This SecNova AI-SIEM release expands AI-assisted security operations across the product and improves workflow automation, reporting, governance, reliability, and usability.
Key Feature Updates
Introducing SecNova AI Across SecNova AI-SIEM
SecNova AI is now available across key SecNova AI-SIEM product pages. Users can open the assistant at any time to learn about page capabilities, receive contextual guidance, and complete tasks such as log queries, data analysis, rule configuration, and automated response through natural-language conversations.
By understanding the current page and operational context, SecNova AI delivers more relevant assistance and reduces the need to switch between pages, tools, and documentation, creating a more streamlined security operations experience.
Major Upgrade to AI-Powered NovaQL Queries
Users can describe what they want to investigate in natural language, and AI automatically generates the corresponding NovaQL query. Queries can be refined through multi-turn conversations by adding conditions, changing the scope, or optimizing the query structure.
The upgraded capability supports join, union, Dataset, View, and Reference Table queries, enabling more advanced data-correlation scenarios. The chart editor also includes the AI NovaQL assistant, making it faster to build queries and visualizations while reducing the NovaQL learning curve.
Enhanced AI-Assisted Parsing and Detection Rules
AI-assisted parsing now supports two core workflows: creating new rules and improving existing ones. Users can load an existing rule and ask AI to explain, assess, and refine it. New rule generation covers sample analysis, Class planning, field mapping, and full-sample validation.
This workflow reduces the manual effort required to understand log structures and repeatedly troubleshoot parsing logic, while improving field-mapping consistency and rule-generation reliability.
Upgraded AI Workflows and Tool Center
Users can create, modify, and manage automated workflows with AI while viewing the status and result of each execution step. More comprehensive configuration checks are performed before execution, reducing failures caused by missing parameters or incomplete settings.
The Tool Center now supports category browsing, filtering, search, and direct execution. Tools in workflows and agents are also grouped by their business source, making it easier to find the right capability and build automation faster.
Multi-Channel Approval
High-risk tool operations can now be approved through email, Slack, Lark, or DingTalk. AI automatically generates a concise explanation of the intended operation and clearly presents its details, potential impact, and validity period, helping approvers make faster and better-informed decisions.
Approvers can provide a reason when rejecting a request, and the result is synchronized back to the original AI conversation. Once approved, the previously paused task can continue, preserving human oversight and auditability without interrupting the automation workflow.
Built-In Security Operations Reports
The platform now includes six predefined report templates covering daily security operations, weekly security posture reviews, monthly management risk reporting, PCI DSS evidence collection, and SOC overviews.
Each report includes built-in NovaQL charts and evidence details for high-risk events. Teams can quickly prepare operational handovers, security reviews, executive reports, and compliance evidence without building reports from scratch.
Enhanced Enterprise Integration and Access Governance
Enterprise communication integrations can now be configured and shared at the organization level, reducing repetitive setup and maintenance for individual users. Support for internal networks, self-signed certificates, and edge network environments has also been improved. When a related node is disabled or removed, its access permissions are automatically cleaned up to reduce residual access risks.
RBAC now supports page-level server-side authorization and permission-based control of UI actions. Administrators can also assign SIEM access roles when inviting users through the Console, helping keep page access, available actions, and backend permissions aligned.
Experience and Reliability Improvements
More Transparent and Reliable AI Execution
Users can view AI task steps, tool calls, execution status, and elapsed time in real time. Consecutive operations are automatically summarized, and clearer explanations are provided when a task fails.
AI conversations can automatically recover from temporary network interruptions. If a user stops a task, the content already generated is retained, and the conversation can continue normally.
Improved Log and Data Presentation
Log details now support expanded nested fields and configurable display of metadata and empty objects. Field layouts, interactions, and accessibility have also been improved to make complex logs easier to inspect.
Overview Dashboard handling has been improved for metric precision, empty values, and abnormal data, delivering more accurate and reliable visualizations.
Consistent Pages and Notifications
AI theme colors, gradients, and selected states have been standardized, while the NovaQL editor now provides clearer structured visual cues. Layout and scrolling behavior across tables, tabs, standard pages, and immersive pages have also been unified.
Severity levels, handling status, and investigation conclusions are presented more consistently across alert and incident notifications. The Task Center has also been moved to the main navigation for easier access.
Bug Fixes
- Fixed formatting issues affecting complex nested NovaQL queries.
- Fixed Overview Dashboard rendering failures caused by abnormal data.
- Fixed height calculation, blank area, and double-scrolling issues across tables and tab-based pages.
- Fixed certain AI query failures caused by inconsistent organization or user context.
- Improved the display of long text, code, status information, and tool descriptions to reduce clipping, misalignment, and horizontal overflow.