What's new in Log360

Learn about the new product innovations we deliver every quarter. Read the release notes,
download helpful resources, and register for our release webinars!

  • Newest capabilities
  • Join the Webinars
  • Related Resources

Q2 updates

Native SOAR in ManageEngine Log360

This quarter, Log360 Cloud expands its detection, investigation, and response capabilities with native SOAR orchestration and improved automation visibility. Here’s what’s new:

Native SOAR orchestration

SOAR is now built directly into Log360 Cloud, enabling analysts to automate investigation and response workflows from a unified platform. Use the visual playbook builder to create low-code workflows with branching, parallel execution, custom functions, and coordinated remediation actions across security tools.

Smarter playbook execution

Run multiple playbooks in parallel from a single alert and reuse common workflows through nested playbooks. Retry and fallback mechanisms help maintain execution continuity, while manual retries resume from the exact point of failure instead of restarting the workflow.

Custom functions for tailored automation

Extend playbooks with custom logic using Python or Deluge functions. Build reusable workflows for threat enrichment, data parsing, ticket creation, endpoint actions, and organization-specific response logic.

Marketplace extensions

Expanded Log360 Cloud’s integration ecosystem with 7 new marketplace extensions including CrowdStrike GravityZone, Bitdefender EDR, Okta, and more.

Centralized connection management

Securely manage integrations and authentication from a centralized connections framework. Configure reusable connection profiles for endpoint platforms, identity providers, cloud services, and threat intelligence tools to simplify orchestration across your security stack.

Re-engineered detection  

Detection just got smarter, sharper, and more scalable

This quarter, Log360 introduces major upgrades to its detection capabilities. From engineering-level precision to large-scale performance. Here's what's new:

Detection engineering

We've redesigned how Log360 detects threats. A new centralized detection console now brings together correlation logic, threat intelligence, MITRE ATT&CK mapping, UEBA insights, and a rule builder that supports standard, anomaly-based, and advanced detection logic. Detection insights helps optimize rules with real-world noise levels and usage metrics—enabling focused, high-fidelity alerts.

Object-level filtering for Active Directory and Microsoft 365

Fine-tune alert scope using filters based on users, groups, and OUs. These filters apply across predefined rules for use cases like privilege escalations, suspicious password resets, and admin group changes—helping reduce noise from irrelevant accounts like test users or developer machines. It's precise detection, not suppression.

Scalable log ingestion

Log360 now supports horizontal scalability with clustered log processors and role-based specialization for alerting, correlation, and search. You can also collect logs from distributed sites and process them centrally — ensuring high performance even in large, hybrid environments.

Cloud-delivered detection content

Get continuously updated detection content mapped to MITRE ATT&CK, without manual imports. Delivered securely from the cloud, this content is curated for emerging threats and multivector attacks, ensuring your detection logic stays current.

Re-engineered detection  

Zia Insights: AI-Driven investigation analytics

Log360 Cloud now features Zia Insights, a contextual AI engine powered by Azure OpenAI (BYOK). Analysts can now:

  • Generate human-readable summaries from alerts, incidents, and logs with a click
  • Map activities to MITRE ATT&CK® techniques for deeper threat context
  • View attack timelines that reconstruct event sequences visually
  • Receive remediation tips, tailored based on log type and context

This release transforms threat investigation workflows— delivering clarity, acceleration, and actionable insights within your SIEM interface.

Zia Insights: AI-Driven investigation analytics  

Register for the launch webinar

LIVE WEBINAR

Native SOAR in ManageEngine Log360

Related resources

Security Orchestration, Automation, and Response (SOAR)
DATASHEET

Security Orchestration, Automation, and Response (SOAR)

Read now
AI-powered Zia Insights
DATASHEET

AI-powered Zia Insights

Read now

Want to see Log360's latest capabilities in action?

  • Centralized Log Management & Compliance
  • Automated Threat Detection & Response (TDIR)
  • User & Entity Behavior Analytics (UEBA)
  • GenAI-Powered Investigations (Zia Insights)
  • Proactive Dark Web Monitoring
  • Security & Risk Posture Management