21/09/2026
The latest updates to Defensys SIEM introduce enhancements across event search and visualization, source auditing, pipeline configuration, and new capabilities for correlation profiling.
Correlation
Exceptions in Correlation Rules
The new version of Defensys SIEM introduces functionality for quickly adding exceptions to correlation process. To manage the handling of correlation events, the correlator now supports an exception mechanism based on blacklists and whitelists. This mechanism enables different processing logic for events associated with blocked and trusted entities, such as IP addresses, users, or hosts.
Exceptions can be added manually by editing the active list or directly from the Event Search section using the exception builder. The builder allows users to select event attributes and create exception rules in a semi-automated mode.
The exception mechanism is an essential tool for tailoring the SIEM platform to customer-specific environments. It helps reduce false positives, lowers the workload on Tier 1 SOC analysts, and enables the SOC to focus on real threats.
Bulk rule updates
A new centralized update mechanism has been added for aggregation, segmentation, correlation, and normalization rules. This functionality allows users to update rules across multiple pipelines simultaneously directly from the Expertise section. As a result, it reduces routine administrative operations, lowers maintenance effort, and minimizes the risk of errors during expertise updates.
Source audit
The Source audit functionality has undergone significant improvements with new calculation methods and expanded configuration capabilities.
Defensys SIEM now introduces a new source audit policy type by pattern. This policy identifies a source based on a unique combination of event fields. It enables highly accurate source identification even when multiple sources originate from the same sending system, such as WEC.
In addition, a new moving average deviation calculation method has been introduced. This mechanism analyzes the average EPS of a source, where the threshold value is defined as a percentage of the incoming EPS. As a result, thresholds are automatically adjusted to match the average EPS of each individual source.
Users can also selectively disable source auditing for individual entry points when adding or modifying them. This makes it possible to exclude irrelevant pipeline elements from audit policies, reduce system load, and optimize data processing costs.
Overall, these improvements increase the accuracy of source monitoring and help detect anomalies more effectively while reducing false positives.
Search and visualization tools
Group Panel in event search
Queries with grouping now display a dedicated group panel that allows analysts to drill down into the list of events within each group. For all queries using GROUP BY, the event workspace is automatically divided into two zones: grouped results on the left and the corresponding event list on the right. This improves analyst efficiency and reduces investigation time when analyzing incidents, creating correlation rules, or performing Threat Hunting activities.
Search across multiple data stores
Users can now perform searches across multiple data stores located in different databases simultaneously. This accelerates analysis in distributed deployments and reduces the time required to prepare reports.
JSON field filtering
Filtering by nested JSON fields (excluding arrays) is now supported using the =, !=, and LIKE operators. RQL has also been extended with type conversion functions for more precise filtering. These enhancements expand search capabilities for JSON-based fields and improve query performance when working with unstructured data.
Maps in dashboards
The following dashboard widgets have been added:
Cluster map - displays data as clusters of points with nearby coordinates.
World map - displays data grouped by country.
Geographical visualization provides new opportunities for building high-level SOC monitoring dashboards and improves overall ability.
Additional enhancements
Integration with Defensys TIP: the Defensys TIP endpoint now forwards events for indicator of compromise (IoC) extraction, automating data enrichment and strengthening proactive threat detection.
New MongoDB entry point: enables collection of application logs from MongoDB for subsequent processing in the SIEM.
Collector space management: during import, users can select the target connection, while disabled collectors can be reassigned to a different workspace. This simplifies migrations and operations in hybrid environments.
Quick start improvements: during deployment, the system now automatically creates preconfigured entities, including sample pipelines, a demo expertise package, baseline and correlation events, and dashboard presets. The SIEM is ready for demonstration immediately after installation, accelerating team onboarding and proof-of-concept projects.
"With the Defensys SIEM 2.6 and 2.7 releases, we introduced several important user-focused capabilities that directly improve the day-to-day work of SIEM analysts. The update streamlines analyst workflows and significantly expands capabilities for event analysis, correlator profiling, and source monitoring. These enhancements help organizations configure the SIEM more effectively, reduce the operational effort required from security teams, and enable the SOC to focus on real threats" – noted Andrey Chechetkin, Defensys CEO.