Skip to content

VAST

v6.7.0 Feature

This release adds 3 notable features for engineering teams evaluating rollout.

βœ“ No known CVEs patched
Read the diff β†’ Tool health β†’ What is this tool? β†’

✓ No known CVEs patched in this version

Topics

dataops incident-response investigation netflow pcap pipelines
+8 more
secdataops security siem sigma soc suricata threathunting zeek

Summary

AI summary

Updates πŸš€ Features, 🐞 Bug fixes, and duration across a mixed release.

Changes in this release

Feature Medium

Adds `fork_merge` operator for fanning out subpipelines and merging outputs.

Adds `fork_merge` operator for fanning out subpipelines and merging outputs.

Source: llm_adapter@2026-07-15

Confidence: high

β€”
Feature Medium

Adds `force-stop` action to terminate pipelines immediately.

Adds `force-stop` action to terminate pipelines immediately.

Source: llm_adapter@2026-07-15

Confidence: high

β€”
Performance Low

Improves latency and overhead of `/serve-multi` endpoint in Tenzir Node.

Improves latency and overhead of `/serve-multi` endpoint in Tenzir Node.

Source: llm_adapter@2026-07-15

Confidence: high

β€”
Bugfix Medium

Restores raw‑log ingestion for Google SecOps via `to_google_secops` operator.

Restores raw‑log ingestion for Google SecOps via `to_google_secops` operator.

Source: llm_adapter@2026-07-15

Confidence: high

β€”
Bugfix Medium

Resets inactive group keys in `summarize` periodic emission, preventing output growth.

Resets inactive group keys in `summarize` periodic emission, preventing output growth.

Source: llm_adapter@2026-07-15

Confidence: high

β€”
Bugfix Low

Eliminates avoidable warnings in macOS source builds.

Eliminates avoidable warnings in macOS source builds.

Source: llm_adapter@2026-07-15

Confidence: high

β€”
Full changelog

This release introduces the fork_merge operator for fanning out subpipelines over the same input and merging their outputs into one stream. It also improves the performance of the Tenzir Platform and restores raw-log ingestion for Google SecOps.

πŸš€ Features

Fan out with the fork_merge operator

The new fork_merge operator runs multiple subpipelines on the same input stream and merges their outputs back into a single stream. Each branch receives a copy of every event, and the results are interleaved downstream:

subscribe "in"
fork_merge {
  summarize a=sum(bytes)
}, {
  summarize b=count()
}, {
  summarize c=max(duration)
}
publish "out"

Unlike fork, whose subpipeline must end in a sink and which forwards its input unchanged, fork_merge lets you fan out independent computations and rejoin them. Every branch is an events-to-events transformation.

By @aljazerzen and @claude in #6436.

Force stop action for pipelines

Pipelines now support a force-stop action that terminates a pipeline immediately instead of waiting for in-flight data to drain.

A regular stop moves a running pipeline into the stopping state and lets it drain gracefully, which can take up to the configured tenzir.shutdown-grace-period.

Sending force-stop to a pipeline that is already stopping cancels the grace period and kills it immediately.

By @aljazerzen and @claude in #6442.

Improved Platform Performance Support

In order to improve the performance of the Tenzir Platform, we made a few internal changes to the Tenzir Node. Notably the /serve-multi endpoint received several improvements that reduce latency and overhead when driving the frontend, making pipeline output fetching more responsive.

This does not requires any user action. We recommend that you do not manually use the serve operator or endpoints.

By @lava in #6373.

🐞 Bug fixes

Cleaner source builds on macOS

Source builds on macOS no longer print avoidable warnings from platform-specific code, fmt 12 integration, or bundled dependencies. This makes new compiler diagnostics easier to spot.

By @mavam and @codex in #6441.

Google SecOps unstructured ingestion support

The to_google_secops operator can once again forward raw logs without parsing their timestamps by selecting the supported Ingestion API:

from {raw_log: "<134>1 2026-07-14T09:00:00Z host app - - - message"}
to_google_secops api="ingestion",
  log_text=raw_log,
  log_type="CUSTOM_JSON",
  private_key=secret("google-private-key"),
  client_email=secret("google-client-email"),
  customer_id=secret("google-customer-id")

With api="ingestion", log_entry_time is optional so that Google SecOps can derive the timestamp from the raw log. The api="import" path remains the default for compatibility with Tenzir 6.2, and UDM events and entities continue to use the Import API.

By @mavam and @codex in #6446.

Reset grouped summarize state after periodic emission

The summarize operator no longer retains inactive group keys when using periodic emission in reset mode. Previously, every interval emitted one event for every group seen since the pipeline started, including inactive groups with reset aggregate values. This caused output batches and import metrics to grow over time. Each interval now contains only groups that received events during that interval.

By @raxyte in #6435.

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track VAST

Get notified when new releases ship.

Sign up free

About VAST

Open source security data pipeline engine for structured event data, supporting high-volume telemetry ingestion, compaction, and retrieval; purpose-built for security content execution, guided threat hunting, and large-scale investigation.

All releases β†’

Beta — feedback welcome: [email protected]