Loading full navigation.

Release Note

2026-September 24 Edwin AI Release Notes (v.15.2)

Feature Highlights

  • Event Intelligence Dashboard Enhancements
  • Delimited Key-Value String Field Mapping Transformation
  • Elasticsearch Log Queries in Edwin AI

Edwin AI Platform

Enhancement

Event Intelligence Dashboard Enhancements

The Event Intelligence dashboard in Edwin AI Dashboards has been reconfigured to highlight critical information.

To access this feature, navigate to Edwin AI > Dashboards. Select the Event Intelligence dashboard from the table.

Enhancement

Delimited Key-Value String Field Mapping Transformation

Edwin now provides additional field mapping transformations for normalizing event data received from third-party integrations. These transformations enhance flexibility when mapping vendor-specific fields and enrichment data to Edwin events, reducing the need for integration-specific ingestion logic.

The following field mapping transformations are now supported:

  • Delimited Key-Value String (DELIMITED_KV_STRING)—Parses delimited key-value strings, such as tags or labels, and maps the resulting values to event enrichments.
  • Copy (COPY)—Copies a value from one field to another, enabling vendor-specific fields to be mapped to the corresponding Edwin field. The source field can optionally be removed after the value is copied.
  • String Transform (STRING_TRANSFORM)—Normalizes string values during field mapping. Supported operations include trimming whitespace, converting values to uppercase or lowercase, and replacing literal string values.
  • Key Alias (KEY_ALIAS)—Renames multiple enrichment keys using a configurable mapping, making it easier to standardize vendor-specific enrichment names to a consistent schema.
  • Transformations can be configured per integration through the existing fieldMappings configuration and applied in sequence, enabling multiple transformations to be combined when normalizing incoming events.

The existing JSON_ARRAY, VALUE, and DATETIME field mapping types continue to be supported.

Enhancement

Elasticsearch Log Queries in Edwin AI

You can now query Elasticsearch logs through the Elastic MCP server using the conversational agent or automatically during AI Investigations.

In AI Investigations, relevant Elastic log findings are surfaced in the AI Log Summary section.

For more information, see Edwin AI Investigation in product documentation.

Resolved Issue

Resolved an issue where SES email actions in Edwin AI sent repeated verification emails to identities with verification already pending. Email identities pending verification no longer receive additional verification emails when this action executes.

Resolved Issue

Resolved an issue where connectivity tests in ServiceNow developer instances failed to authenticate. Connectivity tests now ensure integration tests explicitly target and execute against the provided integration record.

Resolved Issue

Resolved an issue where a deleted integration continued to appear in Edwin AI integration settings. Deleted integrations are now removed from the page without requiring a refresh.