Skip to main content

Changelog — September 28 – October 11, 2026 (in progress)

New Features​

  • Sample data page. Example Corp sample data now has its own page in the docs and its own section in Settings › [Organization] › Sample data: what it includes, Pause for new sample alerts, a Remove automatically date and Remove sample data, which lists what goes and what stays before you confirm. Sample data is removed automatically 14 days after your own data starts arriving. See Sample data.
  • Guided hunts on Example Corp. Start this hunt on a Try a hunt on Example Corp card adds the card's suggested queries as query cells. Once you've started one, the card offers Resume, and a card for a part of the story that hasn't happened yet says when it will be available.
  • Organization profile. Describe your environment — products and data sources, size, business domain, cloud providers, security tools, compliance frameworks — on the organization's Overview, or during setup. Scout uses it to recommend hunts and spot telemetry gaps. See Organization profile.
  • Record & close in one step. The verdict cell asks for a one-line rationale, and Record & close hunt records the verdict and closes the hunt together; Record only keeps it open. After a reopen, the verdicts the hunt was closed on read Superseded. See Verdicts.
  • Undo and restore archived cells. Archiving a cell offers Undo, and an archived cell has Restore.
  • {{parameter}} prompts in the notebook. A query cell with unfilled parameters asks for them inline before it runs.
  • OR in searches. Join words or phrases with a capital OR to find events that contain any of them. Search these N values on pasted text now uses it. See Search telemetry.

Improvements​

  • A query typed on Auto runs. On the Auto language, in a query tab or on Home, SQL, SPL, KQL and other queries run in their own language instead of going to Scout. For SQL, Auto picks the dialect from the tables the query names and the connections in scope.
  • One set of approval words. Approve & run when approving starts a run, Approve otherwise, and Approve step on a checkpoint (under Your approval is needed). Accept task is gone. Endpoint proposals in Needs you show Review and are approved on their own card.
  • Needs you follows the notebook. Items are listed in notebook order, with the verdict last.
  • Honest Run all. The button says what it will do, such as Run 2 · 6 need approval, and its tooltip lists where it will stop.
  • Scout plans behind one gate. When Scout plans a hunt in Guide or Collaborator, the plan is query steps behind one approval checkpoint, and nothing runs before you approve it.
  • Closing a hunt settles it. Steps waiting for approval are rejected, running steps stop, and the hunt leaves Needs you. New Explorer tabs no longer attach to a closed hunt, and a closed hunt offers no reruns.
  • Scout: Guide / Collaborator / Operator. The hunt header's mode chip names Scout, so it no longer reads like a sharing role. When the header is short of space, its chips fold into +N and the title keeps its room.
  • Scout Summary sticks to the hunt. A hunt's Scout Summary is written from its own cells: hypothesis, queries and row counts, notes and verdict.
  • Sample hunts are Example Corp's. Sample hunts are owned by Example Corp (sample) and are read-only, and the hunt menu offers Add from Library…, Import YAML and Triggers… only to people who can edit the hunt.
  • Sample connections don't mark products Connected. In Add a source, products only Example Corp has a connection for show a Sample chip and stay under Available. Sample connections are in scope for queries.
  • Connection setup says why Continue is off, and a reloaded link keeps the product you picked.
  • Pulse links show the whole picture. Links from Pulse into triage keep Pulse's time window and show the whole team's hunts.
  • The approver can end live response that their approval started. See Files and console.
  • Live tail checks access. A live tail ends if you lose access to an organization it covers.
  • Better template search. Library and ⌘/Ctrl+K template search match on words first and only add close matches in meaning.
  • Keyboard. ⌘⏎ / Ctrl+⏎ runs the focused notebook cell, the same keys as inside the editor (⇧⏎ still works outside an editor). Arrow keys, Home and End move along Explorer's tab bar. Shortcut hints show Ctrl on Windows and Linux.
  • Sentence case. Menus and the command palette use sentence case: New query, New hunt, Quick actions, Recent queries. Field and column labels keep acronyms: Client IP, Event ID.
  • Tooltips open and close the same way everywhere.

Bug Fixes​

  • Activity Feed summary cards count every hunt in the window, and sample rows carry the Sample chip.
  • Notification settings no longer fail to load when a new category, such as Inbox, appears.
  • Start hunt from an inbox message creates the hunt in that message's organization.
  • Typing fast in a query editor no longer drops characters.
  • Your chosen organization is kept across a reload.