> For the complete documentation index, see [llms.txt](https://docs.onum.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.onum.com/data-sinks-changelog/falcon-next-gen-siem-data-sink.md).

# Falcon Next-Gen SIEM Data Sink

Learn more about this Data Sink type in [this article](/data-sinks/data-sink-integrations/send-data-to-falcon-next-gen-siem.md).

<details>

<summary>v4.0.0</summary>

<mark style="background-color:purple;">**Released on**</mark> <mark style="background-color:purple;"></mark><mark style="background-color:purple;">06/16/2026</mark>

* New **Enable retry attempts** section to define rules that dictate how the system will automatically re-run failed operations.
* The **Event time limit** field unit in the **Bulk configuration** settings is now milliseconds.
* The **Message** field in the Pipeline configuration allows literal and default values now.
* Fields now preserve their original types instead of being converted to text.
* Fixed authentication token handling when token includes a prefix.
* Improved error response consistency.

</details>

<details>

<summary>v3.0.2</summary>

<mark style="background-color:purple;">**Released on**</mark> <mark style="background-color:purple;"></mark><mark style="background-color:purple;">04/21/2026</mark>

* Fixed race condition causing panics on GZIP compression.

</details>

<details>

<summary>v3.0.1</summary>

<mark style="background-color:purple;">**Released on**</mark> <mark style="background-color:purple;"></mark><mark style="background-color:purple;">12/18/2025</mark>

* Fixed an issue with byte count in bulk mode.

</details>

<details>

<summary>v3.0.0</summary>

<mark style="background-color:purple;">**Released on**</mark> <mark style="background-color:purple;"></mark><mark style="background-color:purple;">11/24/2025</mark>

* **Port** option has been removed form config.

</details>

<details>

<summary>v2.0.1</summary>

<mark style="background-color:purple;">**Released on**</mark> <mark style="background-color:purple;"></mark><mark style="background-color:purple;">10/22/2025</mark>

* Gzip compression is now always used.

</details>

<details>

<summary>v2.0.0</summary>

<mark style="background-color:purple;">**Released on**</mark> <mark style="background-color:purple;"></mark><mark style="background-color:purple;">10/09/2025</mark>

* Added 443 as default port
* Added support for fields in json format
* Changed raw Content-Type to text/plain
* Removed "Splunk " token prefix and added "Bearer " if not present
* Removed Splunk specific parameters (channel, host, index, source, sourcetype)

</details>

<details>

<summary>v1.0.2</summary>

<mark style="background-color:purple;">**Released on**</mark> <mark style="background-color:purple;"></mark><mark style="background-color:purple;">09/10/2025</mark>

Initial version

</details>
