Protocols, Smart Polling, and Arc
A list of the improvements for Protocols, Smart Polling and Arc that have been introduced in this release.
- ENG-346: Added a timeframe chart to display the latest 100 alert occurrences over time. This chart highlights the first occurrence of an alert and shows dots for each subsequent occurrence.
- ENG-538: You can now configure directory exclusions for malware detections.
- ENG-563: The Windows Remote Management (WinRM) Smart Polling strategy is now available to Arc sensors.
- ENG-640: Fixed an issue with Ovation import.
- ENG-687: Fixed the display of alert occurrences. Improved the UX for zooming out to the original scale.
- ENG-790: Added support for HiCONiS protocol.
- ENG-828: Introduced detection for Aconis MPM device operations.
- ENG-1328: Ported the secure shell (SSH) strategy to Go to make it available to Arc.
- ENG-1513: The SSH Smart Polling strategy now verifies the host key before attempting authentication. This security feature can be enabled from the Features page in the administration section of Guardian.
- ENG-1552: Addressed a potential memory consumption problem in Smart Polling hypertext transfer protocol (HTTP) and hypertext transfer protocol secure (HTTPS) strategies.
- N2OS-16662: The connected Guardian now automatically renews the Remote Collector certificates, provided they were issued by Nozomi Networks.
- N2OS-17021: Added support for the Automation Direct KOP protocol to enable asset identification and information extraction for these devices.
- N2OS-17221: Added support for the Automation Direct Productivity1000 protocol to enable asset identification and information extraction for these devices.
- N2OS-17235: Enhanced S7plus protocol detection to detect program changes.
- N2OS-17236: Improved detection of firmware transfer on S7Plus protocol.
- N2OS-17377: Improved asset representation of devices with multiple interfaces
and the same internet protocol (IP) address. Added two configuration
options for the
check_multiple_macs_same_ipsetting:check_multiple_macs_same_ip group_by_ipgroups nodes with the same IP address and distinct media access control (MAC) addresses into a single asset when thecheck_multiple_macs_same_ip enableconfiguration option is set to true.check_multiple_macs_same_ip require_confirmed_macsenables thecheck_multiple_macs_same_ipfeature only on nodes that have confirmed MAC addresses.
- N2OS-17511: It is now possible to disable the aggregation of nodes into assets based on the
device identifier (ID) on a per‑protocol basis. This can be
configured using the new
notify_device_idprotocols setting.