All Systems Operational

Web application Operational
Event ingestion Operational
Event storage Operational
Detection Operational
Hunting Operational
Case management Operational
Automation Operational
AI Operational
CTI Search Operational
CTI Feed (API) Operational
CTI Feed (TAXII) Operational
CTI Feed (MISP) Operational
Operational
Degraded Performance
Partial Outage
Major Outage
Maintenance
Mar 2, 2026

No incidents reported today.

Mar 1, 2026

No incidents reported.

Feb 28, 2026

No incidents reported.

Feb 27, 2026

No incidents reported.

Feb 26, 2026
Resolved - Recovery has been completed, and backlogged events have been fully processed.

We thank you for your patience during the resolution.

Feb 26, 18:45 UTC
Monitoring - The indexation service in the FRA1 region has been restored following a hardware outage at the cloud provider affecting multiple nodes in the event storage cluster. Recovery operations on affected indices have been completed. Monitoring continues to ensure stability and recovery.
Feb 26, 15:22 UTC
Identified - The indexation service in the FRA1 region is currently degraded due to multiple nodes going down in the event storage cluster caused by a hardware outage on our cloud provider. The incident started around 15:00 and prevents writing to several indices. Operations teams are performing recovery operations on the affected indices to restore service.
Feb 26, 15:09 UTC
Resolved - This incident has been resolved.
Feb 26, 10:59 UTC
Monitoring - A fix has been implemented and we are monitoring the results.
Feb 26, 10:57 UTC
Identified - The issue has been identified and a fix is being implemented.
Feb 26, 10:57 UTC
Investigating - Some API endpoints are returning 500 errors intermittently.
Our engineering team is currently investigating the issue.

We thank you for your patience during the resolution.

Feb 26, 10:40 UTC
Feb 25, 2026

No incidents reported.

Feb 24, 2026
Resolved - Event processing delays in the FRA1 region have been resolved. Normal operations have resumed and the system is stable.
Feb 24, 19:05 UTC
Identified - Event processing delays in the FRA1 region persist following yesterday's cloud provider-related incident. We've identified the issue and we're working towards improving system's stability and reducing processing lags. The situation is actively monitored and being addressed.
Feb 24, 18:17 UTC
Investigating - We are currently experiencing delays in event processing in the FRA1 region. This issue is related to an incident from yesterday, which has been resolved and was caused by the cloud provider. Our team is working to fully restore normal operations.
Feb 24, 16:20 UTC
Resolved - A few servers are still offline but FRA1 is fully functional since 23/02 at 23:00 CET. At this time we are still expecting a post-mortem from our cloud provider. This incident is now resolved.
Feb 24, 08:53 UTC
Update - All event storage cluster servers hosting long-term data are now online with indexes gradually recovering; workers responsible for data retention will be restarted shortly. Remaining event storage cluster servers are being restarted via a custom process and should rejoin shortly.
Feb 23, 17:25 UTC
Update - This incident is ongoing with around 80 servers still down. Indexation is operating with less than 10 minutes of lag on the event storage cluster. The data center provider is manually rebooting servers that failed to start correctly, prioritizing critical nodes including message bus nodes. Recovery efforts are ongoing.
Feb 23, 15:58 UTC
Update - This incident continues to impact approximately 80 servers. The event storage cluster is recovering with nodes restarting and data becoming progressively available. Indexation has resumed with some lag still present. Frontend, APIs, automation features, and detection services remain operational. The main residual issues relate to forwarding difficulties caused by four message bus nodes being down, affecting forwarding to search indexing components. Recovery of infrastructure nodes is ongoing.

We are still in contact with our cloud provider to ensure all servers come back online as soon as possible.

Feb 23, 15:06 UTC
Identified - More than a hundred servers are down due to an issue impacting network switches in one of the data centers, causing disruptions to the message bus and other infrastructure components. Our teams are actively investigating, and we are coordinating with the data center provider to determine the estimated time for recovery.
Feb 23, 14:18 UTC
Investigating - We have identified more than a hundred servers down at once on FRA1. As this is affecting nearly all clusters, we are currently looking into a cloud provider issue.

At this time we are not sure about the overall impact, as our team is looking into it.

Feb 23, 14:15 UTC
Feb 23, 2026
Feb 22, 2026

No incidents reported.

Feb 21, 2026

No incidents reported.

Feb 20, 2026

No incidents reported.

Feb 19, 2026

No incidents reported.

Feb 18, 2026

No incidents reported.

Feb 17, 2026
Resolved - Incident has been resolved at 18:05 as stated in previous update.
All remediation actions have been identified to avoid reoccurence.

Thank you for your patience during the incident.

Feb 17, 08:41 UTC
Investigating - At 17:50 one of our web-facing provider had a major incident on their load balancer product, resulting in our web UI and APIs being unavailable until 18:05. We have switched over to another provider, the web UI and APIs are now fully available.

This does not impact event ingestion in any way.
We are still monitoring the situation and opened a case with the faulty cloud provider.

Feb 16, 17:17 UTC
Feb 16, 2026