13-Aug-2019Versions: Hub 6.5.2847, Probe 6.5.2960, Web 6.5.2179

Release Highlights

Trisul Probe

Key featureset to support BGP for ISP application

  • FEATURE: High performance BGP Route Receiver and integration built in
  • FEATURE: New Netflow metrics for BGP NextHop, IP Hext Hop, Prefixes, AS and others
  • FEATURE: Flow taggers can now specify a Tag Group to distinguish tags from multiple sources
  • FEATURE: AggregateFlows is now faster and can handle flow tags and tag groups
Trisul Hub
  • FEATURE: Much improved AGGREGATE FLOWS query
  • FEATURE: Ability to add more than 1 HUB node using the CLI tool trisulctl_hub
Web Interface
  • FEATURE: Much improved plugin API , your tool can attach to a context menu
  • FEATURE: APP framework, you can use HAML for the skeleton and a separate CSS
  • FEATURE: EDGE analytics added to Retro Tools
  • Several other fixes , new Ruby/Rails backend
Trisul Apps

Trisul APPS are free extensions for real time analytics and visualization

For full release notes see Trisul Release Announcement

Get on to the Trisul Network Monitoring platform

Crosskeys

Discover traffic flows

Unique insights into how traffic patterns flows from X to Y to Z. Example detecting internal assets talking to which apps to which countries.

Read more

Graph Analytics

Discover hidden networks

Save hours trying to hunt down X:Y relationships using older hunting techniques

Comprehensive new LUA API

Fully scriptable platform

Use plain Lua language File extraction, TCP reassembly, and a dozen other hooks

Read more

Distributed Probes/Hub

Deploy multiple Trisul-Probes

Management CLI tools included

Older releases

26-Feb-2019Versions: Hub 6.5.2834, Probe 6.5.2939, Web 6.5.2165

Release Highlights

A partial list of the most important features.

See Blog posts on the two biggest highlights

Trisul Probe
  • FEATURE : New Cross Keys counter group allows you to meter upto 3 counter groups.
  • FEATURE : Bug fix with some Netflow v9 equipment vendors when router timestamps are zero
  • FEATURE : Bug fix with Flow Taggers in some rare cases when tags are very long
  • FEATURE : LUA API : new flowkey() method added to object Layer
  • SCRIPTING: Released the BITMAUL protocol dissector library
Trisul Hub
  • FEATURE: Resources now partitioned by time to improve performance even further
  • FEATURE: Max number of probes per Hub increased to 16 in non-Enterprise
Web Interface
  • FEATURE: Explore Flows report now has an Export to XLSX option
  • FEATURE: Cross Key counter group UI
  • Netflow: Router interface drilldown report to PDF
  • Schedule report for Netflow router interface drilldown
  • Export to XLSX from Netflow reports
Trisul Apps

Trisul APPS are free extensions for real time analytics and visualization

For full release notes see Trisul Release Announcement

Get on to the Trisul Network Monitoring platform

21-Aug-2018Versions: Hub 6.5.2815, Probe 6.5.2922, Web 6.5.2144

03-Dec-2018 : New minor Release Trisul 6.5

This release introduces new features to help with Flow Analytics.
Read the Blog Post : Aggregate flows and Export to Excel features

Release Highlights

A partial list of the most important features.

Trisul Probe
  • FEATURE: Now supports multiple unix domain sockets to ingest from IDS
  • FEATURE: NXDOMAIN and other DNS failures triggers a minor alert
  • SCRIPTING: Released the BITMAUL protocol dissector library
  • CLI: Added help commands to all CLI trisulctl_probe commands
  • NETFLOW: Added option IgnoreEgress option to skip redundantly configured Egress NF9/IPFIX
  • and others
Trisul Hub
  • FEATURE: Resources now partitioned by time to improve performance even further
  • FEATURE: Max number of probes per Hub increased to 16 in non-Enterprise
Web Interface
  • FEATURE: Brand new Time Selector
  • FEATURE: Email log shows sent emails
  • FEATURE: Dashboard creation made easier with boxes for every position
  • FEATURE: Cardinality counters proper description is now showin Retro Counters
  • Plus dozens of other smaller fixes
Trisul Apps

Trisul APPS are free extensions for real time analytics and visualization

  • NEW APP: IOC-Harvestor pulls out network artifacts from multiple streams
  • NEW APP: IP2LOCATION based Geo Metering. Adds ASN, COUNTRY, CITY, PROXY info
  • NEW APP: AlienVault OTX integration to check your traffic against threat indicators
  • NEW APP: HTTP-Proxy app when deployed in a proxy environment
  • NEW APP: Edge Vertex monitor shows volumes for each vertex
  • UPDATED: JA3 Server signature added to TLS Fingerprint
  • UPDATED: PCAP Totals dashboard shows all metrics in one place

For a more complete list see Trisul Release Announcement

25-Apr-2018 Versions: Hub 6.5.2803, Probe 6.5.2883, Web 6.5.2127

New Major Release Trisul 6.5
Trisul 6.5 gets even better with our latest update. Monitor very high traffic loads with more stability and faster queries.

Release details

Trisul-Probe
  • NEW: Bottom-K added to all counters. Added to Retro Counters screen as well
  • NEW: Flows now have microsecond timestamps, can be optionally turned off to save storage
  • NEW: IPv6, MDNS, PTR record resources
  • NEW: ERSPAN support to enable remove packet capture mode for Trisul
  • API: LUA setFlowAttribute added to API
  • API: LUA RE2 regex methods and options added
  • STABILITY: Fixed an issue with message monitor stream, which can cause deadlock in high load
  • STABILITY: Fixed a potential crash, prevent Flow stream events outside of flow context, by resetting the flow object to nullptr
  • STABILITY: Filters prevented from doing flow stream metrics like addflowcoutner outside of flow context.
  • FEAT: Bulkping : New tool to monitoring thousands of endpoints for reachability
  • PERF: Major perf update, stream message sponge algorithm change, advanced only by 1sec to prevent deadlock.
  • PERF: Previous sponge logic can cause deadlock at very high loads. Now solved.
  • FEAT: SFLOW use sampledPacketSize directly
  • FEAT: SFLOW VLAN Stats
  • FEAT: Streaming analytics RAT monitor, now we have per-queue drop stats
  • FEAT: URL Category now also uses SNI to classifiy sites
Trisul-Hub
  • FEAT: NetBIOS IP Resolver allow hyphens in names
  • FEAT: Flow Database version update to allow microseconds in flow timestamps (start and end), optional to turn off to save space
  • BUGFIX: Flow tracker was not correctly resolving netflow interface names , guid had a lower case char
  • BUGFIX: Memory leak fixed in CounterItemRequest (with dbz/trfz yield)
  • BUGFIX: Due to lack of checking for interval_id , Cattrf infinite loop bug. fixed now.
  • FEAT: QuerySessions Parallel query support added (MRMT)
  • FEAT: TRPD Parallel Query for All : New option in trisulHubConfig.xml “Server>ParallelQueries”
  • BUGFIX: CacheBuild caused ONE datapoint loss per day at midnight, off by one in loop. Fixed.
  • BUGFIX: Migration ConfigDB BottomNCount error due to “no data to read” error
WEBTRISUL
  • NEW: Brand new Time Range selector added to add screens
  • NEW: Progress bar added to all dashboards and long running query forms
  • NEW: Netflow Router Interface resolver screen redesigned,
  • NEW: Netflow interface drilldown Real time transmit and receive
  • NEW: RealTime interface utilization with all in one view(traffic,host,app,flows)
  • FEAT: Key space explorer , you can now enter in CIDR format. Eg 192.168.0.0/16 instead of 192.168.0.0~192.168.255.255
  • NEW: If SNMP available, Live chart added to Netflow Interfaces due to cust demand/usage
  • FEAT: All Flow screens updated to show Microseconds for flow duration
  • FEAT: InitDB done on 1st raw install by webtrisul.
  • FEAT: HTTPS fixes, previously webtrisulssld was not working with the Real Time Websockets features
    + 100s of other small UI tweaks and fixes.