forked from arkime/arkime
-
Notifications
You must be signed in to change notification settings - Fork 0
/
CHANGELOG
2467 lines (2330 loc) · 116 KB
/
CHANGELOG
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
433
434
435
436
437
438
439
440
441
442
443
444
445
446
447
448
449
450
451
452
453
454
455
456
457
458
459
460
461
462
463
464
465
466
467
468
469
470
471
472
473
474
475
476
477
478
479
480
481
482
483
484
485
486
487
488
489
490
491
492
493
494
495
496
497
498
499
500
501
502
503
504
505
506
507
508
509
510
511
512
513
514
515
516
517
518
519
520
521
522
523
524
525
526
527
528
529
530
531
532
533
534
535
536
537
538
539
540
541
542
543
544
545
546
547
548
549
550
551
552
553
554
555
556
557
558
559
560
561
562
563
564
565
566
567
568
569
570
571
572
573
574
575
576
577
578
579
580
581
582
583
584
585
586
587
588
589
590
591
592
593
594
595
596
597
598
599
600
601
602
603
604
605
606
607
608
609
610
611
612
613
614
615
616
617
618
619
620
621
622
623
624
625
626
627
628
629
630
631
632
633
634
635
636
637
638
639
640
641
642
643
644
645
646
647
648
649
650
651
652
653
654
655
656
657
658
659
660
661
662
663
664
665
666
667
668
669
670
671
672
673
674
675
676
677
678
679
680
681
682
683
684
685
686
687
688
689
690
691
692
693
694
695
696
697
698
699
700
701
702
703
704
705
706
707
708
709
710
711
712
713
714
715
716
717
718
719
720
721
722
723
724
725
726
727
728
729
730
731
732
733
734
735
736
737
738
739
740
741
742
743
744
745
746
747
748
749
750
751
752
753
754
755
756
757
758
759
760
761
762
763
764
765
766
767
768
769
770
771
772
773
774
775
776
777
778
779
780
781
782
783
784
785
786
787
788
789
790
791
792
793
794
795
796
797
798
799
800
801
802
803
804
805
806
807
808
809
810
811
812
813
814
815
816
817
818
819
820
821
822
823
824
825
826
827
828
829
830
831
832
833
834
835
836
837
838
839
840
841
842
843
844
845
846
847
848
849
850
851
852
853
854
855
856
857
858
859
860
861
862
863
864
865
866
867
868
869
870
871
872
873
874
875
876
877
878
879
880
881
882
883
884
885
886
887
888
889
890
891
892
893
894
895
896
897
898
899
900
901
902
903
904
905
906
907
908
909
910
911
912
913
914
915
916
917
918
919
920
921
922
923
924
925
926
927
928
929
930
931
932
933
934
935
936
937
938
939
940
941
942
943
944
945
946
947
948
949
950
951
952
953
954
955
956
957
958
959
960
961
962
963
964
965
966
967
968
969
970
971
972
973
974
975
976
977
978
979
980
981
982
983
984
985
986
987
988
989
990
991
992
993
994
995
996
997
998
999
1000
NOTICE: Please see https://arkime.com/faq#upgrading-moloch for upgrading info
OpenSearch Versions:
* Arkime >= 3.0.0 supports 1.x or 2.x
Elasticsearch Versions:
* Arkime >= 4.0.0 supports ES >= 7.10.0 or 8.x, not 9.x or later
* Arkime >= 3.0.0 supports ES >= 7.10.0, not 8.x or later
* Moloch >= 2.7.0 supports ES >= 7.4.0, not 8.x or later
* Moloch >= 2.2.0 supports ES >= 6.8.0 or >= 7.1.0, not 8.x or later
* Moloch >= 2.0.0 supports ES >= 6.7.0 or >= 7.1.0, not 8.x or later
* Moloch >= 1.5.0 supports ES >= 5.5.0, 6.x, not 7.x or later
* Moloch >= 1.0.0 supports ES >= 5.5.0, 6.x (not prod tested, only for new installs), not 7.x or later
* Moloch >= 0.50.0 supports ES >= 5.5.0, not 6.x or later
* Moloch >= 0.18.1 supports ES 2.4.x, >= 5.3.1 not 6.x or later
Node Versions:
* Arkime >= 5.4.0 requires NodeJS >= 20.0.0 or < 21
* Arkime >= 5.0.2 requires NodeJS >= 18.15.0 or < 21
* Arkime >= 5.0.0 requires NodeJS >= 18.0.0 and < 19
* Arkime >= 4.2.0 requires NodeJS >= 16.0.0 and < 19
* Arkime >= 3.4.0 requires NodeJS >= 16.0.0 and < 17
* Arkime >= 3.0.0 requires NodeJS 14.x
* Moloch >= 2.4.0 requires NodeJS 12.x
* Moloch >= 2.0.0 requires NodeJS 10.x
* Moloch >= 1.6.0 requires NodeJS 8.x, 8.12 or later
* Moloch >= 1.0.0 requires NodeJS 8.x
* Moloch >= 0.20.0 requires NodeJS 6.x
* Moloch >= 0.18.1 requires NodeJS 4.x
NOTICE: Restart wiseService before capture when upgrading
NOTICE: Cross-cluster Shortcuts require you to not restart all your viewers at once after upgrading
NOTICE: Create a parliament config file before upgrading (see https://arkime.com/settings#parliament and https://arkime.com/faq#how_do_i_upgrade_to_arkime_5)
5.5.1 2024/12/xx
## Release
- #3011 Add db.pl to docker.sh
- #3015 Node 20.18.0
## All
- #3010 fix lmdb cont3xt and users DB
## Cont3xt
- #3012 add basic databricks support
- #3016 fixed cont3xt health check request every second - should be 10s
## db.pl
- #3017 New field-list, field-rm commands
## Viewer
- #3008 fixed sessions column sorting not working in some cases
## WISE
- #3012 add basic databricks support
5.5.0 2024/11/11
## Release
- #2925 Node 20.17.0
- #2956 CyberChef 10.19.2
- #2992 Now have official docker container at https://github.com/arkime/arkime/packages
## All
- #2947 new user-role-mappings section for oidc/header auth
- #2950 support authRedirectURIs list (thanks @divinehawk)
- #2954 Fix form/oidc authMode failure to start when deleting old sids failed
- #2964 Add to files tab lastPacket timestamp and start/finish processing time stamps
- #2995 Switch to arkime-iptrie
## Capture
- #2924 _closeNow rule operator
- #2929 Update ja4 for alpn edge cases
- #2940 cert.ja4x* now work with rules/wise
- #2959 New --libpcap option for libpcap offline processing vs
--scheme for new faster method
- #2969 Add back host.dns to rules
- #2991 Add initial IP TTL and TCP Seq number fields
- #2996 pcapDir defaults to /opt/arkime/raw and pluginDir defaults to /opt/arkime/plugins
## db.pl
- #2946 fix sync-files not handling multiple nodes, or dash containing nodes
correctly (thanks @dennisse)
## Multies
- #2962 fix caTrustFile not working with multies
## Viewer
- #2926 cronQueries=auto now uses the node name in the unique key
- #2935 spigraph treemap shows unique Dst/Src IPs
- #2945 add iframe 'allow' option
- #2965 fix millisecond timestamp setting not saving
- #2966 Add the ability to hide tags in the session table
5.4.0 2024/08/05
## Release
- #2885 Node 20.15.1
## All
- #2892 backoff recurring health requests if they fail
- #2898 support using env vars for many config settings (thanks @Jc2k)
## Capture
- #2866 for s3/sqs scheme support standard AWS credentials methods including
env vars, --profile ~/.aws/credentials or config, and meta data service
- #2869 scheme mode for local files support monitor mode
- #2870 log error with pcap_dispatch (thanks @vpiserchia)
- #2873 New --command-socket option to enable a unix domain control port for
controlling capture
- #2875 New --command-wait option to use when no offline files on command line
- #2877 command-socket add-dir now has options to override command line
- #2891 fix JA4 when num extensions or ciphers is > 99
- #2893 support deleting pcaps when ignoreErrors set (thanks @vpiserchia)
- #2894 support --op/--delete with scheme commands
## Cont3xt
- #2879 Added skipChildren query string parameter
- #2880 Only focus on search if no search parameter
- #2890 Date formatting in link groups
- #2903 Added Quad9 tidbits on domains and ips
- #2904 Added Email Reputation integration
## Multies
- #2865 form or oidc require usersElasticsearch to be set for multiES
## Viewer
- #2884 Improve hunt parallelization, run 2 sessions per node at once
- #2886 Expire logging improvements and multiES disable
- #2896 added protocols/tags to default info column fields
- #2899 fixed viewer not loading writer-s3 files since Arkime 5.3.0
- #2900 Support hunts on multiviewer, still need a normal viewer to run
hunts
5.3.0 2024/06/27
## Release
- #2821 CyberChef 10.19.0
## All
- #2842 requiredAuthHeaderVal can be a comma separated list
## Capture
- #2820 fix puny dns entries missing from all list sometimes
- #2832 arkime_config_interfaces.sh fixes (thanks @dennisse)
- #2833 support processing a directory from s3
- #2835 fix crash with bgp parsing and shifting time
- #2835 create pcap files with at least config snapLen
- #2835 fix files with no processed packets hanging capture
- #2856 suppport AWS SQS for notifications to process new S3 files
- #2856 fix scheme pcap processor with corrupt pcap files
- #2859 log error if maxStreams is too low
## Cont3xt
- #2823 added "Add Field" button to top of overview form
- #2829 new DNS integration card
## Multies
- #2853 don't initialize Auth subsystem
## Parliament
- #2849 fix form auth not styling correctly
- #2857 display cont3xt/wise links for non admins
## Viewer
- #2817 new maxSessionsQueried setting, default 2MM
- #2819 hide noFacet fields from being columns
- #2824 add ability to delete shards from ES Shards tab
- #2834 improve forcedExpression help
- #2840 fix downloading pcap of scheme uploaded items
- #2843 new %NODEHOST% substitution
- #2845 fix s3 download to work with LocalStack
## WISE
- #2834 fix azure ip link
5.2.0 2024/05/28
## BREAKING
- db.pl upgrade is required when upgrading from 5.1.2 or earlier
## Release
- #2779 Using https://localhost or https://127.0.0.1 no longer requires --insecure
- #2779 Configure now prompts for OpenSearch/Elasticsearch user/password
- #2783 New debian 12 package
- CyberChef 10.18.3
- #2797 Node 18.20.3
## All
- #2772 fix OIDC login crash
- #2773 Users tab saves automatically on change
## Capture
- #2748 icmp community id support
- #2766 VLAN or VNI can be used in session ids, controlled by sessionIdTracking
- #2784 Added DTLS JA4 support
- #2791 udp databytes was too large when padded
- #2796 Added DTLS JA4S support, requires new ja4plus plugin also
- #2799 support multiple EOL for JA4T and JA4TS
## Cont3xt
- #2795 support adding clickhouse integrations
## db.pl
- #2798 fix expire/rotate warnings
## Viewer
- #2741 save session table info column fields
- #2800 scrubbing pcap of compressed/encrypted packets deletes references
instead of failing
5.1.2 2024/04/23
## Release
- #2759 CyberChef 10.17.0
## Capture
- #2756 parse SMB dialect
- #2758 fix rules not always matching "0" for non array integer fields
## Viewer
- #2765 add esadmin functionality to multiviewer
5.1.1 2024/04/15
## Release
- #2752 Node 18.20.2 (EL 7, Ubuntu 18 still on 18.19.1)
## Capture
- #2732 rules support NOT string and integer fields
- #2746 fix DNS parser PUNY length checks
- #2744 fix empty pcap files hanging capture
## Viewer
- #2745 don't autocomplete values starting with a quote
5.1.0 2024/04/04
## Release
- #2667 support Node 20
- #2734 Node 18.20.1 (EL 7, Ubuntu 18 still on 18.19.1)
- #2737 CyberChef 10.15.0
## Capture/Viewer
- #2694 New DNS parser that captures all the answers, enable with
dnsOutputAnswers=true (thanks @mcgillowen)
## Capture
- #2674 Fix filelist not working in scheme mode
- #2679 cert.alt can be used in rules
- #2699 Disable reader s3 download timeout
- #2726 Fix ZSTD_decompress missing for some builds
## Cont3xt
- #2683 lock integration settings
- #2719 snap to dates
- #2730 Arkime/OpenSearch/Elasticsearch integration had insecure logic backwards
## Viewer
- #2668 fix pcap export with only default time range and no date param in url
- #2680 add default user settings to viewer config
https://arkime.com/settings#user-setting-defaults
- #2681 fix unique of numerical fields
- #2701 Make sure pcap reassembly doesn't starve viewer
- #2704 Support viewUrl having a path
- #2705 Support querying non Arkime indices, enable with
queryExtraIndices (thanks @mmguero)
- #2718 Green on black theme improvements, Elyse's fav now
- #2735 help improvements
- #2736 help improvements
5.0.1 2024/02/20
## Release
- #2631 CyberChef 10.6.0
- #2648 Build for Ubuntu 24.04
- #2655 Support rpm fips installs again
- #2558 Node 18.19.1
## Capture
- #2634 add esp packet stats (fixes #1116)
- #2638 support readTruncatedPackets on live captures
## db.pl
- #2633 noprompt outputs less warnings
- #2639 fix init not working with large number of indices
## JA4+
- Fixed memory leak
- Fixed JA4H issue with long cookies
## Parliament
- #2645 Fixed issues not being detected
- #2659 Fixed parliament crashing if userPrefix not set
## Viewer
- #2632 fix field labels not expanding fully
- #2637 fix session detail grip
- #2668 fix pcap export with only default time range and no date param in url
## WISE
- #2653 set a threatstream.indicator field
5.0.0 2024/02/06
## BREAKING
- #2297 s3Compression/simpleCompression now defaults to zstd
- #2297 s3WriteGzip removed, use s3Compression=gzip for gzip instead of new zstd default
- #2297 s3GapPacketPos defaults to TRUE
- #2297 enablePacketDedup defaults to TRUE
- #2299 #2308 authMode defaults to digest now
- #2312 removed old v1 viewer APIs
- #2349 parliament password removed, must configure common auth via the UI before upgrading or manually in the config file see [parliament](https://arkime.com/settings#parliament) and [how do I upgrade to 5](https://arkime.com/faq#how_do_i_upgrade_to_arkime_5)
- #2402 WISE/tagger must now use http.request.FIELD/http.response.FIELD when referencing header defined with headers-http-request/headers-http-response
- #2450 Centos 7 build no longers includes pfring support
- #2453 Increase simpleCompressionBlockSize default to 64000
## Release
- #2448 zstd 1.5.5, nghttp2 1.57.0, maxmind 1.7.1, yara 4.2.3
- #2443 Centos 7, Ubuntu 18, Alpine use unofficial builds of node
- #2543 node v18.19.0
- #2447 support building on alpine
- #2549 use configure prefix more places (thanks @vpiserchia)
- #2584 AL2023 & Ubuntu22.04 ARM builds
## All
- #2316 programs support same config file formats (ini/json/yaml) and retrieval (file, elasticsearch)
- #2419 json/yaml config file formats now allow arrays instead of comma/semi separated
- #2299 #2308 authMode setting added
- #2299 #2408 #2463 added authMode: basic, form, basic+form, basic+oidc, headerOnly, header+digest (same as header), header+basic
- #2387 notifiers for parliament and arkime merged conflicts mitigated by appending "Parliament" to parliament notifiers
- #2396 drop privileges is now AFTER http(s) list
- #2509 add optional login message for form auth
- #2511 new authOIDCScope setting
- #2482 new logoutUrl setting
- #2571 new scheme pcap reading
- #2618 better error message when can't use OpenSearch/Elasticsearch on startup
## Capture
- #2295 moloch converted to arkime
- #2312 override ips can now set any field
- #2312 overrideIpsFiles setting
- #2314 packetDropIpsFiles setting
- #2390 can have negative cert.validDays/cert.remainingDays (thanks @mcgillowen)
- #2390 added cert.remainingSeconds/cert.remainingSeconds (thanks @mcgillowen)
- #2390 cert.remainingDays is now based on the firstPacket of session instead of current time (thanks @mcgillowen)
- #2409 JA4 support
- #2409 JA3/JA4 support for smtp STARTTLS
- #2297 always build zstd (except arch)
- #2517 new custom-fields-remap feature
- #2186 count the number of http methods per session
- #2528 new oui.txt location, some names have changes, fixes #2347
- #2539 new tls:has_esni tag if the client hello has esni
- #2553 fix rules range matching not working always
- #2554 support fieldSet tcpflag rules
- #2575 fix startup complaint about aliases, category, and transforms
- #2576 support different dlt for pcap-over-ip
- #2592 fix sometimes not identifying quic protocol correctly
- #2600 add tls:has_ech tag (thanks @renini)
- #2614 new kafka-config section
- #2622 fix malicious quic packet crashing capture
## Cont3xt
- #2121 new bulk UI and support for bulk queries
- #2271 lots of keyboard shortcut improvements
- #2383 new array syntax for links substitution
- #2382 new OpenSearch/Elasticsearch integration (config file only)
- #2441 new csv/json file/url/redis integration (config file only)
- #2385 new viewRoles in config file per integration to control access
- #2407 transfer ownership of resources
- #2437 new csv/json data source supports
- #2441 new redis data source support
- #2507 demoMode added
- #2527 skipChildren added
- #2532 new wise integration
- #2580 add links to integration search page from card
- #2565 added punycode decoding
## db.pl
- #2588 db.pl won't try and backup indices that don't exist
- #2588 db.pl backup cont3xt indices
## ESProxy
- #2483 #2484 support field updates/deletes
## Viewer
- #2296 removed x-moloch-auth
- #2392 files/history/stats now have cluster dropdown for multiviewer
- #2402 http.request.FIELD and http.response.FIELD supported
- #2404 add editor for resources
- #2407 transfer ownership of resources
- #2482 added uploadRoles to control who can upload
- #2501 add defaultTimeRange setting
- #2521 add footerTemplate setting
- #2525 add [config setting](https://arkime.com/settings#spiViewCategoryOrder) to set spiview category order
- #2523 resize session detail field label/values
- #2552 added %URIEncodedText% for URI encoded substitution (thanks @vpiserchia)
- #2574 fix longstanding issue with backslash search and SMB
- #2601 patch cyberchef xss vuln (https://github.com/gchq/CyberChef/issues/1468)
- #2606 zstd sometimes didn't read all packets
- #2607 improved session detail display
- #2621 session detail link a link now, multi select info column items now
## Parliament
- #2377 dashboard-only mode removed, if you want users to just see the dashboard don't assign them the parliamentUser role
- #2395 configuration is now stored in opensearch/elasticsearch
- #2530 add Users page
## WISE
- #2537 new urlScrapePrefix/urlScrapeSuffix used with urlScrapeRedirect
- #2537 new jsonl format supported
- #2588 don't setup auth if --webconfig isn't used
4.6.0 2023/10/16
- release - curl 8.4.0
- release - fix viewer systemd file
- capture - fix zstd hanging capture on full buffer
- viewer - corrupt http session decoding might hang viewer
- viewer - handle uncompressing pcap errors better
- viewer - role check in UI didn't always work
- all - handle cookies encoded with bad proxy
4.5.0 2023/09/13
- release - node 16.20.2
- release - added missingok to default logrotate for arkime
- capture - dns answers were double parsed
- capture - custom-fields honors viewerOnly:true
- capture - added dns.https fields
- capture - added cert:certificate-authority tag (thanks mcgillowen )
- cont3xt - remove raw view button for link groups on the cont3xt search page
- cont3xt - Overview shortcut
- cont3xt - fixed overviews not updating on switch
- db.pl - don't allow '.' to be used for sync/add path
- viewer - fixed ipv6 session display issues when :: in ip
- viewer - http display rewritten to not depending on nodejs internals
- viewer - gpe display improvements
4.4.0 2023/08/02
- release - cyberchef 10.5.2
- release - update arkime_update_geo.sh to use different manuf location
- all - improved json verification
- all - better logging when requiredAuthHeader fails
- all - better role creation/usage validation
- all - don't allow circular role dependencies
- all - now need to be an userAdmin and *Admin to update *Admin change
settings for another user
- all - more auth debugging
- all - can now change the password of another *Admin user if you have
userAdmin and all the same *Admin
- all - hide webEnable, headerAuthEnable checkboxes for roles
- all - oidc now uses sameSite: Lax instead of sameSite: Strict for cookies
- capture - handle tcp port reuse better
- capture - fix kafka memory leak when produce fails
- cont3xt - New overview cards
- cont3xt - fix startup race condition with db init
- cont3xt - new search protocol to prepare for bulk
- parliament - fix parliament clean start not letting auth be set up
- viewer - gtp decoding
- viewer - demo mode improvements, arkimeAdmin can use normally
- viewer - fix unique endpoint not enforcing user time limit
4.3.2 2023/06/13
- release - cyberchef 10.4.0 libpcap 1.10.4
- all - config 'prefix' can be at most 50 characters
- all - new cookie generation code
- capture - handle packets better at epoch time
- cont3xt - add twilio country code tidbit
- cont3xt - add httpRealm to sample config
- cont3xt - help improvements
- cont3xt - minor UI improvements
- db.pl - set ISM deleteTime for sessions correctly
- esproxy - add tests
- parliament - fixed occasional missing token error
- viewer/wise - Field/Value actions now support all:true to show on every instance
- viewer - Fix Src/Dst mouse over for packets/bytes
- viewer - Field Actions didn't work in expanded meta
- viewer - Fix sending/receiving sessions not working
4.3.1 2023/05/08
- BREAKING - If running mixed versions of Arkime, broken cron queries error
might show on OLD version
- release - fix ubuntu22 kafka dep
- all - passwordSecret log message now has the right [section]
- capture - --tags option now works as well as --tag
- viewer - new auto cronQueries setting
- viewer - change where primary viewer info is stored to not cause constant
mapping change
- viewer - fixed ipv6 not working, now assumes zero filled with mask (if
not provided)
- viewer - code refactor into javascript classes
4.3.0 2023/04/27
- BREAKING - Only SuperAdmin can assign *Admin roles now
- release - fix kafka library linking
- release - al2023 support
- release - improve arkime_config_interfaces.sh
- release - Configure doesn't offer demo Elasticsearch on Arch
- release - reqBodyOnlyUtf8=true in sample config file
- all - support colon in OpenSearch/Elasticsearch password
- all - fix some prototype pollution
- all - improve roles enforcement
- all - New authTrustProxy setting
- capture - tcpClosingTimeout setting controls delay before saving tcp
sessions after close
- capture - default dbBulkSize to 1M, min 500K, max 15M and removed
from sample config file
- capture - s3 writer now writes multiple files based on packetThreads
- capture - s3 writer supports zstd, s3Compression setting
- capture - s3 writer compression level, s3CompressionBlockSize setting
- capture - s3 writer block size, s3CompressionBlockSize setting
- capture - s3 writer gap encoding, s3GapPacketPos setting
- capture - s3 writer when s3UseECSEnv is true use container env vars to find
the id/key/token for s3 auth
- capture - improve Gh0st parser (#2225)
- capture - new dnp3 & finger classifier
- capture - tcphealthcheck adding debugging
- capture/viewer - includes setting ignores missing files starting with -
- cont3xt - add malicious tidbit from urlscan results
- cont3xt - add malicious and brand columns to results table for urlscan
- cont3xt - link group UI improvements
- cont3xt - add createDate for whois data
- db.pl - new --ifneeded option to init/upgrade that will exit if not needed
- parliament - fix digest auth
- parliament - better auth support
- parliament - improve issue page and filters
- viewer - display errors when cronQueries isn't configured
- viewer - fix first sessions table row obscured sometimes
- viewer - disable more apis in demo mode
- viewer - allow roles forced expression without user forced expression (#2213)
- viewer - s3 now use each file's bucket to determine access style
- wise - only send csp headers in initial request for wise page
4.2.0 2023/03/01
- release - node 16.19.1, support node v18
- release - fix arch build issues
- release - EL9 build uses sha256 digest
- all - OpenSearch/Elasticsearch name cleanup
- all - cleanup nodejs dependencies
- all - refactor how authentication is done, everything now uses passportjs
- all - support oidc authentication method
- all - caTrustFile setting should work everywhere
- capture - support ERSPAN Type I and vlan for Type II
- capture - new kafka plugin for sessions
- capture - use malloc instead of GSlice
- capture - corrupt DNS alt name memory leak fixed
- capture - Added simpleFreeOutputBuffers setting
- cont3xt - raw create link groups
- cont3xt - two clicks to delete link groups or links
- cont3xt - classify domains with multiple dashes correctly
- cont3xt - added ability to copy links between link groups
- cont3xt - support intl phonenumbers
- db.pl - Initial OpenSearch ISM support
- db.pl - Better error text for cert verify failure
- esproxy - fix converting basic auth to base64
- viewer - fix field actions crash
- viewer - can now use expression http.request.FIELD or http.response.FIELD
with headers-http-request, headers-http-response defined fields
- viewer - support viewing ipv6 DLT_RAW (#1293)
- viewer - ESAdmin -> Unflood works on users cluster now also
- viewer - support running in s2s auth mode only
4.1.0 2023/01/10
- release - glib 2.72.4 cyberchef 9.55.0 flot 4.2.3 d3 7.7
- db.pl - backup/restore wasn't dealing with templates correctly
- db.pl - upgrade failed if there was no moloch_shared user
- db.pl - repair now fixes missing history/ecs templates
- db.pl - fix users-export/users-import
- cont3xt - support missing auth and userTmpl settings
- cont3xt - Hide link group when no links match filter
- cont3xt - Added landing page
- capture - allow wise field dst.ip:port
- capture - add VNI field
- capture - initial tzsp reader support
- capture - y2038 fixes
- capture - Integer ops in rules now support a leading min or max which only
sets the value if less than or greater than current value
- wise - added usersElasticsearchBasicAuth setting and lmdb cache support
- wise - add passivetotal value action if at least key is defined
- viewer - fix es node stats for different node.roles
- viewer/cont3xt - can now search roles
- viewer/cont3xt - don't show change password menu item if web auth is enabled for
user and disableUserPasswordUI is true
4.0.3 2022/11/28
- release - cyberchef 9.54.0
- release - copy systemd files instead of soft linking
- releaes - capture/viewer systemd files now After OpenSearch/Elasticsearch
- capture - on short runs, field definitions weren't getting updated
- capture - s3 writer sets s3Compress to false with s3WriteGzip true
- capture - JA3s value was sometimes incorrect
- cont3xt - fixed digest mode fetching settings from config file
- db.pl - fixed init not working with OpenSearch sometimes
- db.pl - will now count data or data_hot node roles
- viewer - fixed showing more than 10 roles
4.0.2 2022/11/01
- release - cyberchef 9.48.0
- all - better console output sanitization
- capture/viewer - Add TLS Certificate Organisational Unit field parsing (PR #2038)
- capture - use arkime_update_geo.sh in error msg
- capture - log error and exit if fields loading fails
- release - Stop Configure from destroying systemd files
4.0.1 2022/10/18
- addUser.js - remove WARNING adding first user
- addUser.js - --webauthonly now sets header auth flag
- all - better console output sanitization
- capture - offline pcap allows more outstanding packets based on maxPacketsInQueue
- db.pl - Fixed some OpenSearch compatibility
- db.pl - Fixed upgrading to 4.x with no _moloch_shared user
- viewer - Fix cert notbefore/notafter showing bad dates in sessions table
4.0.0 2022/10/11
- BREAKING - Must be 3.3.0+ to upgrade to 4.x
- BREAKING - systemd files auto installed, still need to enable
- BREAKING - Move to roles for some permission checking,
userAdmin role required to edit users
- BREAKING - the version file lives in common directory now
- BREAKING - new defaults maxFileSizeG=12, compressES=true
- BREAKING - pcap compression is turned on by default, disable with simpleCompression=none
- BREAKING - simpleGzipBlockSize renamed simpleCompressionBlockSize
- BREAKING - right-click changed to value-actions in config
- BREAKING - the userId search in history for admin nolonger adds the surrounding wildcards automatically
- BREAKING - views & notifiers are now their own indices
- release - cyberchef 9.46.5, node 16.16.0
- release - systemd files are delivered with /opt/arkime path instead of setting at install time
- release - CICD tests with OpenSearch
- all - Support ES 8 & OpenSearch
- all - check for missing users index or no users on startup
- all - update code/docs to mention OpenSearch
- addUser.js - new --roles option, --admin creates superAdmin user
- capture - New ecsEventDataset setting
- capture - save sessions not saving packets for across restarts
- capture - afpacket rewrite, improve performance & less out of order packets
- capture - fix quic crash
- capture - make creating fields from config/parsers/wise/tagger use ES bulk call
- capture/viewer - new outer fields replace gre fields (PR #1889)
- capture/viewer - initial SLL2 support (issue #2002)
- capture/viewer - zstd pcap compression
- chad - new plugin
- cont3xt - new Cont3xt application, see https://arkime.com/cont3xt
- cont3xt/viewer - share new user UI
- db.pl - fix sync-files/add-missing trying to add non pcap files
- db.pl - init/wipe clean up aliases that became indices
- db.pl - determine data node using roles array (issue #2006)
- db.pl - fix warning: Smartmatch is experimental
- db.pl - ilm didn't work if no sessions2 indices
- common - fix userAuthIps setting
- esproxy - check gzip traffic
- esproxy - improved bulk and url sanitization
- parliament - added --insecure option
- parliament/wise - can be configured to use shared user DB
- suricata - support char 127 in json better
- viewer - fixed auth fallback to digest from header mode
- viewer - field-actions to display configurable menu items on field labels
- viewer - share shortcuts with specific users or roles ("arkimeUser" role = old shortcut sharing)
- viewer - share views with specific users or roles ("arkimeUser" role = old shortcut sharing)
- viewer - share notifiers with specific users or roles (all previous notifiers will be shared with the "arkimeUser" role)
- viewer - share queries with specific users or roles
- viewer - share hunts with roles
- viewer - rework some settings UI, try and make UX similiar when adding things
- viewer - no more _moloch_shared user
- viewer - configure auto-hiding map/graph on large queries using turnOffGraphDays (default = 30 days)
- wise - fix some stats sorting
- wise - fix UI saving of INI formatted config
- wise - can configure field-actions
3.4.2 2022/03/31
- release - node 16.14.2
- viewer - Packets/s, Sessions/s, Dropped/s didn't have correct total/average
- viewer - host = $shortcut should work now
- capture - support longer node names (thanks mcgillowen)
- capture - host.smb.tokens wasn't defined correctly
- wise - alienvault no longer uses key
- tagger - support --insecure option
- tests - support --insecure with tests
3.4.1 2022/03/16
- release - node 16.14.1
- capture - new snmp parser of a few fields
- capture - rules can have numeric ranges
- db.pl - stop using history type name
- esproxy - added queries/_mapping to GET allow list
- viewer - Packets/s, Sessions/s, Dropped/s weren't accurate (thanks mcgillowen)
3.4.0 2022/03/09
- release - node 16.14.0, libpcap 1.10.1
- release - Configure script deals with / in password better
- BREAKING - in header auth mode userAuthIps allows only localhost by default
- wise - fix issues with redis source
- wise - threatstream in sqlite3 mode opens in readonly now
- wise - support -o section.var=value command line option
- wise - improve json parsing to handle non arrays when expecting an array
- wise - didn't always encoding number fields correctly
- db.pl - added a repair command that will fix some common issues
- viewer - reading packets from S3 failed
- viewer - increase speed when searching match fields
- viewer - fixed lastUsed when in digest auth
- viewer/wise - new userAuthIps setting that has which ips auth requests can
come from. header mode - default localhost, other - default all ips
- viewer - record which node is cron node and warn if not found
- viewer - allow floating point numbers for disk watermarks
- capture - switch from deflate to gzip posting to ES, lower min gzip size to 860
- capture - ietf quic improvements
- esproxy - can now create a [tee] section that will duplicate all ES calls,
but ignore results
- tests - Add --elasticsearch option which is actually used correctly
3.3.1 2022/01/26
- viewer - fix displaying large packets or xored packets not always working
- capture - refactor curl code based on recommendations
- capture - only allow 50 packets per ip4 frag
- capture - new modbus parser (thanks mcgillowen)
- tests - reduce race conditions
3.3.0 2022/01/19
- BREAKING - non standard pcap files now use the .arkime extension
- BREAKING - for wise multiES entries, prefix: now defaults to arkime_
- BREAKING - for wise threatstream source you must create md5 index manually
- release - node 14.18.3
- viewer - default to hunt reassembled packets
- viewer - add descriptions to hunts
- viewer - hide graph/map (speeds up large queries)
- viewer - history logs es query/indices
- viewer - open up to 50 sessions at a time button
- viewer - make sure hunt progress bar shows up
- viewer - handle corrupt pcap files better
- viewer - handle hunt errors better
- viewer - scrubbing won't crash on unsupported files
- capture - make sure file/seq es requests have higher priority
- capture - support pcap flies with 0 timestamp
- capture - use .arkime file extension for non standard pcap files
- capture - new _dropBySession rule op
- capture - fix infite recursion - thanks albntomat0_1
- capture - improve udp/tcp header length checking
- capture - improve error messages for field setting issues
- capture - cache when getting pcap data from S3 (thanks pjsg)
- capture - New ecsEventProvider setting
- wise - switch from node-sqlite3 to better-sqlite3 package
- all - support creating gzip files, set simpleGzipBlockSize
- all - support creating pcap files with short packet headers, set simpleShortHeader
3.2.1 2021/12/14
- esproxy - handle sessions2 without prefix
- capture - new parseHTTPHeaderValueMaxLen replaces hard coded 1024
- viewer - some hunt fixes
- viewer - switch from ES bool MUST to FILTER
- viewer - increase elasticsearchScrollTimeout default
- viewer - new AND arrays with ][ syntax vs OR arrays with []
- viewer - fix --insecure which broke in 3.2.0
- viewer - ES Nodes has new uptime stat
- viewer - fix 3.x sending to remote cluster
- viewer - disable periodic queries on multiviewer
- viewer - history can always toggle open and show api
- wise - fixed views that used require: not working
- db.pl - sync-files, add-missing, and other fixes since 3.x
3.2.0 2021/12/07
- release - node 14.18.2
- release - remove daily.sh, setup a cron directly now
- all - refactor some shared code into common directory
- capture - fix memory leak with ip4 frags and packet q overflowing
- capture - standardize on config error process exiting
- capture - ietf quic improvements
- tests - add some auth tests to test suite
- viewer - jquery upgrade
- viewer - help fields display improvements
- viewer - support https urls in wise plugin (issue #1777)
- viewer - fix history links with && not working
- viewer - userAuthCreateTmpl improvements
- viewer - fix cron and database bounding queries
- viewer - fix settings page not loading on pre 3.x config
- viewer - cyberchef didn't always load the packets
3.1.1 2021/10/13
- release - node 14.18.1
- addUser.js - fix not exiting on complete when certs defined
- all - deal with usersElasticsearch being an array better
- capture - increase max of pcapWriteSize, tpacketv3NumThreads
- capture - decrease max of maxESConns, maxESRequests
- viewer - fix vlan display (broke in 3.0.0)
- viewer - Issue Query on Page Load "No" option changed to issue query if there is a search expression
- viewer - fix position of value actions dropdown in spigraph table
- wise - fix error msg about redundant parameters
- wise - new mergeQuery setting for splunk
3.1.0 2021/10/04
- all - support float field type
- all - support Q-in-Q ether type
- all - --insecure has consistent messaging now
- all - Finally added elasticsearchBasicAuth/usersElasticsearchBasicAuth can be
user:pass or base64(user:pass)
- capture - s3 writer uses IMDSv2 (thanks fj604)
- capture - dscp src/dst (issue #1626)
- capture - refactor how udp tunnels are added, just normal parsers now
- capture - initial GENEVE, VXLAN-GPE support
- capture - initial IETF QUIC support
- capture - fix interfaceOps crash (issue #1763)
- release - much improved arkime_config_interfaces.sh (thanks arkaØm)
- release - node 14.18.0
- viewer - stop upload menu showing up when empty command
- viewer - improve first load time by spliting bundle and lazy load items
- viewer - combine multiple calls from UI into one call
- viewer - added pcap expire debugging
- viewer - uploadCommand can now use INSECURE-ORIGINALNAME to access uploaded filename
- viewer - shortcut display improvements
- viewer - shortcuts can be in arrays
- viewer - shortcut wildcard support (issue #1554)
- viewer - didn't decrypt pcap for large packets correctly (issue #1756)
- viewer - support wiseURL for wise.js viewer plugin (issue #1758)
- viewer - display "0" values
- viewer - Test alert includes who requested it
- viewer - fixed regex and floats not always working in array expressions
- viewer - fix always putting cursor at end of input when selecting typeahead result
- viewer - add typeahead results in search expression for values in a list
- multies - support elasticsearchApiKey
- multies - support scrolling and large queries/pagination
- wise - handle empty config file on startup
- wise - support ./ with value-actions
- wise - support usersElasticsearchAPIKey
- esproxy - elasticsearchAPIKey and elasticsearchBasicAuth support
3.0.0 2021/08/18
- BREAKING - Elasticsearch - ES 7.10.0 or later required
- BREAKING - if not using a ES prefix, the prefix arkime_ will now be used
- BREAKING - multies - multiESNodes requires a name: and prefix: attribute per entry
- BREAKING - wise - custom sources will need to be modified
- BREAKING - wise - redis urls have a new standard format
- BREAKING - wise - for json data keyColumn has been renamed keyPath
- BREAKING - wise - now lower case lotermfield and upper case uptermfield fields
- BREAKING - capture - override-ips will no longer have leading 0s for ASN
- release - curl 7.78.0, node 14.17.5, glib 2.68.3, yara 4.0.2, lua 5.3.6, maxmind 1.4.3, nghttp2 1.44.0
- capture - search for GeoIP files first in /var/lib/GeoIP
- capture - fixed possible ABR with time parsing
- capture - fixed memory leak with dns bad hostname parsing
- capture - new classifier for nfs and several rpc protocols
- capture - handle larger oracle connect msgs better
- capture - parse small http basic auth headers correctly
- capture - rule matches can now be logged
- capture - new localPcapIndex setting to enable pcap index on capture node instead of ES
- capture - write long open tcp sessions every tcpSaveTimeout even if no syn
- capture - fixed possible memory corruption with --flush option
- capture - check max packet length in more places
- capture - parse proxy-authorization header (PR #1651)
- db.pl - new urlinfile://filepath where elasticsearch url is the first line of filepath file
- db.pl - fix history mapping issue
- viewer - add POST version session query APIs to support long expressions
old GET versions still work
- viewer - reorganize and standardize APIs
- viewer - put npm scripts and common npm packages at top level
- viewer - allow viewing of large encrypted pcap files (issue #1555)
- viewer - can find nodes for pcap based on --host
- viewer - in multiviewer mode can now select which clusters to search (PR #1325)
- viewer - fix addTag/removeTag with multiviewer (PR #1556)
- viewer - can modify some sessions2 template from esadmin tab
- viewer - can modify entire shortcuts now
- viewer - spigraph visualization improvements
- viewer - Can set watermark settings again
- viewer - Start moloch -> arkime cookie changes
- viewer - dark theme improvements and new themes
- viewer - can now toggle on/off capture start times
- viewer - improve toolbar for packet display
- viewer - standardize on . ipv6 and : ipv4 port separator
- viewer - send shallower queries to ES when possible
- viewer - fix cron queries when using autoGenerateId
- viewer - improve session settings across sessions
- viewer - fix multiple requests when changing views and start/stop times
- viewer - fix setting user permissions not applying until page reload
- viewer - improve column resizing
- viewer - add button to open sessions cron query tagged
- viewer - rename cron queries to periodic queries, fix bugs, and add data (created time, creator userId, last run time, enabled/disabled time)
- viewer - add create periodic query to action menu dropdown
- viewer - notifier links to results
- viewer - notifier displays more data (creator userId, created time, last updated time)
- viewer - cancel hunts & remove hunt name and id from sessions
- viewer - shortcuts sync across all clusters if usersElasticsearch and cronQueries is set
- viewer - monitor cert and key files and reload them if they change
- viewer - display http request method in history page
- viewer - add bad status codes for failing to fetch pcap
- viewer - fix uncompress packets by requesting all packets
- wise - new config UI, enable with --webconfig
- wise - more moloch->arkime changes
- wise - for json data can now set arrayPath for start of where to parse
- wise - new nlasticsearchfile type
- wise - threatstream results now cached
- wise - support memcached for cache
- wise - new urlinfile://filepath where config is the first line of filepath file
- wise - help page
- wise - valueactions can be stored in flat file, redis or elasticsearch
- all - renamed rightclicks to valueactions
- all - many typos fixed
- all - support Elasticsearch API Keys (elasticsearchAPIKey setting)
- esproxy - first version, see https://arkime.com/esproxy
2.7.1 2020/12/01
- release - glib 2.66.2, curl 7.73.0, nghttp2 1.42.0
- wise - fix UI queries hanging
- viewer - fix anonymous user settings not saving
- viewer - fix lastUsed time not always saving to ES
- capture - new packet dedup feature https://arkime.com/settings#packet-deduplication-settings
- capture - close pfring on exit (issue #1538)
- capture - fix http2 parsing crash
- db - Moloch to Arkime text fixes
2.7.0 2020/11/18
- NOTICE - Requires ES 7.4 or newer
- NOTICE - Moloch to Arkime rebranding in UI, everything else still Moloch
- all - ES 7 updates, fix most depreciated warnings (mappings/templates still remain)
- viewer - fix mpls decoding
- viewer - new themes and logo selection
- capture - fix http CONNECT response parsing
- capture - New pcap-over-ip reader support
- db - can import gz files directly now
- db - fix issues with version importing
2.4.2 2020/11/10
- NOTICE - db.pl upgrade is required
- NOTICE - this is the last version to support ES 6
- release - node 12.19.0
- viewer - support utf8 chars in content-disposition
- viewer - add capture process restart to timeline graphs
- viewer - add "bookmarks"
apply a view's expression to the search input without issuing a query
- viewer - fix anonymous users settings not being saved
- viewer - share hunts between users
- viewer - move all common client bundling, scripts, and npm modules to top level
- viewer - display business hours on sessions timeline graph
- viewer - fix multi mpls header decoding
- viewer - fix viewer crashing when pcap file not available
- viewer - new getSessionBySearch setting
- viewer - decode vxlan packets better
- viewer - add help icon
- viewer - added startTime and runningTime capture stats
- capture - QUIC version 5x detection
- capture - smtp decoding handles clients that break utf8 section incorrectly
- capture - fix a json parsing fail would cause next json parse to fail even if good
- capture - support 0x6558 Ether Bridging
- wise - threatstream improvements when using the sqlite db
- db - fix rm-node to delete over 10k items, and bad count display
- tests - use our oui/rir files
2.4.1 2020/09/28
- NOTICE - db.pl upgrade is required
- NOTICE - the elasticsearch and usersElasticsearch variables must start with http:// or https://
- release - node 12.18.4
- viewer - fixed export pcap from actions menu not working
- viewer - capture stats/graph now uses regex instead of wildcard
- viewer - support -reindex indices
- viewer - log more info when can't open a file
- viewer - lastpass boxes removed
- viewer - can now edit ILM values from ES Admin tab if ./db.pl ilm has been used previously
- viewer - handle hunts with bad regex better
- viewer - change capture stats default length to 200
- viewer - fix password change with aes256Encryption turned on
- viewer - handle hunts when nodes are down better
- wise - UI improvements
- wise - theatstream mode sqlite3 no longer copies the db, use sqlite3-copy for old behaviour
- parliament - show bits instead of bytes
- db - new reindex command
- capture - http2 header fields were not always indexed correctly
- capture - fix g_hash_table_contains warning
- capture - rules can use special ip values ipv4 and ipv6 now
- moloch_update_geo.sh - fix possible security issue
2.4.0 2020/08/25
- NOTE - RHEL/Centos 6 is no longer supported, Node 12 required
- NOTE - New encoding of packetPos, set gapPacketPos=false for old encoding
- NOTE - 2.4.x will be the last versions to support ES 6
- release - node 12.18.2, glib 2.64.5, curl 7.72.0
- release - Ubuntu 20 support
- viewer - aes256Encryption now defaults to true
- viewer - added a clear cache button to ES Admin tab
- viewer - quote expressions with [ or ] in them
- viewer - add button to only show data nodes on ES Nodes tab
- viewer - files tab can now show the packet pos encoding
- viewer - ES Indices tab can now show the avg doc size per index
- viewer - ES Nodes tab can now show shards and segments per node
- capture - http2 decoding for PRI * h2 sessions
- capture - set http2 protocol when alpn is h2
- capture - upgrade h2c http2 decoding
- capture - no longer use internal libpcap function
- capture - simple writer supports maxFileTimeM (PR #1506)
- capture - new packetPos encoding saves 10%-20% overall ES space
- capture - remove old disk writer methods, use simple or simple-nodirect now
- wise - simple UI
- wise - support json file format config files
2.3.2 2020/06/29
- NOTE - 2.3.x will be the last version to support RHEL/Centos 6
- release - node 10.21.0
- capture - minor tcp dns parsing performance improvement
- capture - refactor some code to be more type safe
- capture - deal with bad utf8/puny in dns and altnames
- viewer - warn at starting about missing ./vueapp/dist/index.html
- viewer - can now use db:<dbFieldName> in expressions (PR #1463)
- viewer - if esAdminUsers isn't set, ES Admin tab now shows up for admins
- viewer - ES Nodes can display molochzone attribute now
- viewer - fixed some Users tab issues
- viewer - fix percentage sorting on ES Recovery tab
- viewer - "right click" actions can how show text in menu with fetch actionType
- viewer - "Reverse DNS" menu option on ips
2.3.1 2020/05/27
- all - Lots of changes to support node 12 in the future (thanks rnbwdsh)
- viewer - fix bug where the next query after an empty query might hang the UI
- viewer - use the same eslint as the UI & parliament, lots of lines changed
- viewer - can now modify or delete a view from the popup
- viewer - fixed so non admins can cancel their searches again
- viewer - fixed columns not always loading with views
- viewer - when user creates a view it will auto switch
- viewer - does basic ip validation in queries
- viewer - fixed users tab header being hidden
- capture - fixed out of bounds read in smtp parsing
- capture - Lowered the default number of ES retries to 2, added new
esMaxRetries setting
- wise - upgraded sqlite version and changed from hashtable to Map (thanks rnbwdsh)
- db.pl - The info command will now display estimate for how many days can be stored
2.3.0 2020/05/06
- release - CyberChef 9.16.2, node 10.20.1, daq 2.0.7
- viewer - set content-type for cyberchef files
- viewer - add support for caTrustFile to addUser and multies
- viewer - can now select to show any integer field in graphs, set on the settings page
- viewer - graph/header can now be pinned to not scroll off page
- viewer - most navbars can be collapsed and hidden
- viewer - mouse over in graphs now show total values too
- viewer - fixed left/right keys not working in search bar after visiting stats page
- viewer - support cancel for multies
- viewer - cleaned up some of the Help docs
- capture - new parsers arp, bgp, igmp, isis, lldp, ospf, pim,
- capture - protocol parsing code has been refactored, can now write parsers
of ethernet and other ip protocols
- capture - new disableParsers, default of arp.so
- capture - new unkEthernet, unkIpProtocol protocols
- capture - support QUIC version 46
- capture - new esBulkQuery setting to override the /bulk call
- capture - added some more lua examples (thanks Antipokemon)
- wise - threatstream fixes to be nicer to the sql database
- all - switch most ES apis to typeless format
2.2.3 2020/03/09
- viewer - Experimental treemap view in spigraph
- viewer - Hunts now retry talking to failed remote nodes
- viewer - Completed Hunts have a repeat button
- viewer - Fix some Hunt stat and display issues
- viewer - Fixed Hunts/Tags working with ILM
- viewer - Fixed notifier issues and issue #1365
- viewer - Increase navbar contrast
- viewer - Spiview should be faster loading data
- viewer - Debug now prints out config vars like capture
- release - Fix lua.so not being included with builds
- capture - Fix "-r -" not working
- parliament - Ignored issues should remain unless deleted
- db - Can set sessions refresh interval
2.2.2 2020/02/18
- release - node 10.19.0