Reporter for Cisco Firepower Release Notes
Reporter for Cisco Firepower 4.5.0.1 (2026-08-27)

This build renumbers Fastvue Reporter to 4.5 and unifies versioning across all Fastvue Reporter brands. Alongside the version change, it brings a refreshed user interface, a significant round of Microsoft 365 email and messaging work, and major improvements to how large reports are processed.

Unified Version Numbering

Fastvue Reporter now uses a unified 4.5.x.x version scheme across every Fastvue Reporter brand (Reporter for Barracuda, Cisco, ContentKeeper, Fortinet, Palo Alto Networks, SonicWall, Sophos, WatchGuard, and even the old Microsoft TMG – yes, some folks still use it!). Previously each brand carried its own major version, but as all Fastvue Reporter products share the same underlying codebase, it made sense to synchronise them on the new 4.5 convention. From this release onwards all brands share the same version number, and 4.5 reflects the scale of recent work including the Microsoft 365 email and messaging integration, the interface rework, and report generation optimisations.

Interface Refresh

Fastvue Reporter has received a minor user interface glow-up. Every icon in Fastvue Reporter has been replaced with modern vector icons, and buttons and colours have been brought into line across the whole product. The result is a cleaner, more consistent interface with improved interactions.

Large Reports
  • Long date ranges: Reports covering long date ranges are now processed in smaller chunks rather than all at once, so reports spanning multiple months, and even years, complete successfully on datasets that would previously run out of memory partway through.
  • Report size warnings: If a report is too large to complete on your server, Fastvue Reporter now tells you straight away and suggests shortening the date range or allocating more memory, instead of running for a long time and then failing.
  • Browsing Time: Optimised the Browsing Time calculation, which could cause excessive memory usage when running very large reports.
Dashboard and Reports
  • Dashboard drilldowns: You can now choose which report to drill down into from the Dashboard. Previously, drilling down from a Dashboard widget always launched the All Usage Report. You can now select the report you actually want, with the widget’s context carried through as filters, just like you’ve always been able to do from within Reports.
  • Markdown export: Reports can now be exported to Markdown, in addition to PDF and CSV.
  • Safeguarding Report: The email card sometimes displayed the wrong ‘From’ address. If the username portion of an external email address matched the username portion of an internal email address, the internal email address would be shown as the ‘From’ address in the email card, while the correct address appeared when viewing the full email. The card now shows the correct sender.
  • PDF exports: Fixed formatting issues in the YouTube video card when exported to PDF.
Message Context Dialog

The Message Context dialog, which displays the content of an email, chat conversation, YouTube video or web browsing session from the Safeguarding Report, has received multiple improvements.

  • Export: The content of the Message Context dialog can be exported directly to PDF, Markdown, or CSV (for Sites/URLs).
  • Images: Images attached to or embedded in emails and messages now display correctly when viewing the full message context.
  • Draft and deleted emails: When viewing an email, the email header section now indicates if the email is a draft or has been deleted.
  • Full context: Fixed an issue that could prevent the full context of an email or chat message from being retrieved.
  • View Sites: In the ‘View Sites’ context dialog, the times shown were incorrectly offset by the local timezone. They now display correctly.
  • Keyword highlighting: The Message Context dialog now highlights the matched keyword correctly.
Microsoft 365 Email and Messaging
  • Import speed: Importing email and chat messages from Microsoft 365 is now substantially faster.
  • Import statistics: Corrected the ‘Processed’ message import statistic to indicate the number of messages examined rather than the number of mailboxes and users checked.
  • Whole-word matching: When importing emails, formatting was being stripped in a way that joined words together across line breaks, so whole-word keyword matches could be missed and keyword highlighting in the Message Context dialog was also affected. These issues have been resolved.
  • Alert and report emails: Fastvue Reporter’s own alert and report emails are now reliably excluded from Microsoft 365 email imports.
  • Filters: Message Sender was listed twice in the filter options.
Alerts
  • Keyword groups: Alerts configured against custom keyword groups now trigger correctly.
  • Browsing Time: Browsing Time is available again as an alert criterion, which also re-enables the alert threshold options that depend on it.
Stability and Security
  • Log4j: Log4j has been updated to 2.26.1, addressing CVE-2026-49844.
  • Database maintenance: Routine database maintenance could run out of memory on very large data stores. This has been resolved.
Licensing

Fastvue Reporter now allows you to add up to twice your licensed source count. Firewalls deployed as HA pairs send logs from two hosts, which previously counted as two sources against your licence and could put you over your limit. The additional headroom means HA pairs no longer require a licence upgrade.

Other Fixes
  • Directory sources: A Default Domain Controller directory source is now only created on first run, rather than being recreated on every startup after being deleted.
  • Demo data: Demo data was generating packet counts orders of magnitude too high across all brands.
Download Update
Reporter for Cisco Firepower 1.0.3.111 (2026-07-20)
Fixes & Improvements
  • Safeguarding Report: Fixed an issue where the ‘View Email’ or ‘View Conversation’ features may return a ‘Null Response’ error while a Microsoft 365 import is in progress.
  • PDF exports: Resolved an issue where Browsing Time in exported PDF reports may show negative values.

Reporter for Cisco Firepower 1.0.3.110 (2026-07-03)
Microsoft 365
  • Organisational structure: Microsoft 365 organisational structure (users, groups, teams, and channels) is now background-synced from your tenant on a periodic schedule, rather than being fetched from the Microsoft Graph API each time the filters UI is opened. This eliminates the delay or timeout error that could occur when opening or editing the Microsoft 365 filters interface.
  • Scheduled report emails: Fastvue Reporter now also ignores its own scheduled report emails during Microsoft 365 email imports, in addition to alert emails. This prevents keyword matches inside report emails from triggering new alerts.
  • Entra ID sync: Reduced the number of API calls made for Entra ID directory sync, improving import speed.
Fixes
  • Index updates: When upgrading from version 1.0.1.86 or earlier, Fastvue Reporter updates older indexes to bake in keyword match data. This task was causing memory usage issues on some instances and could get stuck updating a single index. This has been resolved.
Known Issues
  • The ‘View Email’ or ‘View Conversation’ features in the Safeguarding Report may return a ‘Null Response’ error while a Microsoft 365 import is in progress. Fixed in 1.0.3.111.

Reporter for Cisco Firepower 1.0.3.109 (2026-06-29)
Fixes & Improvements
  • Safeguarding Report: The new Safeguarding Report now renders correctly when viewed in Private Report mode.
  • AI Risk Assessment: Simplified the message returned by the ‘Test Connection’ option in AI Risk Assessment > Fastvue AI.

Reporter for Cisco Firepower 1.0.3.108 (2026-06-21)

Build 108 is a significant feature release covering Safeguarding Report improvements, AI-powered Risk Assessment, and a settings reorganisation.

Redesigned Safeguarding Report

The Safeguarding Report has been completely redesigned with the goal of easily identifying students or people at risk, and making online incidents simple to understand and act on.

Incidents are now grouped by user, and users are ranked by risk. Incidents are displayed in easy to read cards using ‘human’ language, with options to bring in the full context when needed, such as the full email, chat conversation, video, or URLs.

Interactive elements show or hide incidents by category (e.g. Self Harm, Extremism), risk level (Mild, Moderate, Serious or Severe), or activity type (Search, Video, Email, Chat, Web).

AI Risk Assessment

Fastvue Reporter can now use AI to clear false positives and surface real concerns. Incidents are scored as No Risk, Mild, Moderate, Serious or Severe, with understandable reasons provided. The new Safeguarding Report natively integrates these risk levels, ranking users by overall risk, and provides sorting and filtering of incidents by risk level.

The AI Risk Assessment feature adds five new fields:

  • Safeguarding Concern: True/False
  • Safeguarding Risk Level: No Risk, Mild, Moderate, Serious, Severe, or Unscored (for old/existing data)
  • Safeguarding Confidence: 1 to 10 (how confident the AI model is in its assessment of the Risk Level)
  • Safeguarding Reason: A short description of why the AI model chose the Risk Level
  • Safeguarding Categories: self-harm, suicide, violence, sexual-content, bullying, drugs, radicalisation, exploitation, eating-disorder, mental-health, other

Filter your Alerts by Safeguarding Concern ‘Equal to’ True for a simple way to remove false positives from keyword-matched incidents.

Email and Messaging

The Microsoft 365 integration has moved to Email and Messaging in Settings and is available as a separately licensed feature.

Settings Reorganisation

The Settings sidebar has been reorganised into logical groups to keep the navigation manageable as Fastvue Reporter has grown. A few pages have also been renamed to make their purpose clearer.

Known Issues
  • The new Safeguarding Report does not render in Private Report mode. Fixed in 1.0.3.109.

Reporter for Cisco Firepower 1.0.3.107 (2026-06-18)
Import Historical Logs

The ‘Import historical logs’ option is now available for all Fastvue Reporter brands (previously it was only available on selected brands). When Fastvue Reporter has been offline, this feature can be used to backfill gaps in log data from a running Fastvue Syslog instance.

Fixes & Improvements
  • Safeguarding Report: Fixed an issue introduced in 1.0.3.106 where videos were no longer displayed in the Safeguarding Report.
  • Elasticsearch: Fixed an issue introduced in 1.0.3.106 where Elasticsearch indexes could get stuck in a ‘semi-recovered’ state on startup with unassigned shards, requiring manual intervention.
  • Memory usage: Queries that include Browsing Time now use less memory, reducing the memory usage of most Fastvue reports.
  • PDF exports: Fixed emoji rendering issues in PDF exports.
  • Microsoft 365: Improved the filtering interface for including and excluding Groups, Users, Teams and Channels.
  • Settings backup: Improved and extended the automated settings backup process.

Reporter for Cisco Firepower 1.0.3.106 (2026-06-08)
Fixes & Improvements
  • Scheduled Reports: Fixed an issue introduced in 1.0.3.105 that could cause the Reporter service to crash while generating many scheduled reports.
  • Security update: Updated Log4j to 2.25.4 to address CVE-2025-68161 (Apache Log4j Core: missing TLS hostname verification in the Socket appender).
  • Printing: The sidebar is no longer included when printing a report or a private report directly from the browser.
Microsoft 365
  • Filtering interface: A range of refinements to the Microsoft 365 filtering interface in Settings > Microsoft 365. Filter options are now shown immediately instead of a blocking ‘loading’ panel, and section headings clearly indicate that User and Group filters only apply to Emails and Chat messages, not Teams and Channels.
  • Subject line matches: Fixed an issue where emails with a keyword match in the Subject line were not appearing in the Safeguarding Report.
  • Keyword Groups: Fixed an issue where the same email or chat message could be attributed to the wrong Keyword Group when the Subject matched one group and the Message Body matched another. Both matches are now reflected correctly in the Safeguarding Report.
  • Import size: When only the Subject (Email or Channel Subject) matches a keyword, the imported Message Body is now correctly limited to 250 characters, reducing unnecessary import size and storage.
  • Keyword highlighting: Fixed issues with keyword highlighting in the full message context view for Microsoft 365 messages and emails.
  • Group filters: Fixed an ‘Invalid Object Identifier’ error that could occur when filtering Microsoft 365 imports by multiple Groups.
  • Import errors: Fixed errors that could occur during Microsoft 365 import, specifically ‘An item with the same key has already been added’ when gathering users for a tenant, and ‘has to be unique in a batch’ when importing emails.
Known Issues
  • Videos do not display in the Safeguarding Report. Fixed in 1.0.3.107.
  • On some Linux instances, Elasticsearch indexes can get stuck in a ‘semi-recovered’ state on startup with unassigned shards, requiring manual intervention. Fixed in 1.0.3.107.

Reporter for Cisco Firepower 1.0.3.105 (2026-05-28)
Microsoft 365
  • Source filtering: Microsoft 365 imports now support filtering by source. You can choose exactly which user chats, user emails, Teams, and channels are imported, rather than importing everything from the tenant.
  • Keyword highlighting: When viewing the full context around a flagged message, matched keywords are now highlighted in the surrounding messages, not just in the message that triggered the alert.
  • Next import indicator: A ‘Next import in…’ indicator has been added to the Microsoft 365 UI, showing when the next scheduled import will run. This avoids confusion when an expected alert hasn’t yet appeared because the next import is still pending.
  • Chat Messages widget: Reworked so that sender and recipient appear in a single column, consistent with the Email widget layout.
  • Duplicate messages: Fixed an issue where chat messages could appear duplicated in the Safeguarding Report after a reaction or reply triggered a re-import.
  • Multiple recipients: Fixed an issue where chat messages sent to more than one person displayed as ‘System.String[]’ in the Chat Messages widget instead of the list of recipients.
  • Draft emails: Fixed an issue where emails drafted and later sent would continue to show as ‘Email – Draft’ in reports rather than updating to ‘Email – Sent’.
  • Message ordering: Fixed message ordering in the full message context view, so edits and emoji reactions no longer cause messages to appear out of sequence. Messages now display in the same order as in Microsoft Teams.
  • Stopping imports: Fixed errors that occurred when stopping a Microsoft 365 import mid-run. The ‘Import Now’ button is also now disabled until the import engine is ready, preventing errors from clicking it during startup.
  • Gateway errors: Improved handling of transient gateway errors (HTTP 502) during Microsoft 365 user chat and email imports. Affected entries are now retried on the next import instead of being skipped.
  • PDF exports: Fixed display issues with the Chat Messages widget and keyword highlight positioning when reports are exported to PDF.
Features & Improvements
  • Restore Factory Defaults: A ‘Restore Factory Defaults’ option has been added under Settings > Productivity, allowing you to reset the productivity configuration back to defaults.
  • Emojis in PDF exports: Emojis now render correctly in PDF exports of Safeguarding Reports. Previously, emojis appeared as an unknown-character box.
  • Partially Failed reports: A new ‘Partially Failed’ report status has been added, indicating when a report completed but with some missing data. Previously these reports would appear as either successful or fully failed, with no clear way to tell the difference.
  • Keyword Group scoping: Keyword groups can now be scoped to apply only to specific data types (semantics), giving you finer control over where each group is matched. The ‘Rename Keyword Group’ UI has been replaced with an ‘Edit Keyword Group’ dialog that includes the list of applicable semantics.
  • Keyword matching: Keyword matching against large blocks of text (such as newsletters containing multiple unrelated articles) has been improved. An exclusion triggered by one section no longer suppresses legitimate matches elsewhere in the same text.
  • Keyword lookups: Keyword lookups are faster and more reliable, particularly for large keyword sets.
  • Elasticsearch: Startup and recovery handling has been improved, resulting in more reliable service restarts after timeouts or unresponsive states.
Fixes
  • Scheduled report emails: Fixed an issue where scheduled report emails could silently fail to send even though the report itself completed successfully. Queued emails will now correctly attempt to resend.
  • Empty attachments: Fixed an issue where queued or retried emails were sending zero-byte (empty) attachments instead of the intended PDF report.
  • Email retries: Email retries are now capped at a maximum number of attempts, so failing emails can no longer remain stuck in the queue indefinitely.
  • Queued emails: Queued emails now store their attachments on disk in a temporary file rather than in memory, reducing memory pressure when many large PDF reports are queued.
  • Sharing reports: Fixed an ‘Index and length must refer to a location within the string’ error that occurred when sharing a Safeguarding Report via email with the ‘Attach PDF’ option enabled.
  • Report errors: Fixed invalid XmlNodeType errors that occurred when opening certain reports.
  • Filtering: Filtering by User Login Name is no longer case-sensitive.
  • Report files: Report files are now written out as soon as each report is generated, reducing the risk of data loss if the Fastvue service is interrupted partway through a scheduled run.
Known Issues
  • Microsoft 365: For emails with a subject line that contains a keyword match, the full email body is imported, not just the first 250 characters. Fixed in 1.0.3.106.
  • Microsoft 365: Emails with keyword matches in the Email Subject are not displayed in the Safeguarding Report. Only emails with keyword matches in the body of the email are displayed. Fixed in 1.0.3.106.

Reporter for Cisco Firepower 1.0.3.104 (2026-03-19)
Microsoft 365
  • View full message: Safeguarding Reports now include a button in the Email and Chat Message widgets to view the full message content in context. For emails, this opens the complete email including subject, sender, recipients, and full body. For chat messages, this shows a thread view with the surrounding messages to help understand the context of a keyword match.
  • Grouped emails: Emails in the Safeguarding Report are now grouped so a single email involving multiple users appears as one row, rather than separate rows for each mailbox. Sender and recipient avatars are shown visually, with an option to expand and view all participants.
  • Email classification: Microsoft 365 email imports now classify emails as ‘Email – Sent’, ‘Email – Received’, or ‘Email – Draft’ based on the role of the monitored mailbox. All keyword-matched emails from monitored mailboxes are imported regardless of whether the monitored user is the sender or a recipient.
  • User and Message Sender fields: For Microsoft 365 email imports, the ‘User’ field is now populated by the owner of the monitored mailbox, rather than the email sender address. A new ‘Message Sender’ field captures the sender’s details. This allows reports and alerts to be filtered by security groups such as ‘Students’ or ‘Staff’, with the results including emails sent, received, or in draft.
  • Import speed: Microsoft 365 Teams and email imports are now significantly faster. API requests are batched and processed in parallel, reducing the time required to scan larger tenants.
  • Widget columns: The Safeguarding Report widget columns have been reorganised for better readability and consistency. In the Chat Messages widget, the message column now appears first, with time at the end. The Email widget columns are similarly reordered. The ‘Hits’ column has been removed from the Searches widget.
  • Alert emails: The Microsoft 365 email import now identifies and ignores Fastvue Reporter’s own alert emails during import, preventing repeated alerts from being sent.
  • Keyword highlighting: Fixed an issue where keyword highlight positions could be calculated incorrectly for some Microsoft 365 emails.
  • Disabled sources: Fixed an issue where a Microsoft 365 source that had been disabled in Settings would still be included in imports.
  • Draft emails: Fixed an issue where draft emails in Microsoft 365 were incorrectly labelled as ‘Email – Sent’ in reports and alerts. Draft emails are now correctly labelled as ‘Email – Draft’, and the message context dialog clearly indicates when an email is a draft.
Fixes & Improvements
  • Drilldown links: Fixed an issue where drilldown links in reports would navigate to an incorrect URL if the Site URL in Settings > Site Settings did not begin with ‘http://’ or ‘https://’. Fastvue now validates and corrects this automatically, and a validation error is shown in Settings if the URL format is invalid.
Known Issues
  • Duplicate chat messages: You may see duplicated chat messages in the Safeguarding Report. When Fastvue imports keyword-matched chat messages and someone then reacts or replies to one of those messages, the next import from Microsoft 365 (1 hour after the last import finished) re-imports that message, as its ‘last modified’ time has increased. Fixed in 1.0.3.105.
  • Multiple recipients: When a chat message is sent to more than one person, the Chat Messages table in the Safeguarding Report shows ‘System.String[]’ instead of the list of recipients. Fixed in 1.0.3.105.

Reporter for Cisco Firepower 1.0.3.103 (2026-02-25)
Fixes & Improvements
  • Video drilldowns: Fixed the known issue introduced in 1.0.3.100 where drilling down into a keyword-highlighted video title would display HTML characters in the report title instead of the plain video title, and the report would return no data.
  • Duplicate emails: Fixed an issue where Microsoft 365 emails were being imported multiple times, causing duplicate entries to appear in alerts and reports.
  • Large messages: Fixed an issue where Microsoft 365 Teams messages or emails with very large message bodies could cause an indexing error and fail to import.
  • Scheduled report filters: Fixed an issue where filters using the ‘In Keyword Group’ operator were not displayed correctly when editing scheduled reports. The filter would show as ‘Equal to’ with an internal ID code rather than the keyword group name.
  • PDF exports: The ‘d’ (days) unit was missing from Browsing Time values in PDF exports. PDF exports now match the formatting shown in the web interface.