Reporter for WatchGuard Release Notes
Reporter for WatchGuard 1.0.2.92 (2025-09-12)
Encrypted Syslog

You can now create and download a self-signed certificate when enabling Encrypted Syslog, in addition to supplying your own certificate.

Features
  • Drag-and-drop ordering: Columns in the Alert Evidence table, as well as Sources, Alerts, Scheduled Reports and Saved Filters, can now be re-ordered with drag-and-drop.
  • User Statistics: Added a table showing the detected users and devices each day in Settings > Licensing > User Statistics.
  • Drilldowns: When drilling down into reports, the new report opens in a new tab, making it easy to navigate back.
  • Queue statistics: Added a processing queue statistics display to Settings > Diagnostic > Resource Usage.
Improvements
  • Safeguarding Report: Websites listed in the Unacceptable Web Categories sections are now sorted by Hits, and videos in the Keyword Group sections are now sorted by Browsing Time.
  • Internet Usage Report: The Searches and Videos widgets now show the time the search was performed and the time the video was watched. Searches are now ordered by time, and videos are sorted by Browsing Time.
  • Productivity Dashboard: Now shows Blocked Hits instead of Size, and shows the Site Domain of the website instead of the Origin Domain (Cleaned), to avoid confusion with background resources.
  • VPN Report: The VPN Report option is now available in the ‘new report’ popover when hovering over items in Private Reports.
  • Elasticsearch stability: Improved the stability of connections to Elasticsearch.
  • Import queue limit: Added an import queue limit to prevent running out of memory if import falls behind (default limit: 800,000 records). If the limit is reached, new records are discarded until the queue drops below the limit.
  • Import performance: Improved the performance of importing data into Elasticsearch, especially when importing large batches of records.
  • Data Retention: Data Retention settings limits and defaults are now based on remote Elasticsearch cluster storage.
  • Query performance: Improved performance for queries with large numbers of columns.
  • rFlow: Updated the rFlow instrument to show the average rate of incoming records.
Fixes
  • Report errors: Fixed an issue where reports could fail due to the Elasticsearch date_histogram.fixedinterval format.
  • Entra ID: Entra ID Directory Sources can now be edited and updated with new secret keys or client IDs successfully.
  • Private Reports: The report progress bar no longer shows “Undefined” when running new reports in a Private Report window.
  • VPN durations: Fixed an issue with VPN durations being calculated incorrectly when only a VPN ‘End’ event is within the report timeframe.

Reporter for WatchGuard 1.0.2.91 (2025-07-01)
Security Update

Updated the Apache Groovy package included with Elasticsearch to resolve CVE-2016-6814 (affecting Groovy versions 1.7.0 to 2.4.7), which could allow execution of arbitrary code via crafted serialized objects. Existing installations using Elasticsearch 5.6 will be automatically updated. Fresh installs now use OpenSearch by default, which is not affected.

Fixes
  • Productivity Reports: All Productivity Reports and Charts no longer show an “Uncertain” or “Other” group relating to non-web traffic.
  • Failed VPN Logins: Improved the parsing of failed VPN login events, as some were not populating the new Failed VPN Logins reports.

Reporter for WatchGuard 1.0.2.90 (2025-06-03)
Encrypted Syslog

Sources can now be configured with a certificate to secure syslog transmission.

Features
  • Reverse proxies: Fastvue Reporter now respects the X-Forwarded-Prefix header sent by reverse proxies, allowing it to be served from a sub-path (e.g. mydomain.com/fastvue).
  • ARM support: The Windows installation now supports ARM-based hardware.
  • Search terms: Searches on soundcloud.com are now supported.
  • Source hosts: Fastvue Reporter now uses DHCP log events to populate the Source Host field with the hostname and MAC address (e.g. iPhone (b6:54:6e:5f:d3:70)). If no username is recorded with the traffic, the Source Host is shown as the ‘User’ instead. If no Source Host is known, the IP address is shown as the ‘User’.
Fixes & Improvements
  • Browsing Time: Fixed a Browsing Time calculation issue where values were limited to set increments (e.g. 2:11, 4:22, etc).
  • Performance: Fixed performance issues introduced in 1.0.2.87.
  • OpenSearch: Fixed an issue where, upon rebooting the Fastvue Reporter server, OpenSearch would be extracted into existing Elasticsearch databases, preventing the database from connecting.
  • Search terms: The literal + character is no longer removed from Google searches (e.g. searching for 100+42 was displayed as 100 42).

Reporter for WatchGuard 1.0.2.89 (2025-05-12)
Features
  • Safeguarding Report: Added a ‘Time’ column indicating the time of a search, the time a video was watched, or the time an unacceptable website was visited or blocked. The Time column shows the first time the activity was seen for that search, video or website during the reporting period.
  • VPN Report: Added a new VPN report (Reports > Overview Report > VPN tab), containing similar information to the VPN section within the IT Network and Security Report, now available as its own report.
  • YouTube Videos: YouTube videos embedded in other websites are now shown in the YouTube Videos reports.
  • Search terms: Improved search term extraction for Reddit.com.
Fixes
  • Missing data: Fixed an issue where reports on dates older than the previous three days could come back blank or with missing data, due to the report finishing before the database indexes containing that data were opened.
  • IP address filters: Fixed an issue introduced in 1.0.2.87 where filtering by an IP address using the ‘Contains’, ‘Starts With’ or ‘Ends With’ operators resulted in a report error.

Reporter for WatchGuard 1.0.2.88 (2025-04-16)
Listen for Syslog from Any Host

Sources can now be configured to listen for syslog data from any host. Each source shows a list of the devices sending syslog data on the configured port, and each device is considered a ‘Source’ for licensing. If you are licensed for one source and your firewall is an HA pair with two devices acting as a single firewall, Fastvue will increase your licence to two sources free of charge. Contact [email protected] to arrange this.

Fixes
  • VPN usernames: Extra domains are now stripped from the username field in VPN log events.

Reporter for WatchGuard 1.0.1.86 (2025-02-25)
WatchGuard VPN Support
  • Introduced a new VPN Dashboard and a VPN section in the IT Network and Security Report. Easily see when most people connect and disconnect, and proactively respond to unexpected disconnections or excessive invalid login attempts.

For more information, see our article: Introducing WatchGuard VPN Reports and VPN Dashboard: The Secret to Comprehensive VPN Management

Improvements and Fixes
  • Microsoft 365 Email OAuth: Added support for the “Request Admin Consent” flow.
  • Internet Usage Reports: All “Top N” widgets at the start of the Internet Usage Report are now filtered by web data, ensuring consistency with the rest of the report.
  • All Connections Busy Error: Fixed a rare issue that could trigger an “All Connections Busy” error.

Reporter for WatchGuard 1.0.1.84 (2024-12-13)
Features
  • Email Settings: Added OAuth support for connecting to Microsoft 365 and Google Workspace in addition to SMTP.
  • Load current filter: The filter used in the currently open report is now loaded when you open the Filters interface, making it easy to quickly adjust filters and re-run your report.
Fastvue Reporter Email Settings with Microsoft 365 & Google Workspace OAuth
Fixes & Improvements
  • Search Terms: Corrected Ebay search term extraction logic & adjusted exclude keywords.
  • Directory Import: New installations will import users and groups from the default Domain Controller if present.
  • WatchGuard: Improved log import speed and fixed import errors.

Reporter for WatchGuard 1.0.2.87 (2025-03-06)
OpenSearch Support

Added compatibility with OpenSearch, as well as Elasticsearch 7 and 8, for the backend database. New installations will use OpenSearch as the backend database instead of Elasticsearch. Existing installations will continue to use their existing Elasticsearch database.

Improvements
  • Private Reports: Running new reports from within Private Reports now shows the progress bar and loading dialog while the report is generating.

Reporter for WatchGuard 1.0.1.85 (2025-01-22)
Fixes & Improvements
  • Memory Usage: Reduced the number of open Elasticsearch indexes from 32 to 3, improving baseline memory usage. Reports on data older than three days may take a few extra seconds to start as indexes are reopened, temporarily increasing server memory usage. Inactive indexes automatically close after five minutes, freeing up memory.
  • Report Errors: Increased the default Elasticsearch timeout from 5 to 20 minutes to handle larger reports, and resolved an error that references a missing scrollId.
  • OAuth Email: Fixed a problem where emails would stop sending when using Microsoft 365 OAuth.
  • Entra ID: Now imports more than just the first 100 groups or users per group.
  • Activity Reports: Can now be exported as PDF or CSV directly from Private Reports.

Reporter for WatchGuard 1.0.1.83 (2024-10-08)

Fixes & Improvements
  • Search Terms: Corrected search term extraction logic for Amazon.
  • Entra ID: Fixed Entra ID data importing issues.
  • WatchGuard: WatchGuard may log extra domains in the username field such as user@domain@domain, or user@domain@radius. Fastvue Reporter now strips the additional domain, importing it as user@domain.