Docs: Release notes
Documentation / Reference

Release notes

What is in each OBSESC release, compatibility notes, and how to prepare for an upgrade.

This page lists user-facing changes in each OBSESC release. OBSESC ships as an AWS Marketplace AMI. To move to a new release, you update your CloudFormation stack to the new AMI (see Upgrades).

Before you upgrade

Contact us via the contact page before you move a node to a new release. We’ll confirm that your data and configuration are compatible with the target release and tell you about any steps the upgrade needs.

0.1.0

This is the first release of OBSESC. It’s a log retention system that runs entirely in your own AWS account and keeps every event in an S3 bucket you own.

Ingest

  • Push protocols:
    • OTLP over HTTP (protobuf) and gRPC, for logs and traces
    • Elasticsearch _bulk
    • Splunk HEC (/services/collector, /event and /raw)
    • Fluent Forward
    • Vector native
  • Optional listeners:
    • Loki push
    • GELF over UDP and TCP
    • Amazon Data Firehose HTTP endpoint
  • Optional pull sources:
    • Kinesis Data Streams
    • SQS with S3 event notifications
    • Kafka, including MSK and Confluent, with TLS and SASL
  • Traces sent over OTLP are stored as ordinary events, one per span, without sampling.
  • Events are written to durable storage on the node before they are acknowledged. The exception is optional node-side multi-line assembly, which acknowledges a partial event before it is complete. Retries that carry a stable event ID are de-duplicated.
  • host, env, namespace and tenant dimensions are extracted automatically.
  • Redaction at ingest (ingest.redaction) replaces matched values before anything is written to disk.
  • Optional multi-line assembly on the node, for HEC /raw and Fluent Forward.

Console and query

  • A web console served by every node, with sign-in through your identity provider and a role for each user.
  • Search across your services, and live tail.
  • Explore, for counts, distinct counts, percentiles and top values over your history.
  • What changed?, Seen this before? and What tends to follow?, to help you investigate an incident.
  • Unusual behaviour highlighted in the console, with links to the evidence.
  • SQL over your raw events (POST /v1/sql). A scan limit tells you how much a query could read before it runs. Results can be exported as CSV or NDJSON.
  • Your raw events are stored as open Parquet files with an Iceberg catalog, so you can also query them with Amazon Athena or another engine.

Alerting

  • Your own alert rules, evaluated every few minutes, for thresholds and for services that go quiet.
  • Destinations are webhook, Slack, PagerDuty, Opsgenie, Amazon SNS and email. Secrets are given only as references.
  • Silences and alert history.
  • Indicator-of-compromise watchlists, and service digests.
  • Built-in alert rules on every node that tell you when the deployment needs attention, delivered to your Alertmanager.

Governance and security

  • Retention can be set globally or per service, with an optional compliance floor.
  • Legal holds, and S3 Object Lock in governance or compliance mode.
  • Erasure of matching events, run as a plan step and then a confirm step. Erasure must be enabled beforehand; contact us via the contact page to enable it.
  • Optional custody verification, off by default, so you can check that the history OBSESC stores hasn’t been altered. It doesn’t cover raw events in S3; use Object Lock for those.
  • A query audit trail records who read what. By default it stores a hash of the query text rather than the text itself.
  • Role-based access control:
    • built-in viewer, operator and admin roles, plus custom roles
    • token-based access, and per-user sign-in through Application Load Balancer OIDC
  • TLS on every TCP listener, with certificate reload from disk. GELF over UDP is not encrypted.
  • SSE-KMS encryption with your own KMS key, and a pinned expected bucket owner.

Operations

  • CloudFormation deployment. Options include:
    • an optional internal load balancer for the console, with sign-in through your identity provider
    • a bucket created by the stack with lifecycle tiering
    • cross-account and cross-Region buckets
    • daily EBS snapshots
  • Multi-node deployments are available with our help. Contact us via the contact page.

Scope notes

  • OTLP metrics are not ingested. Logs and traces are.
  • OTLP over HTTP accepts protobuf only, not JSON.
  • Splunk is supported through HEC. There is no Splunk forwarder (S2S) receiver.
  • There is no native syslog listener. Send syslog through rsyslog’s Elasticsearch output, or through a shipper such as Vector.