Highlights

An overview of the most impactful changes in this release.

Alert deduplication

Nozomi Networks Operating System (N2OS) v26.5.0 enables alert deduplication by default for all deployments. This new default applies to both new installations and existing installations that have not explicitly configured alert deduplication. This change reflects Nozomi Networks' confidence in the feature's stability and its impact on reducing alert noise and improving operator focus.

  • New and existing installations of N2OS v26.5.0, or later, have alert deduplication turned on by default.
  • The feature remains fully configurable and can be toggled from N2OS or Vantage, depending on the deployment.
  • Existing deployments upgrading to N2OS v26.5.0 keep their explicit configuration for alert deduplication:
    • If you explicitly enabled or disabled deduplication, N2OS preserves that choice across the upgrade.
    • If you left the configuration at its default state, your deployment adopts the version default: disabled by default in N2OS v26.3.0 and v26.4.0, and enabled by default starting with v26.5.0.
Important:
When alert deduplication is enabled, incidents will no longer be generated.

Before you enable alert deduplication, review whether incidents are still required in your environment. If incidents are critical to your operations, do not enable alert deduplication at this time.

If you rely on incidents, open a support ticket and describe how you use them today. Include any key workflows, configurations, reports, or integrations. This feedback will help Nozomi Networks evaluate future incident use cases that can work alongside alert deduplication.

Receiving updated alerts through data integrations

When the alert deduplication feature is enabled, the data integrations will only receive the first event of each alert. This standard behavior helps reduce the number of alerts in the corresponding tool. In some environments, it can also reduce the visibility of security events. To avoid this, data integrations now support a configuration to send alert updates. With this configuration turned on, the alerts are sent again when a new event is recorded.

Minimum ESXi version requirement

Starting with N2OS v26.5.0, the lowest compatible version of ESXi is 9.0. This is due to N2OS's adoption of FreeBSD 15.x, which VMware does not list as a supported and compatible version of FreeBSD for ESXi versions lower than 9.0.

Nozomi Networks cannot support virtual deployments unless they use the correct ESXi and Nozomi Networks version combination, for both new deployments and upgrades of existing deployments:
  • N2OS v26.5.0, or higher (leveraging FreeBSD 15.x), Host ESXi v9.0, and virtual hardware version 22, or higher
  • N2OS between v26.4.0 and v24.5.1 (leveraging FreeBSD 14.x), Host ESXi between v9.0 and v8.0, and virtual hardware between version 22 and version 20

For more information on ESXi virtual hardware version and FreeBSD compatibility, see VMware's OS Compatibility Guide.