Release Notes for Data Security for Dell
This page lists the changes, fixes, and known issues for Data Security for Dell version 2.15.0.
What's Fixed in Version 2.15.0
-
Snapshot History Now Correctly Reflects Reused Snapshots for Events Raised While Pending: A Ransomware Defender event that had a snapshot job run while still in Pending Events, and was later promoted to Active Events, now correctly shows the reused snapshot against the event, and the event's history correctly records the snapshot activity. Previously, the event's snapshot list and history showed no record of the snapshot at all, even though the correct snapshot had been reused rather than duplicated.
-
Reused Snapshots Are Now Verified Before Reuse: Eyeglass could previously still treat a snapshot as reusable after it had been deleted directly on OneFS or through the event history's delete-snapshot action, as long as it was still within the reuse window — so a new event wouldn't get a real snapshot, and attempts to extend the (deleted) snapshot's expiry would fail with an error. Eyeglass now verifies a candidate snapshot still exists on the cluster before reusing it, discarding the stale record and creating a new snapshot if it was deleted outside of Eyeglass.
Known Issues
The following known issues have been identified in version 2.15.0.
General
-
ECS Is Not Supported in the New GUI: ECS-managed environments are not yet supported in the New GUI for version 2.15.0. Continue to manage ECS clusters from the Old (legacy) GUI in this release — New GUI support for ECS is planned for a future release.
-
Only the Administrator Role Has Access to the New GUI: In version 2.15.0, only users with the Administrator role can access the New GUI. Support for additional roles is planned for a future release.
-
Signing Into One UI Signs You Out of the Other: Signing in to the Old (legacy) GUI while already signed in to the New GUI — or vice versa — signs you out of the other interface after a few seconds. Signing in to the New GUI first does not cause this when then signing in to the Old GUI.
-
Jobs That Complete With Warnings Briefly Display as Errors: A job that finishes with a warning (not an outright failure) initially appears in an error state on the Jobs page. After about 15 minutes, once the job's history is pulled from Security Guard, it correctly displays as a success. This is a display-timing issue only — the job itself completed successfully.
Active Auditor
-
Active Auditor DLP Trigger Shows Incorrect Threat Category: A Data Loss Prevention (DLP) trigger event's threat category currently displays as "Suspicious Activity" in the event slideout, instead of the correct "Data Loss Prevention."
-
Active Auditor Allows Creating a CRTA Policy with Empty Audit Criteria: In the new UI, a Custom Real-Time Audit (CRTA) policy can be created and saved with empty audit criteria, with no validation warning shown. The previous UI correctly blocked this and displayed an "audit criteria is empty" warning; the new UI is missing this validation, allowing an invalid or incomplete policy to be created.
-
Active Auditor Events With Multiple Triggers Show Duplicate "Suspicious Activity" Labels: When an Active Auditor event is triggered by more than one rule at once (for example, both Mass Delete and a Custom Trigger), the event slideout and Investigation page show the threat category as repeated, generic "Suspicious Activity" entries instead of naming each distinct trigger. The Signal Strength panel already identifies the actual triggers involved.
Threat Hunting
-
Threat Hunting Instance Cannot Be Deleted from Manage Services: Attempting to delete a Threat Hunting instance from Manage Services fails with an error stating the service could not be found at the specified IP and port, and the instance is not removed.
-
Threat Hunting Webhooks Fail When Leftover
THEventRetrieverTag Is Present: Threat Hunting event webhooks may fail to fire if/opt/superna/sca/data/sync.xmlcontains a leftoverTHEventRetrieverentry from an earlier workaround applied in prior releases. This entry is no longer needed and can prevent webhook delivery for Threat Hunting events.Workaround: Comment out the
THEventRetrieverline insync.xmland restart SCA.
Threat Detections
- Threat Detections Slideout Window Does Not Auto-Refresh: The Threat Detections event slideout window does not consistently refresh in real time. Fields such as Items Affected and lockout time in the details section may not update automatically after an action is taken; the slideout must be closed and reopened to see the current data.
Integrations
- Webhook Payload URL Field Does Not Link to the Correct Event: The
URLfield in the Data Security webhook payload sent to integrated SIEM/SOAR solutions does not link to the correct event. A fix is planned for version 2.16.0.
Investigate & Recover
-
Items & Recovery CSV Download Tooltip and Status Inaccuracies: On the Investigate & Recover page's Items & Recovery tab, the download tooltip label is incorrect, and only a CSV download option is available (no Download XML option). Additionally, the downloaded CSV file always shows "Recoverable" as the status for every row, regardless of the item's actual recoverable, unrecoverable, or recovered state.
-
Snapshot Failure Messages on Investigate & Recover Can Be Stale or Misleading: The snapshot failure message shown for an event does not update if a follow-up snapshot job is run again, the "View Job" button can remain visible even after the job is no longer available, the displayed "Last Attempt" time doesn't always reflect the most recent attempt, and full error detail is shown immediately rather than collapsed behind the expand control.
Detection Controls
-
Some Multi-Word Custom Suspicious Extensions Cannot Be Removed in the New GUI: A custom suspicious extension entry made up of two words cannot always be removed from the Suspicious Extensions list in the New GUI.
-
Learned Thresholds Entry Shows a Path Under User ID After Marking an Event as False Positive: When a threat detection event is marked as a false positive, the resulting Learned Thresholds entry incorrectly includes a path under the User ID field. This does not happen in the Old GUI.
-
Warning Expiry Field Can Appear Blank on First Load (Old GUI): In the Old (legacy) GUI, the WARNING severity Threshold's Expiry (minutes) field can appear blank the first time the Threshold panel is opened after a page reload, even though a value is actually saved. Reopening the panel a second time shows the correct value. If changes are saved while the field displays blank, the blank value is accepted and can overwrite the real expiry setting.
-
A Note Can Be Lost When Converting an Ignore List Entry to Monitor Only (Old GUI): If a path already has a Monitor Only entry, converting an Ignore List entry for that same path to Monitor Only silently drops the incoming note rather than merging it — the pre-existing Monitor Only note is kept instead.
Data Auditing
-
WireTap Events Show the Same Value in the Path and File Columns: In the New GUI, a WireTap event row displays identical data in both the Path and File columns. The Old (legacy) GUI shows only a Path column. A fix is planned for a future release.
-
Robo Audit Report Discoverability and Timestamp Inconsistencies: When a Robo Audit job runs on schedule or manually, the job appears on the Health Check Runs page, but there's no clear indication that the generated user/path audit reports can be found under Data Auditing's Queries & Reports "All Reports" tab. On the All Reports tab, it's difficult to determine which user/path audit report corresponds to which Robo Audit job, and the report's listed start time reflects the Robo Audit job's start time rather than the individual user/path query's start time.
Workaround: Compare the Robo Audit job's timestamp on the Runs page with the timestamps on the All Reports page. Note that the Runs page displays time in 24-hour format while All Reports uses 12-hour format, and that All Reports shows the Robo Audit job's start time rather than the individual user/path query's start time.
-
Built-in Queries Cannot Be Scheduled in the New GUI: Scheduling is currently only available for built-in queries in the Old (legacy) GUI. In the New GUI, scheduling works for custom queries/reports, but not yet for built-in queries — this will be added in a future release.
-
Cannot Remove a Built-In Query's Schedule in the Old GUI: Using the delete/remove schedule action on a built-in query in the Old (legacy) GUI does not actually remove it — the query keeps running on its existing schedule. Removing a schedule works correctly in the New GUI for custom queries; however, since built-in queries currently can't be scheduled from the New GUI at all (see the entry above), there's no way to stop an already-scheduled built-in query if you no longer want it running.
Inventory & Health Check
- No Option to Delete ECA Nodes in the New GUI: The New GUI does not provide a delete option for ECA nodes, on either the Inventory (Manage Devices) page or the Health Check Manage Services page. The Old (legacy) GUI's Manage Services page includes a Delete column for removing ECA nodes.
See Also
- What's New – Entry point for release information.
- Prerequisites – Current platform compatibility tables.
- Installation Guide – Install and deploy Data Security.
Need Help?
- Contact Support: Reach out to Superna Support for configuration assistance or troubleshooting help.