What’s new in TeskaLabs LogMan.io v26.12¶
Release date: 22.06.2026
LogMan.io v26.12 brings major enhancements to Alert Management, including ticket compression, unified severity levels, SLA monitoring, and push notifications. Discover defaults to the last 4 hours, supports up to 1,000 rows with infinite scroll, and lets you filter by alert ticket and navigate back. Parsec adds processors for VMware Aria Operations for Logs and SAP SAL logs and automatic parsing of Windows Event Access fields.
You can find the full changelog on TeskaLabs GitHub.
Ticket compression¶
Older tickets are regularly cleaned up through compression, keeping investigations manageable and Alert Management faster. Compression checks run every 12 hours.
Severity and SLA monitoring¶
Each ticket uses a unified severity scale based on standard SIGMA notation, with medium as the default. SLA checks monitor response times; on violation, a notification is sent and a record is added to the ticket timeline. Custom workflow states are supported, and tickets are sorted by last activity by default.
Push notifications¶
Push notifications can be configured per tenant for alert events. ASAB Iris adds delegated Email MS365 support. Default templates for SLA violation and push notifications on ticket created or updated are included in the Common Library.
Discover improvements¶
Discover defaults to a time range of the last 4 hours and supports up to 1,000 rows with infinite scroll. You can filter events by alert ticket, store personal filters, and navigate back to a ticket from Discover. Filters stored in the Library in the legacy format are automatically translated to the new structure. Dashboards and Reports received fixes for datetime range handling and widget editing.
New parsing rules¶
Parsec adds processors for VMware Aria Operations for Logs and SAP SAL logs. The Windows Events processor automatically parses Access fields. Syntax highlighting now works correctly even when mapping is not loaded.
The Common Library adds parsing rules for Juniper Networks Firewall and Switch, Microsoft SQL Server (via SmartFile and Filebeat), and Fidelis Network. Windows Event Log parsing is extended for FileShare access events. Microsoft 365 Message Trace parsing is updated for the new log format. New reports include EPS Overview and Others Event Overview under Log Source Monitoring.
Library improvements¶
The Library WebUI supports uploading content from a file when creating items. The Monaco editor restores cursor position, scroll state, and selections when saving or switching tabs. Advanced search in the tree menu displays the full folder structure. Disabled items can be renamed, copied, removed, or deleted.
ECS and CEF schema files must be stored on the global layer, not on the tenant layer.
Improved Replay¶
Archive and Replay received significant performance and readability improvements. The Collectors table renders faster, Replay shows log counts and cleans up old replays automatically, and streams are scoped to the selected tenant.
Authentication administration¶
SeaCat Auth adds a common admin API for authentication methods, global role management resources, and MFA reset on password reset.