- Detected by Pingoru
- Apr 27, 2026, 09:32 AM UTC
- Resolved
- Apr 27, 2026, 11:55 AM UTC
- Duration
- 2h 23m
Affected: Web application
Timeline · 2 updates
-
monitoring Apr 27, 2026, 09:32 AM UTC
We are currently experiencing slowness on some pages due to one of our components being overloaded. A fix has been applied by our team and performances are coming back up. We are still investigating on the root cause and working on improving performances and latency. We will keep you updated
-
resolved Apr 27, 2026, 11:55 AM UTC
Response time were back to normal at 11:25 CEST and are stable since. This incident is over. Thank you for your patience.
Read the full incident report →
- Detected by Pingoru
- Apr 24, 2026, 03:59 PM UTC
- Resolved
- Apr 25, 2026, 08:50 AM UTC
- Duration
- 16h 51m
Affected: Event storage
Timeline · 4 updates
-
identified Apr 24, 2026, 03:59 PM UTC
Today at 12:38 CEST, we have started to progressively deploy our detection engine. Unfortunately, due to a misconfiguration, some events were not indexed into our storage engine, but all events were processed and related alerts were raised. The proportion of non-indexed events increased gradually. This issue was identified at 16:40 CEST and a fix was deployed around 17:00 CEST. We are now working to fix the situation and ensure that all missed events will be correctly pushed to the storage engine. During the issue, the detection engines continued to work as expected and alerts (including their related events) were correctly raised. All events related to alerts were also correctly indexed into our storage engine.
-
identified Apr 24, 2026, 04:58 PM UTC
Our team is currently deploying a fix in order to index the missed events into the storage engine. Be aware that the process is expected to cause duplicates of some events that were already pushed. Thanks for your patience.
-
monitoring Apr 24, 2026, 06:16 PM UTC
The fix has been deployed and missed events are currently being indexed into our storage engine. We will continue to inform you on the progress.
-
resolved Apr 25, 2026, 08:50 AM UTC
All missed events were correctly pushed to our storage engine during the night. This incident is now over. Thank you for your patience throughout this incident.
Read the full incident report →
- Detected by Pingoru
- Apr 22, 2026, 08:54 AM UTC
- Resolved
- Apr 22, 2026, 03:43 PM UTC
- Duration
- 6h 48m
Affected: Event storage
Timeline · 3 updates
-
identified Apr 22, 2026, 08:54 AM UTC
We are currently experiencing instability in the event storage cluster impacting indexation processes. This causes delays in events showing in events pages. Troubleshooting efforts are ongoing. Detection and alert raising are not impacted. Thanks you for your understanding.
-
monitoring Apr 22, 2026, 09:29 AM UTC
Event storage cluster instability impacting indexation has been resolved. Indexing performance has returned to normal and is stable. There is still some expected delay before events show on events page, but it is decreasing slowly. Detection and event alerting remained unaffected throughout the incident. We will provide a new update once indexation is back to real-time.
-
resolved Apr 22, 2026, 03:43 PM UTC
The indexation is back to real-time since 17:30 CEST. Thank you for you patience.
Read the full incident report →
- Detected by Pingoru
- Apr 16, 2026, 03:16 PM UTC
- Resolved
- Apr 16, 2026, 06:41 PM UTC
- Duration
- 3h 25m
Affected: Event ingestionEvent storageDetectionHuntingCase management
Timeline · 5 updates
-
investigating Apr 16, 2026, 03:16 PM UTC
We are currently investigating an incident affecting several components including the ingestion process and the event searches. Our engineering teams are actively working to identify the root cause and implement a resolution. Further updates will be provided as the situation evolves.
-
identified Apr 16, 2026, 03:26 PM UTC
The issue has been identified. Our teams are working on a fix.
-
monitoring Apr 16, 2026, 03:28 PM UTC
Our team partially fixed the situation. The systems are progressively recovering.
-
monitoring Apr 16, 2026, 04:02 PM UTC
The delay on event ingestion is now catching up. The event ingestion is stable and systems are recovering. Our teams are still monitoring the situation.
-
resolved Apr 16, 2026, 06:41 PM UTC
This incident has been resolved.
Read the full incident report →
- Detected by Pingoru
- Apr 15, 2026, 07:57 AM UTC
- Resolved
- Apr 15, 2026, 04:46 PM UTC
- Duration
- 8h 48m
Affected: Event ingestionAutomation
Timeline · 4 updates
-
investigating Apr 15, 2026, 07:57 AM UTC
We are currently experiencing an incident impacting the playbook automation feature. The team is actively investigating the root cause and working on remediation.
-
identified Apr 15, 2026, 08:34 AM UTC
The issue has been identified and a fix is being implemented.
-
monitoring Apr 15, 2026, 12:08 PM UTC
A fix has been implemented and we are monitoring the results.
-
resolved Apr 15, 2026, 04:46 PM UTC
This incident has been resolved.
Read the full incident report →
- Detected by Pingoru
- Apr 08, 2026, 09:15 AM UTC
- Resolved
- Apr 08, 2026, 12:07 PM UTC
- Duration
- 2h 51m
Affected: Detection
Timeline · 4 updates
-
investigating Apr 08, 2026, 08:58 AM UTC
We are currently investigating an issue affecting Assets availability on the platform. Our Engineering team is fully mobilized to resolve the issue.
-
monitoring Apr 08, 2026, 09:15 AM UTC
The issue has been identified and the assets functionalities are back up, and available through the web application and APIs. Stabilization actions are ongoing which should not further impact users
-
monitoring Apr 08, 2026, 09:15 AM UTC
We are continuing to monitor for any further issues.
-
resolved Apr 08, 2026, 12:07 PM UTC
All assets functionality have been resolved and recovery actions completed. Thank you for your patience during resolution
Read the full incident report →
- Detected by Pingoru
- Apr 04, 2026, 09:00 PM UTC
- Resolved
- Apr 04, 2026, 10:50 PM UTC
- Duration
- 1h 50m
Affected: Event ingestion
Timeline · 3 updates
-
investigating Apr 04, 2026, 09:00 PM UTC
We are currently investigating degraded ingestion performance. Our teams are actively working to identify the cause and restore normal performance as quickly as possible. We will share another update as soon as more information is available.
-
monitoring Apr 04, 2026, 09:26 PM UTC
We have identified and fixed the issue affecting ingestion. Ingestion is now operating normally again. Some delay may still be visible while the remaining lag is being processed, and we expect the situation to be fully back to normal soon. We are continuing to monitor the recovery closely.
-
resolved Apr 04, 2026, 10:50 PM UTC
The issue affecting ingestion has been resolved. Ingestion performance is back to normal, and the temporary lag has been fully absorbed. We will continue to monitor the platform, but the incident is now closed.
Read the full incident report →
- Detected by Pingoru
- Mar 20, 2026, 08:25 AM UTC
- Resolved
- Mar 23, 2026, 08:13 AM UTC
- Duration
- 2d 23h
Affected: Automation
Timeline · 4 updates
-
identified Mar 20, 2026, 08:25 AM UTC
We are currently experiencing an incident affecting task execution due to a limitation in the cluster responsible for coordination and scheduling. This issue started yesterday around 18:26 and has prevented new processing tasks from starting. The engineering team has identified the root cause to mitigate the issue. Investigation and remediation efforts are ongoing.
-
monitoring Mar 20, 2026, 09:05 AM UTC
Pod scheduling and task execution have resumed following administrative actions on the cluster. The situation is currently being monitored.
-
monitoring Mar 20, 2026, 03:56 PM UTC
We are currently replaying the pending tasks and monitoring system stability.
-
resolved Mar 23, 2026, 08:13 AM UTC
This incident has been resolved.
Read the full incident report →
- Detected by Pingoru
- Mar 06, 2026, 10:54 AM UTC
- Resolved
- Mar 06, 2026, 03:52 PM UTC
- Duration
- 4h 57m
Affected: Web applicationDetectionCTI Search
Timeline · 3 updates
-
identified Mar 06, 2026, 10:54 AM UTC
Following a maintenance operation on a shared event storage cluster node, observables are currently unavailable, impacting alert generation and sightings across all regions. This results in alerts not being raised, affecting the product's visibility on security events.
-
monitoring Mar 06, 2026, 10:59 AM UTC
A fix has been implemented and we are monitoring the results.
-
resolved Mar 06, 2026, 03:52 PM UTC
This incident has been resolved.
Read the full incident report →
- Detected by Pingoru
- Feb 26, 2026, 03:09 PM UTC
- Resolved
- Feb 26, 2026, 06:45 PM UTC
- Duration
- 3h 36m
Affected: Event ingestion
Timeline · 3 updates
-
identified Feb 26, 2026, 03:09 PM UTC
The indexation service in the FRA1 region is currently degraded due to multiple nodes going down in the event storage cluster caused by a hardware outage on our cloud provider. The incident started around 15:00 and prevents writing to several indices. Operations teams are performing recovery operations on the affected indices to restore service.
-
monitoring Feb 26, 2026, 03:22 PM UTC
The indexation service in the FRA1 region has been restored following a hardware outage at the cloud provider affecting multiple nodes in the event storage cluster. Recovery operations on affected indices have been completed. Monitoring continues to ensure stability and recovery.
-
resolved Feb 26, 2026, 06:45 PM UTC
Recovery has been completed, and backlogged events have been fully processed. We thank you for your patience during the resolution.
Read the full incident report →
- Detected by Pingoru
- Feb 26, 2026, 10:40 AM UTC
- Resolved
- Feb 26, 2026, 10:59 AM UTC
- Duration
- 18m
Affected: Web applicationEvent ingestionEvent storageDetectionHuntingCase managementAutomation
Timeline · 4 updates
-
investigating Feb 26, 2026, 10:40 AM UTC
Some API endpoints are returning 500 errors intermittently. Our engineering team is currently investigating the issue. We thank you for your patience during the resolution.
-
identified Feb 26, 2026, 10:57 AM UTC
The issue has been identified and a fix is being implemented.
-
monitoring Feb 26, 2026, 10:57 AM UTC
A fix has been implemented and we are monitoring the results.
-
resolved Feb 26, 2026, 10:59 AM UTC
This incident has been resolved.
Read the full incident report →
- Detected by Pingoru
- Feb 24, 2026, 04:20 PM UTC
- Resolved
- Feb 24, 2026, 07:05 PM UTC
- Duration
- 2h 45m
Affected: Event ingestion
Timeline · 3 updates
-
investigating Feb 24, 2026, 04:20 PM UTC
We are currently experiencing delays in event processing in the FRA1 region. This issue is related to an incident from yesterday, which has been resolved and was caused by the cloud provider. Our team is working to fully restore normal operations.
-
identified Feb 24, 2026, 06:17 PM UTC
Event processing delays in the FRA1 region persist following yesterday's cloud provider-related incident. We've identified the issue and we're working towards improving system's stability and reducing processing lags. The situation is actively monitored and being addressed.
-
resolved Feb 24, 2026, 07:05 PM UTC
Event processing delays in the FRA1 region have been resolved. Normal operations have resumed and the system is stable.
Read the full incident report →
- Detected by Pingoru
- Feb 23, 2026, 02:15 PM UTC
- Resolved
- Feb 24, 2026, 08:53 AM UTC
- Duration
- 18h 37m
Affected: Event storage
Timeline · 6 updates
-
investigating Feb 23, 2026, 02:15 PM UTC
We have identified more than a hundred servers down at once on FRA1. As this is affecting nearly all clusters, we are currently looking into a cloud provider issue. At this time we are not sure about the overall impact, as our team is looking into it.
-
identified Feb 23, 2026, 02:18 PM UTC
More than a hundred servers are down due to an issue impacting network switches in one of the data centers, causing disruptions to the message bus and other infrastructure components. Our teams are actively investigating, and we are coordinating with the data center provider to determine the estimated time for recovery.
-
identified Feb 23, 2026, 03:06 PM UTC
This incident continues to impact approximately 80 servers. The event storage cluster is recovering with nodes restarting and data becoming progressively available. Indexation has resumed with some lag still present. Frontend, APIs, automation features, and detection services remain operational. The main residual issues relate to forwarding difficulties caused by four message bus nodes being down, affecting forwarding to search indexing components. Recovery of infrastructure nodes is ongoing. We are still in contact with our cloud provider to ensure all servers come back online as soon as possible.
-
identified Feb 23, 2026, 03:58 PM UTC
This incident is ongoing with around 80 servers still down. Indexation is operating with less than 10 minutes of lag on the event storage cluster. The data center provider is manually rebooting servers that failed to start correctly, prioritizing critical nodes including message bus nodes. Recovery efforts are ongoing.
-
identified Feb 23, 2026, 05:25 PM UTC
All event storage cluster servers hosting long-term data are now online with indexes gradually recovering; workers responsible for data retention will be restarted shortly. Remaining event storage cluster servers are being restarted via a custom process and should rejoin shortly.
-
resolved Feb 24, 2026, 08:53 AM UTC
A few servers are still offline but FRA1 is fully functional since 23/02 at 23:00 CET. At this time we are still expecting a post-mortem from our cloud provider. This incident is now resolved.
Read the full incident report →
- Detected by Pingoru
- Feb 16, 2026, 05:17 PM UTC
- Resolved
- Feb 17, 2026, 08:41 AM UTC
- Duration
- 15h 23m
Affected: Web application
Timeline · 2 updates
-
investigating Feb 16, 2026, 05:17 PM UTC
At 17:50 one of our web-facing provider had a major incident on their load balancer product, resulting in our web UI and APIs being unavailable until 18:05. We have switched over to another provider, the web UI and APIs are now fully available. This does not impact event ingestion in any way. We are still monitoring the situation and opened a case with the faulty cloud provider.
-
resolved Feb 17, 2026, 08:41 AM UTC
Incident has been resolved at 18:05 as stated in previous update. All remediation actions have been identified to avoid reoccurence. Thank you for your patience during the incident.
Read the full incident report →
- Detected by Pingoru
- Feb 12, 2026, 02:16 PM UTC
- Resolved
- Feb 12, 2026, 05:01 PM UTC
- Duration
- 2h 45m
Affected: Case managementAutomation
Timeline · 3 updates
-
identified Feb 12, 2026, 02:16 PM UTC
We have identified an issue impacting retrieval of Alerts and Cases through API. The issue is also impacting the Web UI in Alerts listing and Display. Our Engineering team is applying remediation actions to restore the service. We apologize for the inconvenience caused and we thank you for your patience during the resolution.
-
identified Feb 12, 2026, 03:24 PM UTC
We are continuing to work on a fix for this issue.
-
resolved Feb 12, 2026, 05:01 PM UTC
The situation has been recovered and the Alerts and Cases functionalities are now fully availaible, through API and the Web UI. We thank you for your patience during the resolution of the incident.
Read the full incident report →
- Detected by Pingoru
- Feb 10, 2026, 05:34 AM UTC
- Resolved
- Feb 13, 2026, 03:04 PM UTC
- Duration
- 3d 9h
Affected: Event ingestionEvent storageDetectionHuntingCase management
Timeline · 20 updates
-
investigating Feb 10, 2026, 04:02 AM UTC
We are investigating an ongoing incident on the storage cluster having a major impact.
-
identified Feb 10, 2026, 04:04 AM UTC
The event storage cluster is partially down and most data are unavailable. The team is trying to stabilize the cluster state. No data is lost but data availability will recover progressively in the next hours.
-
identified Feb 10, 2026, 05:34 AM UTC
The event storage cluster is partially down and most data are still unavailable. The team is currently trying to reload all data. No data is lost but data availability will recover progressively in the next hours. There is also a huge delay on event processing.
-
identified Feb 10, 2026, 06:37 AM UTC
The event storage cluster is partially down and most data are still unavailable. The team is still trying to reload all data. No data is lost but data availability will recover progressively in the next hours. There is also a huge delay on event processing.
-
identified Feb 10, 2026, 07:34 AM UTC
The event storage cluster is partially down and most data are still unavailable. The team is still trying to reload all data. No data is lost but data availability will recover progressively in the next hours. There is also a huge delay on event processing.
-
identified Feb 10, 2026, 09:39 AM UTC
Update - Our engineering teams have identified the source of the recent instability and are actively progressing through the restoration process. We would like to emphasize upfront that all data remains fully intact and secure. - Data Preservation: All data is preserved and its integrity is guaranteed. - Progressive Recovery: Data reloading is underway, and access will be progressively restored over the coming hours. - Additional mitigation works: in parallel of the data reloading, additional technical solutions are under evaluation to further accelerate recovery - Event Processing: Temporary delays in event processing may be observed while the system returns to its optimal state. Our priority is to restore the cluster to full operational capacity, and we are working diligently to finalize these steps. We appreciate your continued patience and will provide the next update before 12.00 CET.
-
identified Feb 10, 2026, 11:13 AM UTC
Our engineering team is making steady progress with the restoration. Our efforts have continued and are focused on the following actions - Alert Data Recovery: restoring events linked to alerts to ensure customers can resume immediate investigations. - Search Functionality: re-enable general event searching outside of the alert scope. - Cluster Restoration: full background restoration of the Storage facility for all historical events. Our full technical team is committed to restore the cluster to full operational capacity, and we are working diligently to advance these steps. We appreciate your continued patience and will provide the next update before 14.00 CET.
-
identified Feb 10, 2026, 12:21 PM UTC
Our engineering team continues to make steady progress restoring the storage facility. What’s working again - You can search events again, - Events linked to older alerts are fully available, so you can investigate historical alert activity as usual. What may still be delayed - Events linked to newer alerts may still appear with some delay. These delays are decreasing and are expected to be fully resolved within the next 2 hours. What’s still impacted - Some functionality remains inconsistent, including SOL queries. Our full technical team remains engaged and is working to restore full operational capacity as quickly as possible. Thank you for your patience, we’ll share the next update before 15:00 CET.
-
identified Feb 10, 2026, 12:22 PM UTC
We are continuing to work on a fix for this issue.
-
identified Feb 10, 2026, 02:24 PM UTC
Customers can now investigate their alerts with the associated events in real time. What’s working - Events linked to alerts are fully available, so you can investigate all alert activity as usual. - Global event search is restored, except for search combining eternal and non-eternal events What is still impacted - Some functionalities remain inconsistent, including SOL queries. Our technical team remains fully committed and is working to restore full operational capacity as quickly as possible. Thank you for your patience and understanding. The next update will be shared before 17:00 CET.
-
identified Feb 10, 2026, 03:47 PM UTC
Our engineering team continues to make steady progress restoring the storage facility. What’s working - Events linked to alerts are fully available, customers can investigate all alert activity as usual. - Global event search is restored, except for search combining eternal and non-eternal events What is still impacted - Some functionalities remain inconsistent, including SOL queries, correlation and anomaly-based alerts. Our technical team remains fully committed and is working to restore full operational capacity as quickly as possible. Thank you for your patience and understanding. The next update will be shared before 18:30 CET.
-
identified Feb 10, 2026, 06:11 PM UTC
Update - Our engineering team is continuing to work diligently on the full restoration of the storage facility. We are making steady progress, and the platform status remains consistent with our previous update: What’s working - Alert Investigation: Events linked to alerts are fully available. - Event Search: Global event search is available (excluding searches combining eternal and non-eternal events). What is still being restored - Advanced Functionalities: SOL queries, correlation, and anomaly-based alerts remain inconsistent. Our team remains fully mobilized to resolve these remaining items as quickly as possible. Thank you for your continued patience. The next update will be shared before 21:00 CET.
-
identified Feb 10, 2026, 07:48 PM UTC
Update - Our engineering team is continuing to work diligently on the full restoration of the storage facility. We are making steady progress, and the platform status remains consistent with our previous update: What’s working - Alert Investigation: Events linked to alerts are fully available. - Event Search: Global event search is available (excluding searches combining eternal and non-eternal events). What is still being restored - Advanced Functionalities: SOL queries, correlation, and anomaly-based alerts remain inconsistent. Our team remains fully mobilized to resolve these remaining items as quickly as possible. Thank you for your continued patience.
-
monitoring Feb 11, 2026, 12:09 AM UTC
Our engineering team is continuing to work diligently on the full restoration of the storage facility. We are now fully in control of the storage platform and are progressively re-enabling its core features. We’ve also entered the last phase of the incident: the lag processing phase to catch up on pending/backlogged processing. What’s working - Alert Investigation: Events linked to alerts are fully available. - Event Search: Global event search is available (excluding searches combining eternal and non-eternal events). What is still being restored - Advanced functionalities: SOL queries, correlation, and anomaly-based alerts may be inconsistent until the backlog is fully processed. Our team remains fully mobilized and committed to resolving the remaining items as quickly as possible. Thank you for your continued patience.
-
monitoring Feb 11, 2026, 09:22 AM UTC
Our engineering team is continuing to work diligently on the full restoration of the storage facility. We are now fully in control of the storage platform and are progressively re-enabling its core features. The lag processing phase continues to catch up on pending/backlogged processing. We are making steady progress, and the platform status remains consistent with our previous update: What’s working - Alert Investigation: Events linked to alerts are fully available. - Event Search: Global event search is available (excluding searches combining eternal and non-eternal events). What is still being restored - Advanced functionalities: SOL queries, correlation, and anomaly-based alerts may be inconsistent. Our team remains fully mobilized and committed to resolving the remaining items as quickly as possible. Thank you for your continued patience. The next update will be shared before 14:00 CET
-
monitoring Feb 11, 2026, 03:22 PM UTC
Our engineering team is continuing to work diligently on the full restoration of the storage facility. The lag processing phase continues to catch up on pending/backlogged processing. We are making steady progress, and the platform status remains consistent with our previous update: What’s working Alert Investigation: Events linked to alerts are fully available. Event Search: Global event search is available (excluding searches combining eternal and non-eternal events). What is still being restored Advanced functionalities: SOL queries, correlation, and anomaly-based alerts may be inconsistent. Our team remains fully mobilized and committed to resolving the remaining items as quickly as possible. Thank you for your continued patience. The next update will be shared before 19:00 CET
-
monitoring Feb 11, 2026, 08:53 PM UTC
Our engineering team is continuing to work diligently on the full restoration of the storage facility. Correlation detection capabilities have been restored. Related alerts will continue raise as the lag is being resolved. The lag processing phase continues to catch up on backlogged processing. What’s working - Alert Investigation: Events linked to alerts are fully available. - Event Search: Global event search is available (excluding searches combining eternal and non-eternal events). What is still being restored - Advanced functionalities: SOL queries, and anomaly-based alerts may be inconsistent. Our team remains fully mobilized and committed to resolving the remaining items as quickly as possible. Thank you for your continued patience.
-
monitoring Feb 12, 2026, 08:54 AM UTC
All features are now operational and the service is live, including SOL and anomaly detection. We are continuing to process a backlog of older events generated during the incident window. Some specific functionalities remain impacted until processing of the backlog, including - Event Search: searches combining eternal and non-eternal events - SOL requests for events between 10/02 13:00 UTC - 11/02 11:00 UTC Thank you for your patience throughout this incident.
-
monitoring Feb 12, 2026, 05:39 PM UTC
All features are now operational and the service is live. We are continuing to process a backlog of older events generated during the incident window. Some specific functionalities remain impacted until processing of the backlog, including - SOL requests for events between 10/02 13:00 UTC - 11/02 11:00 UTC Thank you for your patience throughout this incident.
-
resolved Feb 13, 2026, 03:04 PM UTC
The storage issue impacting our FRA1 region have been fully resolved. All functionalities have been restored. All queued data and events have now been successfully processed. We thank you for your patience throughout this incident.
Read the full incident report →
- Detected by Pingoru
- Feb 04, 2026, 07:00 PM UTC
- Resolved
- Feb 04, 2026, 09:22 PM UTC
- Duration
- 2h 21m
Affected: Detection
Timeline · 4 updates
-
investigating Feb 04, 2026, 08:14 PM UTC
We detected an outage in our alert processing service. We're currenlty investigating the issue. We appreciate your patience and will provide updates as soon as we have more information.
-
identified Feb 04, 2026, 08:15 PM UTC
We identified the issue and fixed it, and are currently catching the lag of delayed alerts.
-
monitoring Feb 04, 2026, 08:40 PM UTC
We're currently catching the delay on alert processing and monitoring closely the situation. We appreciate your patience and will provide updates as soon as we have more information.
-
resolved Feb 04, 2026, 09:22 PM UTC
Alert processing is fully operational, and all queued alerts have been processed. This incident is resolved, and we apologize for any inconvenience this may have caused.
Read the full incident report →