Highlights
An overview of the most impactful changes in this release.
Centralized N2OS assertion management from Vantage
Users can now configure and manage Nozomi Networks Operating System (N2OS) assertions directly from Vantage, with centralized control and selective propagation across their monitoring architecture. Assertions defined in Vantage can be scoped to target and run locally on specific sensors, improving detection accuracy for fast, distributed events.
From the new Assertions page in Vantage, users can switch to the N2OS tab to create, edit, and delete assertions. The workflow follows the standard assertion configuration process. Users define the query, then configure key properties such as name, group, description, alert type, and the assertion check interval.
To support this centralized model end-to-end, Central Management Console (CMC)s and all connected sensors must run N2OS v26.2.0 or later. Sensors on earlier versions continue to run their existing local assertions. New or updated assertions from Vantage or a CMC on N2OS v26.2.0 or later are not propagated to sensors running N2OS v26.1.0 or earlier. This version alignment ensures that assertion scope, propagation, and local evaluation behave consistently across the deployment.
Alert deduplication
In N2OS v26.3.0 alert deduplication was no longer considered an experimental feature as it became a standard, fully supported feature that any deployment can use.
The feature continues to be disabled by default and users can toggle alert deduplication from both N2OS and Vantage. Starting with N2OS v26.5.0, alert deduplication will be enabled by default for all installations, unless explicitly configured otherwise. Existing documentation remains valid, and no changes are required to user workflows. The underlying implementation incorporates learnings from the experimental phase, without changing how users enable or use the feature.
This ensures a smooth transition for environments that are already using the experimental capability, while providing a clear and stable path for new adopters.
Before you enable alert deduplication, review whether incidents are still required in your environment. If incidents are critical to your operations, do not enable Alert deduplication at this time.
If you rely on incidents, open a support ticket and describe how you use them today. Include any key workflows, configurations, reports, or integrations. This feedback will help Nozomi Networks evaluate future incident use cases that can work alongside alert deduplication.
Receiving updated alerts through data integrations
When the alert deduplication feature is enabled, the data integrations will only receive the first event of each alert. This standard behavior helps reduce the number of alerts in the corresponding tool. In some environments, it can also reduce the visibility of security events. To avoid this, data integrations now support a configuration to send alert updates. With this configuration turned on, the alerts are sent again when a new event is recorded.