Ask AI
VirtualMetric is now a member of the Microsoft Intelligent Security Association (MISA)

News overview

DataStream 2.0: Faster, Smarter, Built for Scale

virtualmetric datastream 2.0

June 19, 2026

This is not a regular monthly update. DataStream Version 2.0 is a milestone — the result of relentless building, learning from customers, and pushing the platform toward what enterprise-scale security operations actually demand. The core has been rebuilt, new capabilities have been added across the board, and the platform is now faster, more resilient, and more extensible than ever.

Here’s what’s new.

New features 

Director 2.0: rebuilt for performance at scale 

The Director is the heart of every DataStream deployment. It is a lightweight service that runs in your environment: collecting, processing, and routing security telemetry data locally, while being managed centrally through the DataStream platform. In version 2.0, it has been rebuilt from the ground up. 

Log collection and processing are noticeably faster. The platform sustains higher throughput under heavy loads and operates with greater resilience in demanding production environments. For teams running DataStream at scale – across hundreds of customers, high-volume log sources, or mission-critical pipelines – this is the foundation that makes everything else possible. 

Rules & Alerts: continuous visibility into system health 

DataStream now supports rule-based alerting across Directors, devices, and targets. Teams can define rules around log volume and performance metrics, and let matched rules raise alerts automatically. 

The result is continuous, end-to-end visibility into what’s happening across the platform and the ability to act on emerging issues before they affect operations. 

rules & alerts datastream

Library: define once, reuse everywhere 

The Library is a central home for lookup tables, schemas, and Grok patterns used across pipelines and targets. Define each resource once and reference it wherever it’s needed without duplicating configuration or risking inconsistency: across multiple pipelines, devices, or targets. 

For teams managing complex, high-volume environments, this removes a significant source of repetitive work. 

REST API: full programmatic access 

DataStream now exposes a REST API across the full platform, with inline API examples available on every create screen. Teams can automate provisioning and configuration, integrate DataStream into existing tooling and workflows, and reduce time spent on manual setup. 

Director Proxy and TLS 

Two additions that matter for security-conscious and network-restricted deployments: 

Director Proxy – Proxy settings now live within Director configurations, giving teams a single, consistent place to manage connectivity in environments where traffic is routed through proxies. 

Director TLS – Director-to-Agent communication can now be encrypted in transit, ensuring sensitive data stays protected end to end and making compliance requirements straightforward to satisfy. 

director tls datastream

Account Termination 

Tenant owners can now remove their tenant and all associated data entirely on their own terms. Full control over data ownership and compliance obligations without dependency on support processes.

Improvements 

New device integrations and targets

Ten new device integrations extend what DataStream can collect from:

  • SMTP — email-protocol log ingestion for mail-flow coverage 
  • TFTP — Trivial File Transfer Protocol activity capture 
  • IPFIX — standardized network flow data ingestion 
  • NetFlow — Cisco NetFlow for network traffic monitoring 
  • sFlow — sampled network traffic for high-volume environments 
  • Datagen — synthetic data generation for pipeline testing and validation 
  • File — direct ingestion from log files 
  • Datastream Stats — platform statistics and metrics collection 
  • Microsoft Graph API — Microsoft 365 and Azure AD data ingestion 
  • Google Cloud Pub/Sub — Google Cloud managed messaging as an input source 

Six new targets expand where DataStream can route data: 

  • Google Cloud Logging — Google Cloud’s managed logging service 
  • Google Cloud Pub/Sub — streaming into Google Cloud messaging 
  • Google Cloud Storage — archival to Google Cloud object storage 
  • ClickHouse — high-performance analytics database delivery 
  • HTTP — forwarding to any HTTP endpoint 
  • Syslog — output to Syslog-compatible receivers 

Content Hub: 328 ready-to-use packs 

The Content Hub now ships with 328 ready-to-use packs, up from 92 — a major expansion of out-of-the-box coverage across vendors and platforms. Each pack provides prebuilt parsing, normalization, and routing for a specific source, so onboarding a new vendor is a matter of selecting a pack rather than building a pipeline from scratch.

datastream content hub extended

More in this release

This release also includes TLS format validation at configuration time, input validation improvements across the platform, and an updated Log Stream column focused on the most recent 15-minute window. 

For the full list of changes, see the release notes.

As always, feedback from real-world deployments helps guide future development. If you would like a walkthrough of any of these features or want to share suggestions, we would be glad to hear from you.

See VirtualMetric DataStream in action

vm – header-13

Start your free trial to experience safer, smarter data routing with full visibility and control.

Start free