Video: October 2025 Quarterly Launch, LogRhythm SIEM | Duration: 2840s | Summary: October 2025 Quarterly Launch, LogRhythm SIEM | Chapters: Introduction and Speakers (0s), Product Portfolio Overview (104.8913817337019s), Product Improvements Overview (234.79638173370193s), Threat Center Introduction (390.1313817337019s), Platform Updates Showcase (521.9813817337019s), Configuring Metric Widgets (1158.0813817337018s), New Dashboard Features (1555.0413817337019s), Setting Up LR Control (1654.376381733702s), OpenCollector Setup Process (1701.9763817337018s), Survey and Clarification (2334.2513817337017s), Docker Integration Clarification (2390.941281733702s), Future Update Considerations (2483.381381733702s), JSON Data Integration (2526.946381733702s), Release and Availability (2625.1265817337016s), Feedback and Conclusion (2745.9815817337017s)
Transcript for "October 2025 Quarterly Launch, LogRhythm SIEM": On this one call from the last right, Ryan? I'm sorry. Right, Jake? Anyways, you'll be hearing from him on a recorded demo, so we have definitely prepared some a lot of material for you here in advance. So with that said, Jake will be taking us through the the latest and the updates. Jake will have the reins from about slide four onward. Anyways, just a a quick view about the speakers today just to let you know who we are. My name is Brook Chelmo. I'm the director of product marketing. Mister Ryan Gamboa, the the Robin to Jake's Batman, is our senior product manager. And Jake, who is also here on the call, is a senior product manager here, who has his, fingers in both pies on the NetMod side as well, of course, LogRhythm and shares that responsibility with Ryan. So with that said, our agenda today is going to be an overview of the portfolio. We're gonna speak about promises made and promises kept and how we keep developing quarter and after quarter. I was joking with an analyst last week that as far as I can see this, we will have an October update until the sun burns out. And Jake and I actually did the math on this. So it's like about 12,000,000,000 quarters of updates. With that said, we're talking about what's new in this release. We're gonna talk about we're gonna show a demo that was recorded by Ryan and then cover q and a. The q and a button is on the side of your screen there. Please feel free to type any questions, and we'll take a look at those as our team on the back end will be evaluating those. So with that said, Jake, if you could take this away and speak a little bit about our portfolio. Absolutely. Thank you, Brook. Thank you, everybody. Welcome to, the the quarterly launch for LogRhythm SIEM You know, just to get started, we wanna remind everybody about the product lines. It's been, you know, quite a while since we've had the merger between LogRhythm and Exabeam, the merger of equals. Just wanna remind everybody of the the awesome product portfolio that we have across the the two, merged companies together. New-Scale, that that's what we call the cloud platform that's available for customers that are looking to to move off of on prem and into the cloud. And then, of course, there's the logarithms in product line. If if you're on this webinar, you probably know and love it already. And, you know, we're gonna continue delivering updates on both these product lines. And, of course, right there in the middle, there's the highlight, one of my favorites, NetMon, to help fill in that need for network analytics, network monitoring, to to help with, detecting threats as it comes across the wire. So be sure to to be familiar with the LogRhythm or the Exabeam family product portfolio. And, you know, with that, there's tons of really cool new things that we're rolling out in the New-Scale side. If, if you didn't see we had a webinar yesterday, go watch that webinar. Watch the replay, and you can get caught up on some of the great new features that we're adding to the New-Scale platform for our cloud computing. With that, let let let's jump ahead and, highlight a little bit of of what we've been focused on the last several quarters. You know, our our CEO, has always had a mantra of promises made, promises kept, And this is another quarter of keeping our promises, of delivering innovations and new features to our customers across all of our product lines. So we're really excited to continue that tradition, adding quarter upon quarter, as Brook said, until the sun burns out. Now granted, I don't know if I'll be here till the very end of the the sun burning out, but I'll I'll stick around as long as I can. With that, I just wanna give a couple highlights of some of the things that we've been working on for the LogRhythm SIEM platform over the last year, maybe a little bit longer than that year and a half. You know, we we've been doing a lot of continual improvements, in the, you know, last, year and a half or so, we've delivered, made sure that there's over a thousand different products that are supported within the LogRhythm SIEM. We've delivered a 140 product improvements in the last couple quarters. We've improved performance of the logarithms in ecosystem across the the board, up to 10 x faster pattern matching, 80% decrease in heat DX heat consumption, making the the data indexers, our data lake side of the product just more more effective and faster, and 50% throughput improvement in detection. And then, of course, also an 87% faster log source loading in the consoles. So really excited to continue to, adding these capabilities. And, of course, the the the one that's always important is we've continued to improve encryption, making the logarithms in product just a better and more secure product line, making it so that your logs are safer than Ryan's fantasy football picks. Just have to pick on Ryan since he's not here today, of course. Good job. Thanks, Brook. So let's jump right into what's new. What what have we been working on, and what are we doing in the LogRhythm SIEM, in this quarterly release? The first thing I wanna highlight is this new feature that we've added about multi cluster log forwarding. This is the giving you the ability to send logs from one data processor over to multiple date DX clusters or data indexer clusters. This means, we're gonna make it so it's easier for regional data resiliency on the data indexer side. You can now configure the data processor duplicate logs across multiple clusters. This means you can search and store data in any region regardless of which cluster is active. And we'll have a really cool demo of this in just a little bit, so hang on. Another new feature that I'm really thrilled about is continuing to improve the capabilities of our DX dashboards. In the last few quarters, you may have heard about the DX dashboards. This is adding the ability to populate data in our dashboard directly from that DX cluster or our data lake, ecosystem. This means that now, analysts can use can leverage metrics in the UI, making it so, making it so you can get count, sum, average, min, max, all visualized in the web console, through the dashboards. And, you know, this isn't just eye candy. It's about speeding up investigations and improving threat visibility. Really excited about this new feature. And, again, we'll we'll highlight this a little bit more, and we'll show you how you can configure it in the demos coming up. The next item that I wanna highlight is a really new approach that we're trying to take around how we manage alarms, cases, and threats in general across the LogRhythm in ecosystem. This is something that we learned from the Exabeam New-Scale product line, the idea or concept of a threat center. In this release, it's the the beginning of that evolution to to in to bring the threat center as a single pane of glass to manage your alarms and your cases, in a unified experience. Like I said, this this is just the starting point. So watch in the next few quarters as we continue to innovate and make improvements here. It's gonna streamline workflows and bring a more effective analyst experience. And if you like the new scale UI, you're gonna feel just as home just at home in the Logarithm SIEM ecosystem as well. Mhmm. OK. Next, let's talk a little bit about the open collector architecture. This is an area that's near and dear to my heart, something we've been working on for quite a while. And in this release, we've added more capabilities making it even better. The first thing we've done is we've delivered our o three sixty five management activity beat. You might say, hey, Jake Haldeman. That sounds really familiar. And, Brook, it is familiar. That's actually something we've been collecting through the system monitor agent for a number of years. But what we're trying to do is we're trying to make some shifts in how we collect that data. And because this comes from an API, we feel like it'd be most effective collecting it through the open collector. So moving forward, you're gonna see that we're gonna be rolling out more beats to replace some of the API collection age, capabilities of the system monitor agent. We're gonna move that right into the the open collection architecture. So this gives you that ability to get visibility around audit and at man activity from the Office o three sixty five ecosystem. So if you're a Microsoft Office or Office three sixty five customer, this is a great way to get that log data into your LogRhythm SIEM. One of the other areas that we've delivered that is really exciting, and we'll have a demo for this at the end as well, is the ability to have a two way sync between your open collector and the web console. The reason this is big because there's many of us in the world that are familiar and comfortable working in in command lines, but it just takes time. It requires looking up, your reference documentation to know the exact kit commands, things like that. And so now with this new integration, any beats that are running on the OpenCollector will be be re reported in to the web console so that you can view and manage those beats all within the, web console user experience. And so the great thing with this is you can deploy a beat on the open collector. It'll be populated in the web console. And then from there, you can actually go and make changes, and it'll push it back to the beat. So it's a two way sync, making it so, beats that are already running will be brought into the web console, and then you can edit, modify those beats, or deploy new ones, and they'll automatically go through the, API into the web con from the web console into the open collector. Again, we'll highlight this a little bit more as we move over to the demo section. Alright. Let's keep going. The last area I wanted to talk about today is some of our platform updates. Security enhancements has been a big focus for us. Making sure that our ecosystem is secure and protecting you as a customer, so that your data isn't gonna be compromised as a LogRhythm SIEM customer. One of the things that we've done, and this is actually continuation of something we started last quarter, is updating the self signed certificates that we use within the system. There is tons of documentation, if you wanna go and change out our self signed certificates, but we've been rolling out updates to move it from a smaller encryption size to thirty seventy two bit. This makes the certificates just a little bit more secure and, follow some of the best practices of modern security. Another item that we've done is we've included a new YAML file with the installer to give you the exact component versions of the LogRhythm SIEM platform. The reason this is big is because in some customer environments, we have dozens of servers and a lot of, installs that go on. And now you can use this YAML file to ensure that every LogRhythm SIEM component that you're installing is the exact version necessary for that, LogRhythm SIEM release. Just to give you an example, LogRhythm SIEM 7. 22, with that release, there's couple LogRhythm components like the web console that might have a different version number. That might be LogRhythm, LogRhythm web consoles 10 dot something. And so this YAML file is gonna provide those exact version numbers so that you can go and validate it and ensure that it's accurate. This is just a great step for, ensuring the whole upgrade experience is, exactly what you need and right on par with the expectations. Alright. So I've quickly highlighted a lot of new features, lot of the new capabilities. Let's make a pivot over to, the video that Ryan made for us. And by the way, Daniel Moore. Everyone. Senior product manager Ryan Gamboa here coming you, coming to you via prerecorded demo. Thanks, Jake and Brook, for helping cover me today. I'm gonna go through three different demos, for you in the recording. And if you have any questions, ask Jake. Let's start off with the data processors and, their new ability to send to multiple clusters. So as Jake pointed out earlier, starting, with version seven twenty two, data processors or DPs have the ability to send data to multiple data indexer clusters. This configuration sends two identical copies of every log to both clusters, and provides cluster level redundancy, at the DX level. It supports up to two clusters per data processor. Each cluster can be single or multi node, and Windows or Linux is supported. So it's pretty SIEMple, but, keep in mind, you'll want to make sure both d x clusters are the same size. If if you do not do that, then you you you could end up in a situation where one is able to handle the load while the other one struggles. So good to keep those clusters, equal in in performance capabilities. Alright. So, let's jump over to, the setup here. I've got, I've already navigated to, the location where the the configuration file is for the mediator. So mediator config, and you're gonna want this I n I file. So you can just edit it. I've got it already open in the background here. But very, very SIEMple to to set up. There's this optional, piece down here. You may not already have this inside of your, INI file. It's in the documentation. Copy and paste, makes it really SIEMple. And then the thing we care about is this secondary DX cluster ID. So we need to, fill out which ID, we're gonna send this extra copy of the data to. You can find this, pretty easily, through going over to SQL Server, and running, this command here that just selects the different clusters. Again, this is in the documentation, so easy enough to copy and paste this, into a new query here in, management studio. Hit execute. And then I only have one cluster in in my demo here, but, you know, not not necessary, to, show you and have set up another cluster. You know, as as you build out more clusters, you're gonna have, cluster ID one, two, three, etcetera. So you can match the cluster name of where you want to send your data to to the cluster ID and grab that cluster ID that you care about. So, you likely have, most customers will just have one or two clusters. So, in this case, I'll just use number two as an example. I put that in. We're good to go. All I have to do is save this file and then restart the mediator so that, it will start sending to both clusters. Some other quick, but important tips, about about this. When it comes to searching, you're since we're sending an identical copy of every log to two different places, you could actually see duplicate results in your search results. If you're searching both clusters, you'll see logs show up twice. So to prevent that, you wanna make sure that you just search, a single repository, your your primary repository. So in the console here, if you come up to your settings, you can actually fill this out and say, hey. My query locations, here are the repositories that I want to query. So I'm I'm defaulting to my single cluster, but if I have multiple clusters, I can can I can make sure that that's unchecked, and then I won't see that duplicate result. So, just a heads up on that. Make sure you have it unselected. And then in the result of of a failover, you can just swap those and and make sure you're querying the one that that matters. Alright. Let's go to the next feature. And for that, I want to highlight, a strategic shift in our web console, that you'll see evolve over time. We're introducing the threat center here. As you can see, we've combined the alarms and the case tabs into this single view. It's a unified view, and it's the first step in our long term vision to create a more streamlined workflow for analysts. The goal is to get analysts to focus on the threat center as their holistic workspace rather than context switching between alarms and cases individually. It's a really small change today, but it's it's foundational for where we see the product headed down the road with threat management. Just a a quick call out. This really is just a navigational change. We've combined these two tabs together. I can switch between them. And all my workflows, right, if I'm working a case versus if I'm working an alarm, all the workflows here are exactly the same. No changes to any of that. It's really just how you get to alarms and how you get to cases. So short and sweet, that brings us to our last feature, which is, dashboards. Let's talk dashboards. You already know that you can visualize data across all your logs, not just events with the new data index or dashboards. And now in 07/22, I am super excited to introduce a new widget, that gives you at a glance metrics, something we're calling the metric widget. You can see it in action here, and I'll get into, the configuration here in a second. But with this widget, you know, it's all about boiling down your data into a single powerful number. You can easily display the the count, sum, minimum, maximum, or average of a supported field using, any query you want, just updating that Lucene syntax, and applied, at the widget level. So for example, you could do something like, displaying the total bytes transferred from a critical server. So let's jump into, the actual configuration. Just like any widget, it's gonna show up here at the top. I've I've reached the maximum here, so let's let's get rid of one. Configure. I'll delete this one, and we'll grab a new one. So, I now have two options in my drop down, top x widgets, which you are all hopefully very familiar with, and our new metric widget. So I can just drag this guy over, put it anywhere as usual. I can expand it as well, if you wanna take up more space. And, then to configure it, we've got our configuration menu here under configure widget. Alright. So, as usual, we have the ability to just auto create a title, or customize it. So I can do my widget. And, then I can also give it a a label. So you can see here in this one, I'm looking at number of accounts created in the last seven days, and I just gave it a label of 42 accounts. So that makes it, pretty quick for the, the user to to know what this number is. Maybe it's bytes. Maybe it's, you know, in terms of gigabytes. Right? It it allows you to be pretty specific around what that number actually is. So I'll leave label blank on this one. But, as as usual, I've got different, the different fields here that I can, that I can use just like in, my other widgets. So let me, actually switch over to this one because I've got a a good example already already configured. I'm I'm using the class classification field, and I'm saying count. Right? My modus count, this classification, over the last seven days, where common event is equal to user account created. So, I could also do, you know, in this case, common event might might make sense as well. And it it would should give me the same number, because I'm just counting, anytime I see this user account created. And then SIEMilarly, I've set one up where I've got, one that's removed. Removing might, might be a deletion or a disable. So I've I've got an an or statement here in my Lucene syntax that says, you know, count if user account is is deleted or account is disabled. And, again, on on this one, I'm looking at user impacted, but, again, it it might make more sense to do common event or classification. The the outcome should be the same in those cases. So, you'll notice though that, for something like common event, I only have, the ability to do mode count. That's because common event is, it's an alphanumeric field. Right? And I can't I can't do an average of of something that's not numeric. So in order to do some of those other modes, you need to have a numeric field something like, bytes in or bytes out. So, I've got bytes in here. And if I switch to bytes in, I can then do something like a sum or an average. And I don't have, you know, I'm filtering out here. These don't typically have data around bytes in, bytes out. But if I get rid of that and I do, you know, the average bytes in or bytes out, this would update. And, actually, I think I still don't have any logs in this, test environment that that does that. And to, you know, to, maybe prove that, you can you can double check. Right? Hey. This seems weird. Why why is it a an average of zero? I should be I should have something. So, I'm gonna go ahead and maybe look at the underlying logs for this. Right? I can go, say, view logs that match this query. And, of course, I don't have any logs here that show bytes in of of something. Right? So if I switch over to k bytes, packets, this is all blank, which is expected. I just don't have any in this test environment. But maybe I I switched over to accounts created and I said view logs, I I should have 42 results returned for this. Of course, I do. I can see that here. And then I can also validate that, you know, I was using, user account created common event, and I can see that here as well. That's my only result. So you have that option to drill into each of these and and see those underlying messages, just like you would any other widget. And then if we just go back to configure, we'll we'll go through the rest of these here. So we've got our widget filter. That mode, again, this is gonna change depending on the field that you select. And then, of course, we have the the change of color that's pretty standard for all of the, the widgets. Copy options as well as delete, which is, again, standard. So, any changes, make sure, you know, you you select, save here to get, get those saved. And when you come back, your changes aren't gone. But that pretty much covered it for the new metric widget. So happy dashboarding. This wraps up my demo for today. So thanks for tuning in. And remember, if you've got any questions, Jake's your guy. So back over to you, Jake. Thanks. I mean, I feel like Ryan was just live in person. That was great. I know. I I felt it right here. Thankfully, I convinced him not to give the folks your phone number and to call you at 2AM with those questions. I appreciate that. Before I switch over to my my demo, there there was a question in the q and a about, how do I get to this new interface? We still have the old web interface. Well, you know, the the great thing is with these new DX dashboards, as long as you're upgraded to a newer version of LogRhythm, when you click the new dashboard button, with that icon on the the web console, it'll actually prompt you which type of dashboard you wanna use. So if you're currently using LogRhythm, you go into the web console, and you're saying, how do I get these new widgets? How do I access this? Well, it it's in that new DX dashboard format. So you click the new dashboard icon, and it will give you the option to do a classic LogRhythm events dashboard or new, data index or DX dashboard. So go in, click new new widget, choose that DX dashboard option. That's where these new widgets will become available, and that's how you'll be able to start doing queries against all of your data rather than just that event cache. So, just wanna thank Vicky for that question. That that was a good one. With that, I'm gonna go ahead and stop sharing and switch over to a video that I recorded. And, we'll we'll watch through setting up the open collector for that two way sync. So, let me go ahead and stop here and switch to a screen share. Alright. So I'm gonna go ahead and hit play on this video, and I'll walk you through the process. You know, the the first thing here, we're looking at the web console. We go in and, you know, everyone can get access to see the open collectors on your system. But if you haven't yet set up the the two way sync, you're just gonna have blank pages, which is not ideal. So I'm quickly switching over to a open collector server, command line here. You see I I run a status check just to see what's running, and then I'm gonna jump right into setting up what we call the LR control service, the long running LogRhythm control service. There's tons of documentation on docs.logarithm.com or docs.executing.com under the LogRhythm section on how to get this set up. But it's a really SIEMple process. You can see I'm gonna do it in just a couple of minutes here. What what you first need to do is provide an entity ID of where the open collector is gonna live. You don't need to precreate the entity. You just need to be able to tell it which of the entities it's gonna go in. So here, I'm looking at my system. I say I wanted to go into the primary site. So I right click properties. I get that entity ID for primary site. It's one in my situation. Perfect. The next thing it wants to know is the IP address for the, admin API. This is usually your XM or your platform manager server. It could be other situations, of course, too. And then you need an API API key. So I jump over to that third party applications tab. I create an API key. But But don't forget, you have to do do a description. Very important. Very helpful too, really, when you're troubleshooting these items. Now to save time, I fast forwarded about a minute, to wait for it to be able to let me generate my token. And so you don't have to sit here waiting waiting for me to hit refresh until that becomes available. Just remember, it even says it takes about a minute before you can generate that API token. So I got my API key. I'm gonna go back into the Linux server, and I'm gonna paste it in. This is always the weird format how it replicates the the token a few times, but that's fine. You just hit enter at the end. And now it's gonna actually start up a a a new, beat that's gonna manage that communication back and forth. And so as soon as this is done, I I hit refresh on the web console just just to make sure we're getting the latest data. But when you switch over to OpenCollector, it's now gonna have the OpenCollector that we set up there. So now you can see the OpenCollector is up and running. We we see it in the web console. And this is actually a good reminder, learning experience for me to remember that, today, unfortunately, webhook beats aren't in the two way sync. And so I had a webhook beat already up and running. It's not populating. That's okay. That's by design. We're gonna fix that in the future. So now what I'm doing is I'm just quickly setting up a demo, beat of connecting to Okta Okta. Excuse me. So I just put in demo.okta.com, sample API key, then I give it the IP address of a system monitor agent with the JSON listener enabled, and then, I chose the default port there. Again, when I switch back to the web console here, I fast forwarded it about one minute because these things happen every minute. But, you now see that that shows one beat on that open collector. When I go to the beats page, it's now populating that beat. And I actually say, hey. You know what? I I have a typo on my Okta domain. I changed it to exademo.okta.com. I hit save, and now it's gonna actually push that information back to the beat. Fast forwarded it about one minute to give it that that sync delay, but now you can see the Okta URL is populating just how we'd like. So, this is really awesome because this now means you're able to start switching back and forth between command line, web console to manage your beats, making it so it's a little bit faster, a little bit easier than ever before to get the open collector up and running, bringing that data into your ecosystem. We're absolutely thrilled that that this is now available. So if you've been using an open collector, this is a perfect time to get that two way sync set up. You can see it only took me a couple minutes. You know, I needed an API key. Just needed to know my API information of how to talk to the the admin API, and I was up and running. So really excited about these new features, new capabilities. Let's go ahead and switch back to our slides to keep us, in check here. I think we're about ready to to move over to q and a. I know I've answered a couple questions in mine, but really quick before we do that, Brook, did you wanna talk about this slide a little bit? Sorry. I pressed the wrong button. Yes. So with that being said, this is, you know, if you wanna take a look into how LogRhythm intelligence works within LogRhythm SIEM, it's called, you know, our engine's called the UEBA engine, machine learning analytics. So take a look at this and download this one here, and, that can give you a really good sense of how we're adding that kind of level of of machine learning analytics within LogRhythm SIEM. And then, then then, actually, you know, I'll do this too before we go over the q and a. Jake is also speaking about this. And you're gonna see this in the docs, so you actually click these links here, or it could be the version of the QR codes. We'll see. But, we have two webcast coming up. One is on October 16 and the other sorry, on November 13. So the one on October 16 is called What is New is Old, How Agenda AI Threats Mirrors Securities, basically with Steve Moore, our chief security strategist here at Exabeam, and Matt Ryder, who is our global VP of customer support. He is on the front lines with customers all the time dealing with these things. So great pair for that webcast. They're going to explore, you know, lessons from antivirus, firewalls, SIEM, identity defenses, etcetera. And these will help us, you know, secure against today's, you know, modern and driven AI threat landscape. And then the other one is on November 13. I will be leading that one myself. I'll be doing that also with mister Matt Ryder as well as Finley Whitelop. Finley is not an Exabeam employee. She's an industry veteran. She has had some experience with a competitor. She's a security researcher, and she's a strategist. She's currently working on her doctorate. So that's gonna be a very fast at anyone, not just because I'm on there, Jake, but because of Finlay and and also Matt. So, Steve Moore, by the way, on October 16 to kinda toot Steve's, you know, horn a little bit, He was a former customer who has now become a chief security strategist with us. So he spoke about going through a breach and how Xavim end up saving his soul. So with that said, let's turn this over to the q and a session, if you can, Jake. Yeah. Absolutely. So I I've gotten a couple questions. One that I wanted to start with is, somebody sent me a message directly in, in Goldcast here. They said that they're just starting their partnership with Exabeam. They really wanna begin with the basics on, you know, installation configuration, and then kinda moving up from there. First off, that's the perfect way. If you're a new LogRhythm SIEM or even new skill analytics customer, that is the the best approach. You gotta start with the basics, then then you iterate from there. You know, I'm such a huge fan of that continuous improvement cycle in any security platform, especially logarithm SIEM, NewScale Analytics. But but so to to answer the question, what's the best road map or path to get started, at the basics then kind of maturing your ecosystem and your deployment from there? The the thing I'd highly recommend is two two resources. The first thing is LogRhythm University. We have a really, really, friendly subscription program where, you get all the training you want for one set price. You know, back in the day, we would do tokens and you're, like, doing all this conversion stuff. No more do you have to worry about that. You just pay one price per year, and you get all the training that you can handle. Absolutely great way to get started. Our training is updated regularly. The product management team, myself and Ryan, we, regularly talk to, our our training department to make sure that everything is in sync and that all the new features are being, brought over into the training content. The other thing I've mentioned is that within the LogRhythm web console, as well as New-Scale, we have a, resource center. In that resource center, we actually have some tutorials. So you get in app tutorials of how to use different components. So I highly recommend checking those out because those will give you the the guided tour within the the LogRhythm web console or in New-Scale, if that's what you're choosing. But it's just a great way to get you started learning the the basics of the product, learning the basics of, you know, the security practices of of our ecosystems, and then you can continue to mature from there. So great question. Hopefully, that gives you some good ideas. If you wanna learn more about the LogRhythm unit or, New Scale University, I guess, we or, Exabeam University, we'd call it now, not LogRhythm. Reach out to your account team. They can get your information. The other thing I'd mentioned is head to the community. I guess it's trip, suggestion number three. When you go to the community, mycommunity.xibun.com, and that's a unified community for New-Scale and LogRhythm SIEM, but we actually have a section in there called product coaching. You can go in there and you can actually get one on one time with some one of our pro professional services engineers, and they can do one coaching so that you can jump through and understand what's going on, ask direct questions, get that feedback, get best practices through that conversation. So, definitely recommend that as another alternative. Jake, I have a question. Yeah. I have a question here in the chat. So, can we get a preview of how log sources look like? Is there any improvement in this area? Yeah. You you know, every two weeks, we release our new knowledge base, which includes all the updates to the out of the box log source parsing that LogRhythm send up delivers. New scale analytics business as well. We call those content packs. SIEMilar idea of knowledge base and content packs. But, you know, if you wanna see the changes, if you wanna understand what's going on, head to the community, mycommunity.exibeem.com, and we actually have a knowledge base release notes in there. And we have a basic release note that will give you all the details of the the release, you know, the changes that came out come out in this new release. So they'll let you know that Microsoft Sysmon XML has been updated, things like that. But then we have an an advanced view. It's an Excel file, and it'll actually show you changes directly so you can start to get a deeper insight in in what those changes are, so that you can be prepared for them. We you know, we're we're constantly evolving our ecosystem for parsing. In my opinion, if we can't normalize the log correctly, it's not gonna help downstream with security analytics. So it's very important that we deliver these content packages or or knowledge bases regularly. Make sure you're getting the updates to them so that you can get the benefits that are available there. Thank you. By the way, we have one more question at least here in the chat, unless you have any more private, questions, Jake. But we do have a survey. Take a look at at the side of your screen there for the survey button. There's five quick questions. We'd love to get some input from you. So if you could just take a moment right now to go out and fill that survey, we would greatly appreciate that. Jake, last question that I have here and, again, we're open for more questions, so keep Wait. Hold on a sec. I'm doing this survey. So I'm just Sorry. What's that? I I said I'm trying to do my survey. I need a minute. No. Okay. Sorry. This is that was an unscheduled joke. So we didn't get the timing down. My apologies. The viewership just dropped off right now. With that said, Jake, mister Amy Werner says, just to clarify, OpenCollector no longer requires the Kubernetes container to run. Is that correct? Yeah. So so it sounds sounds like some confusion. We actually don't use Kubernetes with OpenCollector. We do use Docker. You know, we leverage the the community version of Docker. If necessary, the the, enterprise edition can be used. You know, just install that on your own with the licensing. But so we do still leverage, Docker for that, open collector ecosystem. The long running control service, the LR control service that we have that we demonstrated that I set up there, that basically runs as its own beat, which are you know, we call it beat docker container, same story. But that allows it to continue to monitor, manage, and update the beats that are running. So we we're still using the same Docker ecosystem as we previously done. So that's more streamlined in terms of how you can control and manage those those beats. Thank you. Question here is any integration with Cyber Reason EDR and Illumio ZTS? Yeah. You you know, I'd have to double check our our exact integration levels there, but I do believe we have some support with Cyber Reason. I'm not familiar with Illumino ZTS, so we'll have to check that out. But what I can recommend is if you're a LogRhythm user, log in to your web console, go to that resource center, and there's actually a new log source request button in there. So, I'd I'd encourage go put in a request for these, and we can then communicate directly one on one, and we can, work together to get in that integration in place. Okay. And I I should maybe make one comment here as a security researcher. So for every reason, EDR, decent it was decent. I'm not sure. There's not a lot of excitement left in the market for it. It's, having some issues. So my recommendation is, yeah, if you're committed to it, yes. You know, we're gonna commit to you and, you know, bring what you have. But I would start looking at other alternatives to where this is because of just the the issues that, is going on with the firm right now and the the credibility of that EDR tool itself. Sorry, former EDR nerd. So with that said is our question here. Any future updates to the pure JSON, JSON, receiver and the LRA agent, without Beats? Yeah. Mark, this is actually a great question because this is something we introduced a couple quarters ago. We introduced the ability for the JSON listener to receive any TCP JSON message. In addition to that, you can use, the elastic log stash protocol to send the the the, messages to the JSON listener on the system monitor agent. And so, you know, if you're looking to get JSON data into LogRhythm SIEM, go look at the advanced settings of your system monitor agent. There's two different ports that it can listen on. One is the straight TCP message. The other one is for that log stash protocol. So two different ways you can get JSON data into LogRhythm SIEM. You know, the great thing is the reason we call that open collection architecture is because the system monitor agent can, receive beats through that JSON message, but you can send direct data directly to them as well. And then on top of that, we have our JSON policy builder. If you, again, if you open up the resource center, there's a link to that. It's exibeam.com/jsonpolicybuilder, but quick link in the web console makes it easy. You can go in there. You can paste through the sample message. It'll help you generate the, the JSON parser. Head to the community if you have questions or problems with that. We are making some, improvements to that policy builder. So keep your eye out keep your eyes peeled because we're really excited about the changes and new workflow for it. But, great question. Definitely reach out if you have questions, getting JSON data in. It's something we really wanna make easy and SIEMple for customers. So we've done a lot in the last year. Great. So, by the way, folks, this is you were looking at the 07/2022 release of LRSM. Jake, when is that available for customers? We released, LogRhythm seven dot '22 October 1. So it's been out for almost a week now. It's available to for downloads if you have the, correct licensing on the community. We also have the license request page on it's been moved over to exabeam.com, but the link is through the community still to get your license, and you can download that and get upgraded, immediately. We already have a number of customers that have upgraded to 7.22. Really excited about it. It's, you know, one of my, you know, what a very exciting release. We haven't done any groundbreaking changes here, but we're adding some new functionality that's absolutely thrilling. Bringing in the new threat center concept, these new metric widgets, tons of new features available in login 7.20two. So go check that out today. So I'm not too familiar with the release cycle methodology. Do we go is everything just GA, or do you have an early release and then you have a GA release? Yeah. Good good question, Brook. You know, we we we we skipped the EA. We do a ton of internal testing. We spend about a month every quarter doing that finalization testing before we do a release. So we we we can have high confidence in our release cycle. And and you'll but like I said, our CEO instituted our promises made, promises kept. So every quarter, we're gonna have a GA release of LogRhythm SIEM that you can download and use and trust that it's gonna continue to be a a security tool that you can leverage. Lovely. Okay. Any other questions from the audience right now? Otherwise, we can wrap this up. Jake, do do you have any additional things that you wanted to say? You you know, I I just once again, thank you to everybody for joining us today. And, you know, the other side is we're using a new, webcast, system. Let us know how it is. If you have feedback, we'd love to understand what went well, what could have been better. And, you know, really, we're doing this for our customers. So let us know what we can do to to make this a better experience for you in the future as well. With that, I'll also give a a a shout out to Soren. He he sent us a a little joke. He said, wait. LogRhythm is not spelled correctly. That's right. Because we're LogRhythm, part of the Exabeam family. LogRhythm SIEM is a product, and Exabeam is our company name. So thank you, Soren. Always good to hear from you. Used to work with him. Now he's a customer. So, always great to have those types of interactions. So thank you for joining us. Yeah. I was reading I was going to the deck. I was like, he is what is he talking about? So okay. You understand it. Okay. Absolutely. Awesome. Well, hey. You know, feel free to reach out. Ryan and I are both very active in the the community. You know, you can always talk to your account teams to set up one on one conversations with the product management team as well. We're here to make sure that you have all your security concerns addressed and and handled. Thank you so much, Brook, for letting me join you today. Can't wait for those other webinars that you'll be joining, hosting soon too. Well, I thought I was joining you. So but, thank you everyone, and, you know, thank you to mister Ryan for recording that demo. And you're most likely gonna see him on the next webcast unless he, finds another way to squirrel out of this one. So Alright. Thank you, team. Take care, everybody.