Insight historical release notes
Selected historical changes from earlier Capuris Insight analytics releases.
These notes summarize selected behavior from earlier releases. They are useful when maintaining an older installation, but they are not a statement of the current product’s complete feature set. Consult the package-specific release notes before an upgrade.
Analytics 2.0.0 — May 30, 2024
Release 2.0.0 introduced a standalone Kafka-based architecture for Insight analytics and refreshed several investigation surfaces.
Highlights
- Revised aspects for viewing packet-derived relationships.
- Updated reports and broader protocol handling.
- Reworked reports within Interactive Search.
- Changes to Flow Analysis behavior and presentation.
- Dashboard improvements for operational visibility.
- TACACS+ support in the administration workflow.
- Elasticsearch reliability and performance work.
Because this release changed core services, upgrades should verify queue health, search completion, reports, saved workflows, database state, and node connectivity.
Analytics 1.6.1 — May 24, 2023
Version 1.6.1 added IDS-oriented investigation features and packet slicing.
IDS alerts
The IDS Alerts experience brought detections into Insight so analysts could move from an event to related packet evidence and context. Operators should still validate a detection against the original traffic and supporting security telemetry.
Packet slicing
Packet slicing allowed a workflow to retain headers and a configured number of packet bytes rather than the entire payload. This can reduce storage and exposure, but omitted bytes cannot be recovered from the sliced output.
Analytics 1.5.0 — November 4, 2022
Version 1.5.0 expanded the core analytics workflow:
- Interactive Search for selecting and processing packet data.
- Malicious-node investigation from relationship views.
- Flow Analysis and DNS or HTTP reporting.
- Usage analysis for traffic-volume questions.
- Administration improvements for operating the platform.
When reproducing an older result, record the exact release, filters, sampling, graph aspect, and input PCAP. Decoder and visualization behavior can differ across versions.
Using historical notes
Before applying an old procedure to a current system:
- Check whether the feature or label still exists.
- Compare the installed version with the version named here.
- Review current administration and API documentation.
- Test the workflow on a small, non-production input.
- Preserve the original data so a changed decoder can be evaluated safely.