← Back to all sparks
M

ManageEngine Log360

ANALYTICS
Velocity5.0

Integrated SIEM solution with log management, threat detection, and compliance auditing.

Log360 is collapsing a scattered suite into one console — and opening the migration door to it.

siemplatform-consolidationmarketplace-extensionslog-managementcve-remediationmigration
Current state
Two threads run through these builds. The first is consolidation: Unified Log360 is a centralized architecture pulling Log360 components and integrations into a single interface, and a PPM now lets standalone Log360 and EventLog Analyzer deployments carry supported configurations across. The second is a heavy security cadence — CVEs in this window include an unauthenticated local collector registration bypass, an authentication bypass allowing login as another user, and two authenticated RCE paths, alongside bundled PostgreSQL, Tomcat, Elasticsearch, and Kafka upgrades.
Where it's heading
ManageEngine is turning integrations into marketplace extensions rather than core releases — CrowdStrike Falcon Event Streams, Okta, Bitdefender GravityZone, and MikroTik all arrived that way, and extensions can now own a Dashboard tab. Combined with the Unified migration path and earlier work pulling NetFlow Analyzer, Firewall Analyzer, and the OpManager suite in as log sources, the shape is clear: one console, one log pipeline, and a plug-in surface where connector work happens. The recurring fixes around migration failures and service pack stacking suggest that transition is still bumpy in the field.
Prediction
Expect connector coverage to keep expanding through the marketplace rather than through builds, and continued migration hardening as more standalone deployments move to Unified Log360. The steady CVE cadence points to further security patch builds on a two-to-four week rhythm.

Recent moves

  1. 8d ago

    Two auth-bypass CVEs patched; PostgreSQL and Tomcat bumped

    A security-weighted build closing an unauthenticated collector registration bypass that let an actor impersonate a trusted local collector, plus an authentication bypass permitting login as another user. It also lifts bundled PostgreSQL and Tomcat and fixes agent memory on terabyte-scale File Integrity Monitoring, the kind of ceiling only large deployments hit.

  2. 16d ago

    CrowdStrike, Okta and Bitdefender ship as marketplace extensions

    Bitdefender GravityZone, CrowdStrike Falcon Event Streams, Okta, and MikroTik land as marketplace extensions rather than core integrations, and extensions gain their own Dashboard tab. It broadens both the connector catalogue and what a third-party extension is allowed to own in the interface.

  3. 1mo ago

    Applying multiple service packs in one pass no longer fails

    A narrow fix for applying several service packs in sequence without restarting Log360 in between. Upgrade-path plumbing that matters only during maintenance windows.

  4. 1mo ago

    Three CVEs closed, including two authenticated RCE paths

    Three CVEs closed, two of them authenticated remote code execution — one in the remote agent installation workflow, one reachable by users holding log forwarding and filtering privileges. Both sit in exactly the delegated-permission surface a SIEM hands to operators.

  5. 2mo ago

    Standalone Log360 can now migrate to the Unified Log360 architecture

    ⚡ SPARK

    This PPM makes Unified Log360 reachable for the installed base: eligible standalone Log360 deployments, and those integrated with EventLog Analyzer, can migrate supported configurations to the unified architecture. It converts consolidation from a greenfield option into the destination for existing customers, and the surrounding migration bug fixes show the transition is actively underway.

  6. 2mo ago

    Migration failures from threat import and missing tables fixed

    Fixes for migration failures traced to the threat import module and missing database tables. Small in itself, but another data point that the move to the unified architecture is where the breakage is showing up.