Every detection platform asks for your trust twice: once when it raises an alert, and once when you tell it to stay quiet. Logster v1.3.0 is built around both halves of that bargain. It rebuilds whitelisting so that approvals stay visible, measurable and impossible to hide behind, and it connects every explanation Logster gives you to the evidence that produced it.

Alongside that, this release adds storage that looks after itself and a delivery model for air-gapped clusters. Here is what changed.

Whitelisting you can trust

A whitelist is a statement of trust, and, as we have written before, whitelisting a graph is harder than whitelisting a filename. Logster v1.3.0 makes that statement easier to write precisely, easier to check, and much harder to abuse.

Why this matters beyond convenience: every suppression that nobody can explain later is tuning debt, a permanent blind spot. Approvals should stay visible, measurable and reversible, and Logster v1.3.0 is built that way.

Evidence you can click

When Logster flags an attack, it explains its reasoning. In Logster v1.3.0 that explanation is connected to the evidence.

Open an investigation and the events behind the verdict move to the top of the list. The graph highlights the handful of nodes that form the attack chain, out of what can be dozens of routine ones. Click a step in the explanation, for example “PowerShell wrote to the startup folder”, and the graph spotlights exactly the nodes that step refers to.

This runs only when an analyst opens an investigation, so it never slows detection. It also annotates the original verdict rather than re-deciding it, so what you click through is the reasoning that produced the alert. Linux events now carry the same traceability back to their source, so this works across Windows and Linux.

It answers the question we think every buyer should ask a detection vendor: show me a finding exactly as an analyst receives it. (More on that in our guide to evaluating threat detection platforms.)

Storage that looks after itself

Security data grows quietly until the disk fills up, usually at the worst possible moment. Logster v1.3.0 adds storage-aware retention.

Built for air-gapped environments

For organisations that can’t send security data anywhere, the Logster AI model can now be delivered separately from its runtime image and loaded from local storage inside an air-gapped OpenShift cluster. The runtime image is much smaller, the two downloads can be verified independently, and the model runs fully offline with no internet access at runtime.

Under the bonnet

A few smaller things that shipped with Logster v1.3.0:

Upgrading to Logster v1.3.0

Logster v1.3.0 is available now. Upgrade instructions from v1.2.1, including the new retention settings, are in the Logster documentation.

If you’d like to see Logster v1.3.0 on your own data, get in touch.