This SecNova AI-SIEM release improves page-aware AI assistance, reasoning controls, multimodal analysis, report editing, workflow automation, and multi-turn incident response.
Key Feature Updates
Enhanced AI Page Reading and Understanding
SecNova AI can now better read and understand the current SecNova AI-SIEM page. The assistant uses the business object being viewed, page information, and entered content to provide more relevant queries, analysis, and recommended actions.
Users can invoke AI directly in editors such as NovaQL and continue working with the current content, reducing page switching and the need to restate context.
Selectable AI Reasoning Complexity
Users can choose from four reasoning modes—Fast, Standard, High, and Max—based on task complexity. This allows users to select an appropriate depth of analysis for routine questions, data analysis, and complex investigations.
AI Multimodal Support and File Processing
AI supports multimodal requests containing images. The system automatically selects a multimodal-capable model to process these requests.
Users can upload a single file, multiple files, or a complete folder in AI Chat for cross-file reading, search, and analysis. Conversation files support preview, download, deletion, version comparison, and history restoration, helping users manage source materials and processing results in one place.
Enhanced AI Report Editing
Existing reports can now be edited in SIEM Chat. Users can build on existing content to add analysis, refine the structure, and improve wording without generating a new report from scratch.
AI-generated reports also remain available as conversation files for continued viewing and editing, turning one-time outputs into work products that can be refined over time.
Enhanced AI Workflow Orchestration, Scheduling, and Approvals
Users can create, modify, publish, and run automated workflows through natural language. Before saving, the system validates nodes, parameters, and connections and identifies the locations that require changes, reducing execution issues caused by incomplete configuration.
AI supports the creation and management of Cron and fixed-interval schedules. Users can also trigger tasks manually and review run history.
When a workflow requires additional information or approval for a high-risk action, the task waits for user input. Users can respond through the product interface or a connected instant-messaging approval channel, then resume the task. Task Center displays waiting-for-input, running, canceled, and retry states, with a complete execution record for tracing results.
Enhanced Multi-Turn Incident AI Investigation and SIEM Response
Incident AI analysis now uses the standard SIEM Chat conversation flow, enabling multi-turn investigation of the same incident. Users can ask follow-up questions, provide additional investigation information, adopt AI findings to update incident data, and generate or download analysis reports.
SecNova AI also supports queries across alerts, security incidents, threat intelligence, agents, data sources, pipelines, and ingestion status. Users can take authorized alert and incident actions within the same conversation, connecting evidence queries, assessment, and response.
Experience and Reliability Improvements
Clearer Task Clarification and Independent Conversations
When essential information is missing, AI asks single-choice, multiple-choice, or free-text questions to clarify requirements and collect the information needed to proceed.
Multiple conversations can run independently at the same time, allowing users to work on different analysis and investigation tasks in parallel.
Improved Model Onboarding and Credential Management
The system validates LLM keys when they are saved and provides specific failure reasons. New tenants can immediately use the system-provided default model service, reducing initial setup work.
Unchanged keys do not need to be re-entered when updating model configuration. Virtual keys are displayed only when created or rotated, balancing configuration convenience with credential protection.
Resolved Issues
- SIEM Queries, Jobs, and Data Operations: Fixed Context Job creation failures, LogSearch query suggestion issues, Reference Table CSV export failures, and known SIEM project issues.
- IM Integration and Conversation Reliability: Fixed bot mention failures in Lark group chats, recovery failures for existing conversations, bots remaining connected after integration deletion, and SIEM links in IM messages that could navigate to the wrong tenant.
- AI and Content Center Interfaces: Fixed Content Center package logo caching across routes, AI rule-analysis action-menu positioning, and display issues affecting long conversation titles, knowledge-base cards, and selected Tool Center pages.
- Workflow and Task Center Interactions: Fixed focus loss during workflow tool input, poor export-menu visibility, and the inability to horizontally view complete wide-table content in Task Center.