Ask AI
VirtualMetric is now a member of the Microsoft Intelligent Security Association (MISA)

News overview

Safer Pipeline Changes, Flexible Deployment, and More 

datastream product update v2.1.0

August 5, 2026 

The latest VirtualMetric DataStream release focuses on how pipeline changes move from idea to deployment, safely and without slowing teams down. Version 2.1 puts a deliberate step between building a pipeline and shipping it to production, along with new deployment options for Directors and multi-tenant ingestion for teams managing data across many customers. 

Here’s what’s new. 

New features 

Pipeline Editor 

Working on pipeline logic has traditionally meant moving between multiple screens to build, check, and troubleshoot. That changes with this release. 

Pipelines can now be built, reviewed, and debugged entirely from a single page. Configuration logic, validation, and debugging tools all live in one view, so teams no longer lose context switching between screens while working through a pipeline. This makes configuration faster and reduces the errors that tend to creep in during that back-and-forth. 

pipeline-editor-debugging

Pipeline Source Control 

Until now, pipeline changes deployed directly to Directors as soon as they were saved. That direct path is fast, but it also means a mistake reaches production immediately. 

Pipeline Source Control adds a lightweight review workflow between editing and deployment. Changes now require review and approval before they go live, giving teams a checkpoint to catch problems before they affect running pipelines. For teams where a broken pipeline means lost or misrouted security data, that checkpoint matters.

commits

Director Serverless Mode 

The Director is the component that collects, processes, and routes telemetry in your environment. Before, it ran on traditional operating systems such as Windows and Linux — a limitation for teams that have already moved their infrastructure to containers and cloud platforms. 

Directors can now be deployed to Kubernetes, Docker, Azure Container Instances, and Azure Container Apps. Rather than running Directors as a separate, traditionally-hosted component, teams can deploy them the same way they deploy everything else in a container-native or cloud environment. 

director-mode-cards

Director Processing Mode

Different environments have different needs when it comes to balancing speed against durability. This release gives Directors configurable storage behavior to match. 

Directors now support three storage modes: in-memory, for maximum performance where data loss on failure is an acceptable trade-off; crash-resistant, for a middle ground; and fully persistent, for environments where data durability takes priority. Teams can choose the mode that fits their specific requirements rather than accepting a single default behavior. 

Source-Based Monitoring Rule Creation 

Alerting now goes a level deeper. Syslog, TCP, UDP, and HTTP devices support source-based monitoring rule creation, so teams can define separate rules for different sources behind the same device, giving alerting far more granular control over when and how alerts are triggered. 

rule-log-sources

Improvements 

Multi-tenant ingestion 

Elastic, Splunk, OTLP, HTTP, Syslog, UDP, and TCP devices now support multi-tenant ingestion, so a single device can separate and collect data belonging to multiple tenants rather than requiring a dedicated configuration per customer. For MSSPs and teams onboarding customers at scale, this removes a layer of repetitive setup. 

New device integrations and targets

This release adds two new device integrations: 

  • OTLP — telemetry ingestion from OpenTelemetry Protocol sources 
  • SNMP Trap — capturing SNMP trap notifications from network equipment 

Ten new targets expand where DataStream can route data: 

  • NATS and MQTT — lightweight and IoT messaging environments 
  • Snowflake and Databricks — via S3 or Azure Blob staging, for analytics and data warehousing 
  • IBM Cloud Logs, IBM Event Streams, and IBM QRadar — for IBM environments 
  • CrowdStrike — endpoint security workflow integration 

These are the highlights – the full release also includes Managed Identity support for Microsoft Graph API and Sentinel devices, a decoder field for Windows and Linux File Datasets, multi-Director Live Data collection, expanded audit log coverage, and a broad set of stability and usability fixes. 

Looking ahead

This release strengthens the foundation for teams operating at scale: safer pipeline changes, more deployment flexibility, and cleaner multi-tenant operations. In upcoming releases, we’ll continue building on that foundation. 

For the full list of changes, see the release notes

As always, feedback from real-world deployments helps guide future development. If you would like a walkthrough of any of these features or want to share suggestions, we would be glad to hear from you

See VirtualMetric DataStream in action

vm – header-13

Start your free trial to experience safer, smarter data routing with full visibility and control.

Start free