

Yes

Prisma Cloud Beat

6.0.2


Proofpoint Beat

6.0.4

Yes

PubSub Beat

6.0.4

Yes

Qualys FIM Beat

6.0.5


Salesforce Beat

6.0.2


SentinelOne Beat

6.0.1


Sophos Central Beat

7.0.0


Symantec WSS Beat

6.0.3


Tenable Beat

6.0.1

Yes

Webhook Beat

6.1.7


New Features/Beats

Feature or Beat

Description

Relevant Documentation Updates

ChatGPT Beat

The ChatGPT Beat allows customers to collect audit logs from the ChatGPT Enterprise API, including workspace access, authentication activity, and administrative actions taken.

ChatGPT Beat

OpenAI Beat

The OpenAI Beat allows customers to use the OpenAI API to collector audit log data from your organization’s OpenAI account, including platform activity and security data.

OpenAI Beat

GitHub Enterprise Beat

The GitHub Enterprise Beat allows customers to collect Enterprise Audit Logs, Organization Audit Logs, and User Security Logs across 11 specialized log sources.

GitHub Enterprise Audit Beat

Enhancements/Improvements

Feature or Beat

Description

Relevant Documentation Updates

PubSub Beat

The PubSub Beat has been updated to allow users to collect Gemini Enterprise Model Armor logs.

Configure the PubSub Beat

Heartbeat Log Sources

Beat setup via command line has removed the need to create a heartbeat log source to track the functionality of your beats. Instead, the existing Silent Log Source detection functionality will be used to monitor this activity.

Configure Beat Log Sources in the SIEM

Resolved Issues

The following issues were resolved with a defect fix or platform enhancement in Open Collector 2026.10.

Bug ID #

Description

ENG-104237

The Tenable beat now emits its fully qualified beat name in the "tenablebeat_[beatname]" format so that logs can be attributed to the correct beat when multiple beats run on one Open Collector.

ENG-104993

The Box beat JSON policy has been updated to correctly map event and file fields, parse previously unmapped fields, and correct misconfigured file hash and size values.

Resolved security-related issues are available for customers to review on the Community.

Notice of JQ Pipeline Deprecation

Exabeam released JSON Parsing for Open Collector and Beats along with LogRhythm SIEM version 7.13. This feature was intended to replace the JQ pipeline within Open Collector, and as a result support and maintenance for the JQ pipeline, including dependencies such as the “ocpipeline” and “metrics beat,” are coming to an end in this October 2026 release.

To ensure that your Beats remain fully supported and maintained, it is recommended that any customers still using the JQ pipeline for their beats move to the JSON Parsing method and remove all metric and OC JQ images from the system.