7.10.0.8001 November 2022 Release Notes

Release Details

Software Component

System Monitor (SysMon)

Version Number

7.10.0.8001 (Windows)

7.10.0.8001 (*NIX)

Compatibility

LogRhythm 7.10.0 GA

LogRhythm 7.9.0 GA

Microsoft .NET Framework 4.7.2


LogRhythm System Monitor Agents for Windows require the Microsoft .NET Framework 4.7.2. 

New Features

  • The AIX Agent installer now supports AIX version 7.2.

  • Ubuntu 22 is now supported for Linux System Monitors.


Improvements

No new improvements in this release.

Deprecated Features

LogRhythm has deprecated Check Point collection via OPSEC LEA in favor of the newer Check Point Log Exporter. Support for OPSEC LEA was removed starting with LogRhythm System Monitor Collector version 7.7.0.8004 and results in an error in the scsm.log file if this collection method is used. Customers who need to use OPSEC LEA for collection should not upgrade agents past System Monitor 7.7.0.8002 release.  For information on how to configure Check Point Log exporter, see Syslog - Check Point Log Exporter device configuration guide.

Resolved Issues

Bug ID

Salesforce Case ID

Found in Version

Release Notes

DE3641

366039, 370659

7.4.7

Collecting logs from a remote Agent no longer causes an issue with the position file in certain situations.

DE4324

354948, 365538

7.4.6

The Client Console no longer allows a regex greater than 1024 characters.

DE6166

328482, 327926

7.3.4

The Agent now assigns date and time based on date-time in the raw log to explicitly define the year.

Resolved Issues - Security

No security-related resolved issues in this release.

Known Issues

Bug ID

Found In Version

Components

Description

Release Notes

DE7241

7.2.5

Windows Agent

When collecting sFlow Expanded Flow Format logs, warnings are constantly written to the System Monitor log file.

Expected Results: The System Monitor Agent should collect this log format without producing warnings in the log file.

Workaround: The System Monitor Agent does not support sFlow Expanded Flow Format. You must convert these logs to NetFlow to collect the data. There is a Golden Nugget posted to LogRhythm Community that shows you how to convert from sFlow Expanded Flow to NetFlow. You can find it on the Community here: https://community.logrhythm.com/t5/Golden-nuggets/LogRhythm-Golden-Nugget-Use-Case-sFlow-Expanded-Flow-Format-No/m-p/109276

DE10288

7.2.7

7.4.7

Windows Agent

When setting up log collection on AWS CloudTrail S3 and trying to establish a trust relationship for the SSL/TLS secure channel, customers may receive the following error exception message:

**ERROR** Exception msg: A WebException with status TrustFailure was thrown.

Expected Results: Customers should be able to configure CloudTrail S3 log collection without errors.

Workaround: Use Open Collector to collect from CloudTrail S3 log sources or suppress the trust check.

DE14004

7.8.0

Mimecast

When enabling cleanup scripts for Mimecast collection, customers may receive tracking errors and collection may not be reliable.

Expected Results: Collection should be reliable during cleanup.

Workaround: There is no workaround for this issue.