LATEST RELEASE

v1.119

Feb 27, 2026

Panther AI can now access web pages for richer alert analysis, and the Panther console supports light mode.

New and Noteworthy
  • Panther AI can access web pages for additional context during analysis. Configure approved and forbidden domain lists and optionally require user approval before the AI accesses domains outside the approved list.

  • Set a delay tag to postpone AI alert auto-run triage, giving additional alert context time to accumulate before analysis begins.

  • Ingest Iru (formerly Kandji) audit logs with Panther's new log source integration.

  • Ingest Upwind logs with Panther's new log source integration.

  • The Panther console supports light mode. Switch between light and dark mode in Profile Settings.

  • Set a unique value threshold for detections to control alert generation based on distinct field values observed over a time window.

Now Generally Available
Enhancements
Schema Changes
Bug Fixes
  • Fixed Google Workspace application list display to reflect all supported apps across the log source list, Overview tab, Configuration tab, and setup.

  • Fixed a bug where a source's "last event received" timestamp was incorrectly updated when only internal audit events (not actual log data) were processed.

  • Updated AWS.ALB schema to support IPv6 client IP addresses.

  • Fixed IP indicator extraction for the ClientIPAddress and ClientIP fields of the Microsoft365.Audit.Exchange log type.

  • Fixed a bug where large GCS Enrichments (several GBs) were failing to be processed.

  • Bulk detections download now support ZIP files larger than 6 MB.

Deprecations

LATEST RELEASE

v1.119

Feb 20, 2026

Feb 27, 2026

Panther AI can now access web pages for richer alert analysis, and the Panther console supports light mode.

New and Noteworthy
  • Panther AI can access web pages for additional context during analysis. Configure approved and forbidden domain lists and optionally require user approval before the AI accesses domains outside the approved list.

  • Set a delay tag to postpone AI alert auto-run triage, giving additional alert context time to accumulate before analysis begins.

  • Ingest Iru (formerly Kandji) audit logs with Panther's new log source integration.

  • Ingest Upwind logs with Panther's new log source integration.

  • The Panther console supports light mode. Switch between light and dark mode in Profile Settings.

  • Set a unique value threshold for detections to control alert generation based on distinct field values observed over a time window.

Now Generally Available
Enhancements
Schema Changes
Bug Fixes
  • Fixed Google Workspace application list display to reflect all supported apps across the log source list, Overview tab, Configuration tab, and setup.

  • Fixed a bug where a source's "last event received" timestamp was incorrectly updated when only internal audit events (not actual log data) were processed.

  • Updated AWS.ALB schema to support IPv6 client IP addresses.

  • Fixed IP indicator extraction for the ClientIPAddress and ClientIP fields of the Microsoft365.Audit.Exchange log type.

  • Fixed a bug where large GCS Enrichments (several GBs) were failing to be processed.

  • Bulk detections download now support ZIP files larger than 6 MB.

Deprecations

Ready for less noise
and more control?

See Panther in action. Book a demo today.

Get product updates, webinars, and news

By submitting this form, you acknowledge and agree that Panther will process your personal information in accordance with the Privacy Policy.

Get product updates, webinars, and news

By submitting this form, you acknowledge and agree that Panther will process your personal information in accordance with the Privacy Policy.

Product
Resources
Support
Company

Get product updates, webinars, and news

By submitting this form, you acknowledge and agree that Panther will process your personal information in accordance with the Privacy Policy.