What's New
While release notes provide a comprehensive view of our release updates, here is a preview of our most exciting features in ExtraHop 25.2.
New versioning format
Beginning with this release, ExtraHop is updating firmware version numbers to Year.Quarter.Maintenance.Revision (for example, 25.2.0.1687), where Year is a two-digit representation of the year and Quarter is a single-digit representation of the quarter that the firmware is released.
Detection Optimization Guide
A new in-product guide is now available to help you optimize detections by defining your environment, refining which detections you display, and distributing results for action or analysis. Access the guide at any time from the system settings menu.

Detection Log
You can now interact with the Detection Log in detection details to create tuning rules or view packets and records for individual log entries. You can also click IP addresses, usernames, device names, and properties in log entries to view additional information.

Notifications for Smart Investigations
You can now create a notification for recommended investigations, which sends an email when recommended investigations, also known as Smart Investigations, are created.

Enhanced Users page
The Users page now displays the number of detections in which the user was a participant and when the user was last observed on the network. In addition, you can now click a user row to view user properties in a side panel without leaving the table. The side panel also includes links that filter devices or detections by username.

Enhanced Devices page
From the Devices page, you can now click a device row to view and edit device properties in a side panel without leaving the table. The side panel can also include investigative links that navigate to pages for IP lookups, detections, activity maps, and records.

New Dashboard Home page
You can now display a new dashboards Home page that enables you to scan a list of the dashboards in each collection that you own or that were shared with you.

Packetstore lookback metrics on the System Health dashboard
You can now view packetstore metrics on the System Health dashboard if a packetstore is connected to the selected sensor. New charts have been added that display metrics about the estimated lookback, throughput, packet activity, and interface frames and drops.

Enhanced CrowdStrike Falcon integration (RevealX 360 only)
You can enable a new option for the CrowdStrike Falcon integration that imports and displays device properties from CrowdStrike Falcon. When viewing a CrowdStrike Falcon device in the ExtraHop system, certain CrowdStrike properties such as the last user, hostname, local and external IP addresses, and containment status are displayed in the device details. These CrowdStrike properties are also available as filters when searching for devices.

For Administrators
- Webhook payload metrics on the System Usage dashboard
- Administrators can now view metrics about webhook payloads sent to a target
based on a detection notification rule. New charts have been added to the
System Usage dashboard
that display the number of webhook payloads sent, payloads that failed, and
the event types associated with payloads.
Thank you for your feedback. Can we contact you to ask follow up questions?