Skip to main content
Skip table of contents

7.21.0 GA Release Notes - 1 July 2025

Experience the power of next-level security with LogRhythm SIEM 7.21! Accelerate your workflows with advanced alarm filtering, instant log access from Dashboards, seamless MITRE ATT&CK® framework alignment, and a streamlined developer portal for effortless API integration. Discover how these enhancements empower your team to detect threats faster and respond with confidence.

What’s new in SIEM 7.21:

Maintenance

Surface Critical Threats With 14 New Alarm Filters 

Security teams often need greater agility when investigating alerts, especially when pinpointing activity linked to specific users, hosts, or IP addresses. LogRhythm SIEM 7.21 answers this need with 14 new alarm filters, more than doubling the options available in previous releases. These expanded filters empower analysts to drill down with precision and gain sharper, more actionable insights into critical events.

With this update, analysts can now filter by the following additional fields: 

  • Classification 

  • Common Event 

  • Log Source 

  • Entity (Origin/Impacted) 

  • IP Address (Origin/Impacted) 

  • Hostname (Origin/Impacted) 

  • User (Origin/Impacted) 

  • Location (Origin/Impacted) 

  • VMID 

NewAlarmFilters_Short.gif

For more information on the new alarm filter fields and how to use them, refer to Alarm Filters and Use Dynamic Alarm Filters.

Filter Alarms by MITRE ATT&CK TTPs 

Unlock deeper threat detection with LogRhythm SIEM 7.21’s MITRE ATT&CK® alarm filters. Instantly filter alarms by specific ATT&CK tactics to pinpoint high-risk activity. By mapping Common Events to analytics rules, analysts can quickly organize and highlight incidents by ATT&CK phase, streamlining triage and enabling teams to spot threat patterns with greater speed and accuracy.

MitreFilter.gif

For more information on linking Common Events to analytics rules, refer to Create Common Events.

Instant Log Access in Data Indexer Dashboards 

Easily transition from visual data to the underlying log details with just a single click in LogRhythm SIEM 7.21. Say goodbye to the hassle of opening new tabs or running manual searches. Everything you need is at your fingertips with the View Logs option! Get ready to enhance your threat hunting workflows with this dynamic and interactive investigation tool.

DXDashLogGrid.gif

For more information, refer to the Data Indexer (DX) Dashboards topic.

New LogRhythm SIEM Developer Portal 

Speed up automation and development with the new Exabeam Developer Portal. This centralized, user-friendly environment streamlines development with prebuilt code samples, multi-language support, and clean documentation. The Developer Portal helps security teams: 

  • Automate repetitive tasks,

  • Accelerate integration timelines, and

  • Reduce API troubleshooting and scripting errors.

Log Source Enhancements and Updates

LogRhythm SIEM 7.21 introduces updates designed to enhance the speed, consistency, and compatibility of data collection with third-party platforms. These enhancements include:

New and Updated Log Sources

This past quarter of bi-weekly LogRhythm SIEM Knowledge Base updates included 40 enhanced or improved log sources, and five newly introduced log sources. This allows customers to expand their security capabilities by increasing log visibility within the LogRhythm SIEM.

The following log sources have been added or updated:

New Log Sources

Updated or Improved Log Sources

  • Syslog - Symantec Endpoint Threat Defense for AD

  • Syslog - McAfee Database Security CEF

  • Syslog - threatER

  • Syslog - ManageEngine PAM360

  • Syslog - NetScout Arbor Edge Defense CEF

  • Flat File - Microsoft IIS (IIS Format) File

  • Flat File - Microsoft Windows 2012 DNS

  • MS Windows Event Logging XML - Application

  • MS Windows Event Logging XML - System

  • MS Windows Event Logging XML - Security

  • MS Windows Event Logging XML - PowerShell

  • Syslog - Apache Error Log

  • Syslog - Cisco FirePOWER

  • Syslog - Cisco FirePower Threat Defense

  • Syslog - Cisco Router

  • Syslog - Cisco Switch

  • Syslog - Cisco ISE

  • Syslog - CyberArk

  • Syslog - Cylance Optics Detection\Protection Events

  • Syslog - F5 Big-IP ASM v12

  • Syslog - F5 Big-IP LTM

  • Syslog - Fortinet FortiAuthenticator

  • Syslog - Fortinet FortiGate

  • Syslog - Generic Linux OS

  • Syslog - Imperva SecureSphere

  • Syslog - Imprivata OneSign SSO

  • Syslog - Juniper Switch

  • Syslog - Kaspersky Security Center

  • Syslog - Legacy Checkpoint Firewall

  • Syslog - Linux Audit

  • Syslog - McAfee Database Security CEF

  • Syslog - MS Windows Event Logging XML - Application

  • Syslog - Netscout Arbor Edge Defense CEF

  • Syslog - Open Collector - Elastic Load Balancing Access Logs

  • Syslog - Open Collector - GCP PubSub Audit

  • Syslog - Open Collector - GoogleWorkspace Admin

  • Syslog - Open Collector - Google Workspace Login

  • Syslog - Open Collector - Google Workspace Token

  • Syslog - Open Collector - Mimecast SIEM

  • Syslog - Palo Alto Cortex XDR

  • Syslog - Proofpoint Spam Firewall

  • Syslog - Pulse Secure

  • Syslog - Rubrik

  • Syslog - Sophos XG Firewall

  • Syslog - Snort IDS

  • Syslog - SonicWall

  • Syslog - Sourcefire IDS 3D

  • Syslog - Tanium

  • Syslog - Tanium LEEF

  • Syslog - Trend Micro Deep Security CEF

  • Syslog - Trend Micro Deep Security LEEF

  • Syslog - Ubiquiti UniFi Security Gateway

  • Syslog - Vectra Networks

  • Syslog - VMWare vCenter Server

  • Syslog - Vormetric Data Security Manager

  • Syslog - Zscaler Nano Streaming Service

  • UDLA - Oracle 12C Unified Auditing

The following Log Sources have been renamed:

Old Name

New Name

Syslog - Tanium

Syslog - Tanium LEEF

Syslog - Open Collector - GCP Audit

Syslog - Open Collector - GCP PubSub Audit

Threat Intelligence Service Updates

The LogRhythm Threat Intelligence Service (TIS) has been updated to version 1.9.7 as a part of this release! The following new features and improvements are included in the 1.9.7 release.

Added Support for TAXII 2.0

Pagination is implemented via multiple requests using Range headers and the added_after filter to ensure only recent and relevant data is ingested.

Added Support for TAXII 2.1

Pagination follows the TAXII 2.1 specification, using the next link and hasMore flag to manage feed retrieval.

MaxRecordsToFetch Configuration Setting

A new configuration setting, MaxRecordsToFetch, allows users to control the maximum number of STIX objects ingested per session (capped at 100,000).

TIS Improvements/Enhancements

The following new features/improvements are also included in the release:

  • UI-level enhancement introduces a “Fetch Feeds Added After” date filter for V2 providers, with validation to ensure data stays within the configured retention window.

  • The system handles large datasets without memory/time-out issues.

  • The HailaTAXII feature has been deprecated due to the service no longer being active.

Platform Updates

LogRhythm 7.21 is packed with platform updates to improve security, performance, and stability. Spend more time hunting for threats and less time managing the platform.

Security Improvements

The following enhancements were made to improve the overall security standing of the SIEM product:

  • Increased encryption key length to 3072 bits,

  • Implemented SHA-256 signing for installers, and

  • Added support for TLS 1.3 for Web Console.

Dependency Updates

As part of our ongoing commitment to maintaining third-party dependencies for stability and security improvements, the following packages have been updated:

  • Web-Indexer Java Corretto JDK updated to 21.0.7

  • Data-Indexer Java Corretto JRE updated to 8.0.452

  • .NET 8 Core updated to 8.0.15

  • Grafana updated to 11.6.1

  • Telegraf update to 1.34.1

  • Web-Console NGINX updated to 1.28.0

  • NodeJS update for Web Console UI, Web Console Services Host API, Authentication API and API Gateway to 22.14

An API Gateway NodeJS update was partially released for Windows only. Note that NodeJS no longer supports CentOS 7. Customers are advised to upgrade their Linux-based Data Indexers, as CentOS 7 support will cease in a future LogRhythm SIEM release. Refer to the Notice of Eventual Deprecation section for more information.

  • Go Update to 1.24.2 for DX Services, Admin API, Metrics API and True Identity Sync Client

Data Indexer Improvements

The following improvements to the Data Indexer have been made for version 7.21:

  • Added Metrics collection and tracking of node shard counts for monitoring limits,

  • Increased default disk High Watermark to 90% for SSD-based DXs,

  • Maximum Ultra-Warm TTL is now configurable up to six months (180 days),

  • Increased Transporter threading to increase max indexing throughput on nodes with available hardware capacity, and

  • Improvements to warm tier search handling for a more reliable user experience.

Updated the Web Indexer Java Development Kit

The Java Development Kit (JDK) used by the LogRhythm Web Indexer service has been updated form JDK8 to JDK21, which includes a migration from Lucene 4 to 9. This upgrade greatly enhances searching and indexing in the following ways:

  • 10x improvement in query response times for TopX widget requests,

  • Improved average search rendering latency of 200–350ms (down from 400ms) for web console widgets,

  • 50% improvement to Web Indexer indexing rate,

  • 70% reduction in memory consumption under heavy loads, and

  • 45% reduction in CPU consumption of the Web Indexer service.

System Monitor Agents and Multiple LogRhythm Services Updated to .NET 8

Windows System Monitor Agents can now be built using .NET 8 Core, bundled as an optional add-on within the Installation Wizard. With up to 20% improvement in agent data throughput, this update gives teams faster access to insights with less overhead.

Additionally, the following third-party DLLs were upgraded: Newtonsoft.json; nsoftware; SmartThreadPool; and Xceed.

LogRhythm services built with .NET Core (AIE, Data Processor, ARM, and SMA) will now ship with .NET version 8.0.15, to be updated quarterly going forward.

Collection of API log sources on .NET 8 SMA is not supported. System Monitor Agents using .NET 4 will continue to collect API log sources.

System Monitor Agent Silent Installer Improvement

Windows System Monitor Agents (SMAs) now have a new silent install switch, EntityID, allowing for the silent installer to inform the platform with which root entity the pending SMA should be associated.

Refer to Silently Install a System Monitor on Windows for silent installer configurations.

System Monitor Agent JSON Output Improvement

When using the JSON Listener, the JSON Policy name and System Monitor Agent version are now included in the Syslog output from the Agent. These fields are not parsed or used by the LogRhythm SIEM, but can be referenced when debugging or testing JSON Processing Policies.

Notice of Eventual CentOS 7 and RHEL 7 Deprecation

Due to compatibility issues with dependency services that no longer support older operating systems, CentOS 7 and RHEL 7 will reach end-of-life for Data Indexer support beginning with LogRhythm SIEM version 7.23 (January 2026). Beginning with version 7.22 (October 2025), additional features will be added to perform operating system (OS) version checking with data indexer (DX) services and provide warnings for users to upgrade their DX OS versions.

Because the end-of-life for CentOS 7 was June 30, 2024, meaning that the operating system no longer receives security updates, it is strongly recommended to upgrade your Data Indexer operating systems as soon as possible.

For more information about migrating your DXs from CentOS/RHEL7 to Rocky/RHEL 9, refer to the Data Indexer CentOS to Rocky Upgrades guide.

Resolved Issues & Improvements

The following issues have been resolved either via a defect fix or a platform improvement in LogRhythm SIEM 7.21.

Bug #

Component

Description

ENG-41651

Web Console

An issue that arose after upgrading to 7.12 or later where the CAC authorization used to log in to the Web Console stopped working has been resolved.

ENG-50024

Alarms

An issue with alarm email notifications not containing all metadata fields in certain situations has been resolved.

ENG-56766

Rules

A hidden configuration option has been added for overriding rule-sorting behavior.

ENG-57965

Wizards

Using the Windows Host Wizard to onboard event logs no longer incorrectly marks the operating system as XP/2000/2003 despite selecting a newer operating system in the wizard.

ENG-58352

MPE Rule Builder

Improved the performance of MPE Rule Builder and addressed timeouts that would occur in certain situations.

ENG-61707

Admin API

The Admin API can now correctly be used to accept pending log sources even if the host name is already resolved.

ENG-62239

Admin API

An issue with field mappings that prevented certain fields (such as maxMsgCount) from being updated correctly using the API has been resolved.

ENG-62332

Search

Updated GoMaintain monitoring to track shards per node and display this data in Centralized Metrics.

ENG-62357

Web Console

Using the “Check All” option when filtering logs now correctly checks only all filtered logs as opposed to all logs.

ENG-62604

ARM

The Alarming and Reporting Manager (ARM) will now rate-limit the number of concurrent SRPs executing to avoid error messages and large surges of SRP data.

ENG-62641

Job Manager

An AD Sync issue that would throw an error when attempting to set a child entity as a user’s default entity has been resolved.

ENG-63014

JSON Processing Policy

A log parsing issue that was causing errors for users of the Azure Event Hubs Beat has been resolved.

ENG-63031

System Monitor

An issue with the MS Security Event log source stopping collection intermittently in certain situations has been resolved.

ENG-63255

JSON Processing Policy

The AWS CloudWatch parser has been updated to correctly parse the “StartDate” field.

ENG-63322

Search

Data Indexers will no longer close indexes in certain situations while Warm-Closed tier searches are actively being performed.

ENG-63646

Investigations

A “logs got missed” error that would appear in certain situations while running an investigation despite the logs being fetched correctly has been resolved.

ENG-63671

APIs

The API Gateway no longer causes the non-paged pool memory to increase when it does not receive a response from an endpoint, and the Data Processor now performs as expected without a backlog. 

ENG-63672

Client Console

When entering data into an IP Address field, values that are not correctly formatted as IP addresses will no longer be accepted.

ENG-63836

Installation

LR Installers no longer incorrectly state that “dependency installations failed” when in actuality the dependency is already installed and doesn’t need to be reinstalled.

ENG-68584

AI Engine

An issue with the AIE not starting in certain situations when a workload has not been assigned to an engine after upgrading to LR SIEM 7.20 has been resolved.

ENG-69328

Reporting

A new “Recipients” column has been added to the scheduled report job manager, which displays all selected users who will receive an email after job execution.

ENG-69517

Web Console

Various issues with Web Console widget slowness and delays when typing in widget filters have been resolved.

ENG-70031

Web Console

An issue that would cause a Web Console DX dashboard to double log counts in certain situations has been resolved.

ENG-70583

Web Console

An issue with search text autocomplete not displaying in a drop-list in certain situations within the Web Console Analyzer Grid has been resolved.

ENG-70858

Metrics

The LogRhythm Metrics UI service now correctly bundles all necessary plugins in the installer.

ENG-70983

Data Processor

An issue where pending System Monitors are unable to be accepted in certain situations has been resolved.

ENG-71030

AI Engine

An issue where the drilldown cache was not populating in certain deployments with low alarm rates has been resolved.

ENG-71362

JSON Processing Policy

The Microsoft Defender parser has been updated to correctly parse the “IP Address” field.

ENG-72777

Agents

Uninstalling a System Monitor Agent no longer results in necessary configuration files also being removed in certain situations.

ENG-72803

Web Indexer

The Web Indexer service no longer fails to start after installing or upgrading LR SIEM.

ENG-72941

AI Engine

The AI Engine Cache Drilldown log folder no longer installs to an unforeseen location in certain situations.

Resolved Issues - Security

Security-related issues resolved with this release are available for customers to view in the Community.

Known Issues

The following issues have each been found and reported by multiple users.

Bug #

Found In Version

Components

Description

Notes

ENG-35302

Multiple

AI Engine

Alarm with “not observed” rule block is firing even when a log or multiple logs are present.

Expected Results: Alarm should not fire if log is present and is within the time window.

Workaround: There is currently no workaround for this issue.

ENG-42942

Multiple

Data Indexer

Data Indexer Investigations on multi-node clusters may produce different result counts when keyword searches are run multiple times.

Expected Results: All results should be returned each time an investigation is performed.

Workaround: Dev binaries are available for testing, please open a support case if you experience this issue.

ENG-61278

7.19

APIs

After upgrading to LogRhythm SIEM version 7.19, servers running Windows Server 2012 R2 may throw errors when attempting to use the LogRhythm API or connecting through API Gateway.

Expected Results: The LogRhythm API should function as expected.

Workaround: A workaround for this issue has been documented at LogRhythm API Gateway Error on Windows Server 2012 R2.

JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.