What's New?
Version 5.3
📅 Smart Monitor version 5.3.0 released on February 2, 2026.
Critical Changes
Pay attention to the section with critical changes.
Core
⚡️Changes- Updated appearance of
Metricvisualization - Added ability to input custom values for filters with
SelectionandMulti-selectiontypes in dashboards - Now when editing visualization on dashboard, changes are applied automatically
- In
Search Anywhere connectionsettings with typesDB,ClickHouse,Hadoopfixed issue with long loading ofJDBC driverslist - In
Search Anywhere connectionsettings with typeClickHousefixed incorrect connection string formation - Added ability to open link in new window in
HTML visualization
Core: Engine
⚡️Changes- Added ability to configure access to
ClickHousethrough user role settings inSmart Monitor - Now in
searchcommand available field comparison syntax:search <field>=<field> - Added
excludeparameter tosourcecommand, allowing to exclude indexes from search - Added ability to create fields with dynamic names in
evalcommand
- Added output of full error message when
Search Anywhere connectioncheck fails with typesDB,ClickHouse,Hadoop - Added support for
keepevicted,startswithandendswithparameters intransactioncommand transactioncommand now works 10 times faster- Added functions
eval to_timezone(<epoch>, <timezone>),eval from_timezone(<epoch>, <timezone>) - Added function
peval mvdedupin searches byClickHousesource type - Added functions
aggs median/percin searches byClickHousesource type - Now possible to break lines in search query
- Fixed operation of
renamecommand using characters(,)and.in rename pattern - Fixed incorrect field output after
fields/tablecommands or after adding field viaevalin search byClickHousesource type - Fixed operation of following commands translated to
ClickHousesource type: - Added ability to use special characters in index names for
OpenSearch/Elasticsearchconnections:source os:os_sa_connection:'audit_t-2026':10
Core: Job Scheduler
⚡️Changes- Added ability to configure display order of incident
Additional fieldsin active actionCreate Incident - Added ability to add custom headers in active action
Send Email - Now tokenization supported for
Scorefield inRisk Score Assignmentactive action
- Now in
Server SPmode possible to create local tasks - Added filter in job list allowing to view local and SP-job separately in
Server SPmode - Added ability for multiple editing of
SP-job
User Behavior Analytics
⚡️Changes- On
Objectspage now available filtering by base and additional fields - Added interface for displaying duplicates
- Added ability for manual launch of profiling policies
- Table with profiling policies now displays statistics of last 5 runs
- Added ability to filter objects in profiling policies and scoring calculations
- Now supports fixing common time interval for all objects used when calculating profiling policies and scoring
- Added ability to clone and bulk edit for profiling policies and object fill configurations
- Added ability for bulk deletion of objects
- Redesigned interfaces for creating and editing objects
Incident Manager
⚡️Changes- New interface for displaying incident history:
- Added filtering by history
- Simplified comment input, expanded text styling functions
- Added display of total number of incidents
- Added ability to configure field order in
Additional FieldsandIncident Detailssections in incident card
Move To ClickHouse
Improvements- Extended list of compatible data types
- Added parameters for more flexible data transfer configuration
- Added mechanisms for stopping data transfer and tracking status
RSM 2.0
⚡️Changes- Added ability to configure graph display using levels
- Added ability for import/export of layers and metrics
Inventory
Improvements- Now possible to input custom values in asset filters
- Now possible to configure PostgreSQL connection timeout
- Optimized getting statistics on number of assets
- Fixed
Request failed with status code 503 Service Unavailableerror when initializing module inModule Settingssection - Now filters on assets page are not reset after going to specific asset and returning back
- Fixed error migrating
createdandupdatedfields to PostgreSQL
Content Management
⚡️Changes- Added ability to upload tag types
Smart EDR
⚡️Changes- Added support for SSL connection to Kafka with possibility of one-way and two-way authentication
- Added telemetry analysis dashboard
- Now pipelines specify correct names of Kafka topics used in EDR "out of the box"
- On
Smart EDR: Detected Threatsdashboard added handling of null values for fields
Smart Code
⚡️Changes-
Now module supports Continent 4 components
-
Redesigned
Continent: Attack Detectordashboard (supported for both Continent versions):- Added panels with basic information about selected device (ID, IP address, node key status, table with main node information)
- Added panels with general and detailed attack information (attack intensity, classification, attack information, top-10 attack sources and targets)
-
Redesigned
Continent: Access Serverdashboard:- Added panels with basic device information (ID, IP address, access server certificate expiration date, node key status, number of connected users relative to license)
- Added panels with user and event information (table of active users, connection log, unauthorized access events, reference table for user certificates - X.509 data and expiration date)
-
Enhanced
Continent: Architecture and Configurationdashboard:- Added panel with pairwise connection graph (VPN network scheme of AKSH)
-
Added task for sending IPS attacks to Incident Manager
-
Implemented automatic incident creation when user certificate expires
Critical Changes
- Added new fields to task structure:
job_category,actions.incident.order_fields, field typescorechanged fromfloattotext - New fields in
Incident Manager: Card Settingssection now cannot be created with.character in identifier
Version 5.3.1
📅 Smart Monitor version 5.3.1 released on April 29, 2026.
Critical Changes
Please pay attention to the section on critical changes.
Core
⚡️Changes- Updated license format, now you can track expiration dates and support for each module on the
Overviewpage
- Fixed automatic focus reset in text fields of visualization settings
Metric - Added scaling of the search query editor when pasting a query from history
- Fixed display of value instead of name in some cases in filters with
Choicetype on dashboards - In the
Tablevisualization, fixed an error that occurred when configuring color display by field withnullvalue - Transition from the
Metricvisualization on the dashboard page now opens a non-empty search query - Fixed date display in tooltips of the
Metricvisualization - Fixed white background appearance in the
Metricvisualization when no background color is configured - Fixed substitution of token values from the
Metricvisualization into dashboard filters and visualization title - Added additional escaping of returned field values in quick searches
Core: Engine
⚡️Changes- Added
matchcommand, allowing filtering and enriching data by field values from another source
- Added cluster setting for internal request timeout:
sme.core.internal_timeout
- Fixed
joincommand operation: now the command does not output an error if matching fields are not found in any document. Now in this case, the document will not be joined to the result and a warning will appear that the field is not in all data - Fixed
transactioncommand operation aftermakeresultscommand - Fixed formation of result table fields after executing
timeaggscommand - Fixed millisecond truncation in
tostringfunction ofpevalcommand - Fixed writing background query to disk if search results contain a number with
BigDecimaldata type
Core: Job Scheduler
Fixes- Fixed search task update notification: now it contains the correct identifier
User Behavior Analytics
Improvements- Added cluster setting for UBA module index rotation
Incident Manager
Fixes- Incident index rotation format standardized to
<yyyy.ww>when creating an incident manually - Fixed incorrect tokenization of nested fields in
Aggregation Settings(e.g., user.name) - Fixed display of custom workflow statuses in incident cards and aggregations; now available transitions are loaded correctly
- Fixed display of dynamic options in responsible list when creating and editing incidents
- Fixed icon action overlap in incident table during horizontal scrolling
- Fixed display error when editing workflows
Move To ClickHouse
⚡️Changes- Added queue for simultaneous transfer of large number of indexes
- Added setting to override field type
- Fixed handling of
parent CBtrigger: added retry policy
RSM 2.0
Fixes- Metric status now updates correctly within the service
- Fixed processing of incorrect graph configuration with dependencies on non-existent services or metrics
- Now snapshots of metrics and services are created when importing a layer, as when creating them normally
- Fixed error that prevented layer deletion
Inventory
Fixes- Fixed display of source lists and linking fields when there are many elements
- Fixed display of manual changes to additional fields of automatically created assets
Lookup Manager
Fixes- When working with nested fields in a lookup, existing values are now updated instead of creating new fields
Knowledge Center
Fixes- Users with
write_allrights can now save files and add blocks in notes
Smart Beat Manager
Fixes- Fixed error where internal database size increased too quickly
Smart Beat
Fixes- Fixed error in tag binding to agents
- Service now stops after agent removal
Critical Changes
- Updated
MITRE ATT&CKwork logic, now supports loading matrix versions not lower than 18.0, operation of already loaded matrices will not change
Version 5.3.2
📅 Smart Monitor version 5.3.2 was released on June 22, 2026.
Critical Changes
Pay attention to the section on critical changes.
Core
Improvements- Added support for
ClickHousedrivers version higher than0.9.6
- Fixed an issue where part of the filter settings interface on the dashboard was hidden beyond the page boundary
- Now when navigating to the results of a background task, a new query is not launched instead of displaying results from disk
- The search interval now correctly applies to the query when launched via the
Ctrl+Enterkey combination - Fixed the display of the
JDBC Queriespage in module settings when special characters are entered in the search bar - In the
Bar Chartvisualization, fixed display when theVertical Layoutoption is activated on theMaintab - In the
Single Valuevisualization, fixed rendering of negative values when theShorten Large Numbersoption is disabled - In the
Single Valuevisualization, trend is now built not only when usingtimechartandtimeaggscommands - Now when changing filters located inside visualizations on the dashboard, the transition to the top of the dashboard no longer occurs
- Fixed work with
SP-tasks: editing, assigning tags and access rights now works correctly - Fixed field statistics display error on the search page: Error while calculating sidebar :
OpenSearchParseException[Failed to parse content to map]
Core: Engine
Improvements- In the
evalcommand, basic mathematical operations now support working with arrays
Core: Job Scheduler
Fixes- In the
Create Incidentactive action, if the field referenced by the token contains anullvalue, a dash is now substituted in the incident description - When the
Do Not Run for Each Resultoption is enabled in theWrite to DBactive action, one request is now formed for all search results
Incident Manager
Fixes- Fixed pagination calculation: the number of pages now corresponds to the selected number of rows per page
- Now workflow transition can be reassigned from one status to another without errors
- Added validation of required fields when creating (
TitleandDescription) and editing (SeverityandResponsible) incidents
Inventory
Fixes- Fixed hanging of the asset database update process
- Eliminated cases of data loss when processing data from
OpenSearchindexes by the engine - Asset cleanup by
TTLno longer triggers if the option is active in at least one configuration
Knowledge Center
Fixes- Fixed display of incident details in notes: visibility and field order are now taken into account, and values of
Choice,Multi-choice,Date, andmarkdownfields are displayed correctly
Smart Beat Manager
Fixes- Fixed operation of
StatusandConnectionfilters on theClientstab
Critical Changes
- Now, in the incident manager's active action, information about the calling user is always passed in the format:
Previously, the
"user": {
"name": ...,
"backend_roles": [ ... ],
"roles": [ ... ]
}userobject could contain other fields. For example,textorvalue