Kentik has joined Infoblox! Read the blog post

August - 2026

Prev Next

The following updates were released to the Kentik platform during August 2026.

AI / Insights

Features

  • Runbooks Tool: AI Advisor can now create runbooks based on conversation context.
  • New AI models available for participating users: Google Gemini 3.7 was added to the models available through Kentik's AI features, and support for OpenAI's Responses API enables access to newer OpenAI models.
  • AI context for OTT Service Tracking: AI Advisor now understands the OTT Overview, Connectivity, Capacity, and Subscriber views, so it offers more relevant suggested prompts when you analyze OTT services. Also includes a tool for AI Advisor that lists all detected OTT services, categories, and providers
  • AI context for CDN Analytics: AI Advisor now understands CDN transport, offload/connectivity, OTT service, and performance data, producing more contextual suggested prompts on CDN Analytics pages.
  • Longer device command timeouts: AI Advisor device command execution now supports timeouts up to 600 seconds (previously about 30 seconds), so long-running commands such as show route complete successfully.
  • More accurate investigation summaries: AI Advisor investigation summaries now focus on actual findings rather than speculative recommendations, reducing hallucinated content in both short and detailed summaries.

Bug Fixes

  • Cause Analysis dimensions and tab behavior: Forensic Packet Analysis cause-analysis results now include the AWS packet address, interface type, service, and ENI dimensions that were previously omitted. The FPA tab also auto-selects when activated, resets on cancellation, and no longer forces you back if you switch tabs manually.
  • Cause Analysis time window: Enabling Cause Analysis with a "Local" timezone preference no longer shifts the query window into the future, which previously caused Data Explorer to hang with a "start time in the future" error.
  • Custom Network Context page access: The Custom Network Context settings page is now visible to all authenticated users.
  • Interface status filtering: AI Advisor's interface tool now correctly filters by operational status (up, down, unknown, testing, notPresent).
  • Long-running turn timeouts: Complex multi-step AI Advisor turns no longer fail when report generation exceeds the timeout, and the MCP server poll timeout now matches AI Advisor's 600-second response timeout.
  • Auto Investigation cleanup: Deleting an alerting policy now also removes its associated Auto Investigation configuration, preventing orphaned investigation settings.
  • Cancelled requests: If your client disconnects while an AI response is being generated, the request to the model provider is now cancelled instead of continuing, and incorrect error responses are no longer returned.

Alerting

Features

  • Alert chart resolution and Edit Policy shortcut: Alert charts now select an appropriate resolution automatically, and an "Edit Policy" link was added to the alert sidebar for faster access to policy settings.
  • Agent health policy warnings: Kentik now displays a banner when your organization has synthetic or universal agents but no alert policy covering agent health or agent capability health.
  • ServiceNow integration for Australia: An Australia-specific version of the ServiceNow integration package is now available, along with troubleshooting guidance for missing flow conditions and fields after import.
  • Clearer integration setup guidance: Documentation for the Jira alert-deduplication webhook now shows a concrete authorization header example, and the ServiceNow integration docs explain that all actions run under a single configured Kentik credential, recommending a dedicated least-privilege account.

Bug Fixes

  • Disabling toggle-mode policies: Toggle-mode alerting policies now correctly clear activation and clearance delays when disabled, which previously could resurrect stale rule delays.
  • Alerting page filter crashes: Fixed crashes on the Alerting page caused by non-array values passed to the application and severity filters.
  • Policy condition crash: Editing an NMS alert policy condition no longer crashes when the selected metric is null.
  • Juniper BGP session alerts: BGP session-state alerts on Juniper devices now trigger reliably when a session flaps; unstable peer indexing previously prevented them from firing. Existing alerts clear and re-key on deploy.

Cloud

Features

  • Cloud Config Status enabled for everyone: The new Cloud Config Status experience is now enabled by default for all companies, rather than being limited to selected production customers.
  • Multiple active cloud plans: The Cloud Config page and the underlying flow metrics now support multiple simultaneously active cloud plans instead of being limited to one, automatically including all relevant active plans when none is specified.
  • Simpler Azure export setup: Legacy Azure cloud exports without a stored authorization method now default to "Kentik enterprise application" instead of "app_registration".
  • AWS EFA log support: Kentik can now ingest AWS Elastic Fabric Adapter (EFA) flow logs, including MAC address enrichment, extending flow visibility to high-performance HPC networking traffic.
  • AWS flow log source identifier: AWS flow records are now enriched with the identifier of the source flow log configuration, so you can trace which log configuration produced each flow.

Bug Fixes

  • AWS account names in topology: The AWS Map now shows correct AWS account names; the full organization account list is cached and injected.
  • AWS Map "Show Path To" arrows: Animated arrow lines are restored on the AWS Map's "Show Path To" view, including for structural links that carry no traffic data.
  • AWS exporters stuck in provisioning: AWS cloud exporters now report a running/healthy status after starting, instead of appearing stuck in "provisioning" and being marked as timed out after 30 minutes.
  • AWS-to-EU flow delivery: Connectivity tuning for flow data sent from AWS regions to Kentik's EU (fra1) data center reduces retry waits and dial timeouts, cutting response latency from over 10 seconds to under one second for affected customers.
  • GCP NAT gateway display: The GCP Cloud Map no longer shows "Logs Enabled: undefined" for NAT gateways when logging configuration is not set.
  • Cloud Metadata API Status page: Filtering to non-error results now shows the complete dataset instead of an incomplete subset, and the results counter is corrected.
  • OCI timestamp option: The "Use OCI Timestamps" option in Data Explorer no longer appears unless an OCI cloud device is actually configured.

NMS

Features

  • SNMP walk discovery tool: You can now run SNMP walks against eligible devices, specify OIDs, watch progress in real time, view decoded or raw results, cancel in-progress walks, and see clear errors on failure. A MIB object browser makes selecting objects easier.
  • Bulk asset tag management: From the device inventory list, you can now bulk-assign, edit or remove asset tags across multiple devices at once, with tags grouped by name, expandable details, and a preview of additions, edits and removals before confirming.
  • Per-device asset tags: A new "Tag" tab in the device edit dialog, including for ICMP-only devices, lets you manage asset tags directly on a device.
  • Bulk device subtype update: You can now bulk-update the flow type (subtype) for multiple devices at once instead of editing each device individually.
  • Bulk device action confirmations: Bulk actions on devices now show success and failure confirmation toasts, which were previously missing.
  • Server-side device table processing: The Devices table now handles pagination, filtering, sorting and grouping on the server, improving performance for large device inventories.
  • Interface bitrate timeseries graphs: Infrastructure > Devices > Interfaces now shows interactive timeseries graphs for SNMP and Flow In/Out bitrate instead of static numbers.
  • Monitoring Templates renamed to Monitoring Profiles: "Monitoring Templates" are now "Monitoring Profiles" throughout the UI, and the "Essentials" profile was renamed "Recommended" with the description "Kentik's auto-updated baseline measurements."
  • Default units and dimensions in Data Explorer: Navigating to a measurement in Data Explorer now auto-selects sensible default units and dimensions instead of showing an empty state.
  • Metric display precision: Metric values now display with the number of decimal places defined for each metric rather than a fixed hardcoded precision, and CFM synthetic loss ratio metrics now show four decimal places instead of two.
  • ASN asdot notation: A new user preference displays BGP ASNs in asdot notation (RFC 5396), which is useful for ASNs larger than 2^16.
  • Interface Classification improvements: Reordering interface classification (ICv3) rules is now instant with immediate visual feedback, a live progress bar shows company-wide rule regeneration, and admins can manually enable or disable the new experience per company.
  • Orphaned config revision cleanup: Deleting a device configuration revision that makes another revision redundant now prompts you to remove the orphaned revision too.
  • Non-sudo metadata refresh: Users with device-update permission, not just admins, can now refresh interface metadata from the device details page.
  • New device and vendor support: Monitoring was added for Ixia iBypass 100G switches, F5 VELOS chassis, Extreme SLX-OS switches, Cisco Catalyst 1300 switches and Netscout Packet Flow Switches, with expanded monitoring depth for Infoblox, Huawei, Adva FSP3000 and VyOS.
  • Expanded SNMP MIB and trap support: MIB and trap-template support was added or expanded for Corero CMS, Tailf alarms, F5 VELOS partitions, Cisco IETF DHCP servers, Cisco Small Business (CISCOSB), Juniper VPN, Netscout Packet Flow Switches, Huawei, Citrix/NetScaler and Cisco WLC high-availability.
  • New hardware health sensors: Chassis-level hardware health monitoring — fan speed, temperature, power supply and voltage where available — was added to SNMP profiles for F5 BIG-IP, HP ProCurve/ICF, Aruba ProVision, Brocade Fibre Channel switches, Citrix NetScaler, Netgear M4300, H3C and Juniper MX/EX/QFX/SRX devices.
  • Automatic device profile matching: Kentik now downloads device-profile bundles and automatically determines which SNMP profiles, reports and data sources apply to each monitored device based on its OID, sysDescr and agent version.
  • Automatic SNMP agent configuration: SNMP polling agents now fetch their assigned device list and configuration from the backend at startup instead of requiring manual configuration, and fail fast if no valid configuration is available.
  • Device configuration backup for new platforms: Configuration backup now supports Dell Enterprise SONiC and Huawei VRP devices, including credential redaction and CLI paging handling.
  • More Layer 2 connections as clickable links: The Layer 2 connections view now shows hyperlinked connections even when only one side of the link runs LLDP, by matching the far-end device via its MAC address.
  • DNSTAP listener address option: You can now configure the address and port (default 0.0.0.0:6000) that the Universal Agent's DNS capability uses to listen for DNSTAP logs.
  • Measurement name in report metadata: The report listing API now returns the measurement name in each report's metadata, so a separate call is no longer needed.

Bug Fixes

  • Hardware, CPU and memory reporting accuracy: A large batch of Hardware tab and CPU/memory reporting defects were fixed where devices showed "Unknown" or incorrect values, spanning Cisco, Huawei, Check Point, Fortinet, Extreme, Adva and UCD-SNMP devices.
  • Check Point ASG interface speed: A dedicated metadata poller now reads interface speed from the correct SNMP table for Check Point ASG firewalls, fixing inflated capacity and utilization calculations caused by placeholder 1000 Mbps speeds.
  • Spurious interface alias change alerts: Interface alias comparisons now unescape HTML characters before comparing, eliminating false "interface changed" notifications caused by encoding differences.
  • Inflated capacity for 1-minute polled interfaces: An aggregation bug that produced inaccurate max bit rate and capacity values for interfaces polled at one-minute intervals was corrected.
  • Devices stuck in "unknown" status: A monitored device no longer remains stuck showing "unknown" status after data resumes; status now recovers within one polling interval.
  • Paginated syslog view: Device syslogs are now paginated server-side. An hour of syslogs previously returned 400,000 or more rows and could take minutes or crash the page; it now loads in about 1.4 seconds.
  • Non-standard measurement names: NMS measurements without a leading slash, such as custom or non-conventionally named metrics, are no longer filtered out of the measurement tree, and custom report queries resolve them correctly.
  • Invalid Metrics Explorer measurements: Measurements never seen by your company are now hidden from the Metrics Explorer picker instead of appearing as unusable options.
  • Metrics Explorer crash: Fixed an error in the Metrics Explorer selection dropdown that could break the page for certain selections.
  • NMS query defaults: NMS metric queries no longer fail by defaulting to an unsupported "no window function" option; a valid default is chosen automatically.
  • Bulk monitoring template selection: Bulk device selection now shows only NMS templates for NMS-only devices and flow templates for flow-enriched devices, and hides the bulk template option with an error when incompatible device types are mixed.
  • Duplicate interface group on template clone: Cloning a monitoring template with an associated interface group now creates an independent copy instead of duplicating the original group's ID.
  • Device tools permissions and error messages: Device configuration and device command access are now controlled by separate, more granular permissions, with specific permission-related error messages and configuration history links hidden from users without access.
  • SNMP device default port: SNMP devices without an explicitly configured port now default to port 161 instead of showing an undefined value.
  • ICMP-to-SNMP conversion: Converting a device from ICMP to SNMP polling now fully clears the old ICMP settings, so the device no longer still shows as ICMP-only.
  • Accidental manual interface classification: Editing an interface's settings no longer unintentionally marks it as manually classified when the classification field itself was not changed.
  • BGP tab column customization: The "customize columns" feature on the device BGP neighbors tab works again after a tab reorganization.
  • "Unknown" hardware status label: Hardware components with an unknown operational status now show an "Unknown" tag instead of a blank label in the status filter, detail panel and list table.
  • Candy necklace timezone: The metrics up/down "candy necklace" chart now displays times in your configured timezone.
  • NMS empty state alignment: The "no data" message on NMS results pages is now properly centered.
  • Array field clearing: Clearing a list or array field in device-related forms now correctly updates the displayed value.
  • Kproxy Agents site names: The Kproxy Agents view now shows the correct device site name.
  • SNMP traps dropped during template reloads: Incoming SNMP traps are no longer silently dropped with a "missing schema" error while trap templates reload.
  • SNMP trap data corruption: One SNMP trap template can no longer corrupt another's in-memory schema, which previously caused trap data to be reported against the wrong columns.
  • IXIA TradeView trap coverage: Full trap template coverage for the IXIA-TRADEVIEW-EVENT-MIB was restored after an earlier update reduced it to two trap types, preventing untriaged traps from IXIA devices.
  • Agent health during config drift: When Universal Agent control-plane reconciliation temporarily fails, agent health is now capped at "Warning" instead of escalating to a critical outage, since the agent keeps running on its last known-good configuration.
  • Agents kept in place during outages: When a monitoring agent goes offline with no replacement available, its existing assignments are demoted rather than deleted and recreated, reducing disruption when the agent recovers.
  • Agent group health status: Agent cluster group health is no longer incorrectly downgraded when there are temporarily more healthy agents than required.
  • Agent search filter persistence: The "Pending Agents for Discovery" dialog no longer inherits the search filter from the main Universal Agents page.
  • Cumulus Linux config backup: Temporarily empty configuration output from Cumulus devices, for example during a reload, is now treated as a failed fetch rather than saved as a blank revision, preserving the last good config.
  • Metrics pipeline stability: Metrics with no active alert policies or dashboards are no longer cached and forwarded needlessly, reducing memory pressure that could cause crashes in the metrics ingest pipeline.
  • Interface data lookups: Retry and timeout handling for interface-data lookups used to enrich metrics was fixed, reducing measurement drops when the interface service is slow or temporarily unavailable.
  • Silent data loss on ingest retries: Record batches that fail to send after retries are no longer silently dropped without reporting an error.
  • Opaque ingest error messages: Large error messages during data ingestion, for example from syslog records, no longer cause connection resets with opaque errors, and the maximum ingest message size was raised.
  • NMS usage queries: Queries such as /kentik/nms/usage without a device filter no longer fail because a "no device" sentinel value was misread as invalid.

Platform

Features

  • Universal Agent management APIs now public: Agent, agent-capability, config and provisioning-token management APIs for Universal Agents are now publicly available under new ua-admin read and write scopes, with improved API documentation.
  • Company-specific Data Explorer dictionary: The Data and Metrics Explorer dictionary now shows only the dimensions, metrics and data types that apply to your company, hiding unused cloud providers, synthetic test dimensions, event data, unused device subtypes and NMS measurements.
  • Cleaner filter dropdowns: Filter dropdowns no longer show "Select All" when everything is already selected, or "Clear" when nothing is selected.
  • Login page announcement: A promotional banner on the login page announces the "Transforming Network Operations with AI Advisor" webinar.

Bug Fixes

  • Login failures with special characters in passwords: Fixed a password-parsing mismatch that caused authentication failures for companies whose credentials contained characters such as %, :, + or =.
  • Widespread authentication failures: Fixed a bug causing roughly 74,000 authentication failures per day for companies whose database was missing its login role; the role and permissions are now detected and recreated automatically.
  • Web framework security fix: The Echo web framework was upgraded to fix a vulnerability allowing encoded path separators to bypass middleware and expose static files, plus a related host-header validation issue.
  • Connect-protocol API calls: Connect protocol calls (JSON or proto over HTTP POST) to gRPC-Connect backend services now route and authenticate correctly.
  • SSO role cleanup: SSO login now clears locally-assigned roles when a valid role set comes from the identity provider, and the RBAC migration skips users who already have role mappings, keeping role assignments consistent. Super admins are exempt.
  • Device config read permission after migration: Users migrated to the new RBAC system, including via the KMR and SSH Executor roles, now retain the device.config::read permission.
  • Device label permissions: Fixed a permission-key collision that incorrectly blocked normal users from updating device labels.
  • Missing country codes on maps: Dashboards and maps with traffic from certain countries no longer fail to render because the country code was missing from Kentik's allowlist; the list expanded from 246 to 329 codes.
  • Admin table scroll position: Clicking a row to open its detail panel on large admin tables no longer causes the table to jump back to the top.
  • Navigation menu flicker: Fixed flickering in the main navigation menu by hiding "Recent Views" when setup tasks are shown, preventing overflow.
  • Dashboard widget panel crash: Fixed a crash in dashboard widget panels caused by reading a property on an undefined status object.
  • Data integrity for grouping and alerting: Primary keys are now defined across all NMS measurement schemas to prevent duplicate index values, which previously could produce incorrect results when grouping by index in Metrics Explorer or Data Explorer, or in alert policies.
  • Gateway configuration snapshots: The API gateway no longer publishes incomplete configuration snapshots during startup or updates, which could cause request routing gaps.
  • Edge failover reliability: Connection-state synchronization is now separated by traffic class (BGP/Flow versus Portal), preventing stale connection state from one traffic type causing requests to be forwarded to down servers in the other.

Synthetics

Features

  • More cloud providers for global agents: Exoscale, Kamatera and Vultr are now supported as cloud providers for global synthetic monitoring agents, including new icons, filtering and region selection.
  • Simpler agent naming: Universal synthetic agents now automatically adopt the name set in the agent's configured name variable, so you no longer need to rename agents in the portal after deployment. Logs also include a normalized region field.

Bug Fixes

  • Duplicate agent IP addresses: Synthetic agents with duplicate IP addresses now return deduplicated IP lists in both the UI and the API.
  • Agent cloud region errors: Synthetic agents with a missing or undefined cloud region no longer cause display errors.
  • Agent authentication stalls: Fixed an edge case where agent authentication could stall indefinitely after an unexpected error, leaving the agent unable to report results — most often on resource-constrained systems.
  • Test error message display: The synthetics backend now displays an error message for a test result correctly instead of crashing when the underlying error data is not in the expected format.
  • Test baseline loading: Malformed latency, jitter and throughput baseline records are now safely dropped and logged rather than causing failures.
  • Synthetics query column casing: Fixed a case-mismatch in synthetic test data queries in Data Explorer that could cause queries to fail; column aliases are now correctly lowercased.

Traffic

Features

  • Structured BGP alarm evidence: BGP alarm incidents now display structured evidence — affected prefixes, vantage points, flagged ASNs, and timing and impact details — in the incident log and alarm drawer, replacing raw legacy text.
  • Expanded AI platform traffic detection: OTT detection patterns for OpenAI, Anthropic Claude and Perplexity traffic were added and refined, improving AI-platform visibility in traffic classification.
  • New and updated OTT service detection: New detection was added for Ookla speedtest servers, Google Maps, Waymo, Fullstory, Glean, Infoblox SaaS and Infoblox Threat Defense, plus new OTT services (Infold Games, Arena Breakout, Native Instruments) and regional ISP patterns (Telia/Nordfibre, WilhelmTel, Sasktel). Several services were also reclassified into more accurate categories, including Proton, Microsoft Clarity, Bytedance Pangle and Pendo.io.
  • Faster query planning for large environments: Query planning now parallelizes device metadata lookups across up to eight concurrent shards by default instead of running serially, significantly speeding up planning for tenants with large device counts.
  • Plan max-FPS history: You can now retrieve a time series of a plan's maximum flows-per-second limit over time, showing when and how capacity limits changed.
  • Higher default sampling burst allowance: The default unused sampling quota (burst carryover) was raised from 0 to 30,000 FPS, so devices without a custom sampling configuration absorb traffic bursts better.

Bug Fixes

  • RPKI validation cache: RPKI-validated prefixes are no longer incorrectly marked Invalid because of a stale validation cache when a BGP route's origin AS changes.
  • sFlow sample count accuracy: sFlow counting now stops once the declared sample count is reached, so trailing garbage bytes in UDP datagrams no longer inflate flow counts.
  • Stale CDN patterns removed: About 197 obsolete OTT detection patterns tied to the decommissioned footprint.net CDN were removed and affected streaming services remapped to current domains, restoring accurate classification.
  • GitHub OTT traffic identification: GitHub's published IP and CIDR ranges were refreshed across the web, API, git, Pages, Packages and Codespaces categories.
  • ASN naming corrections: ASN name mappings were corrected and expanded, including misspelled Kakao Enterprise entries, Transtelco renamed to "Flo Networks (Transtelco)", and Starlink/SpaceX entries.
  • BGP dimension queries: Fixed query errors when using certain BGP routing and next-hop dimensions, such as source and destination route prefix length and next-hop IP and ASN, in Data Explorer.
  • Chart rendering with many dimensions: Fixed a chart rendering and query issue in Data Explorer when the auto-merge-series option was used with a high number of dimensions.
  • Traffic Breakdown widget tabs: Tab selection in the Traffic Breakdown dashboard widget is now consistent, so the correct tab stays selected.
  • Capacity plan crash: Capacity plan Detail pages no longer crash when interface utilization data is missing.
  • Country map data: 83 missing FIPS country codes were added to the map allowlist, fixing 404 errors on certain country views in Customer Traffic Overview.
  • Market Intelligence setup tasks for subtenants: Fixed a 404 error when loading Market Intelligence (MKP) setup tasks for subtenant users.
  • Array columns on legacy query endpoints: Array-typed columns such as numeric[] and timestamp[] on the /q and /v202211/query endpoints now render as proper array values instead of raw internal data, with correct NULL handling.
  • v202608/q response format: The /v202608/q endpoint now returns the documented row-object format instead of row-array format.
  • Streaming query error codes: Certain user query errors on the streaming query path now return HTTP 400 instead of HTTP 500.
  • sum() on large counters: Queries summing large uint64 metric columns no longer fail when the total exceeds the signed 64-bit range.
  • BGP listener protocol guard: BGP listener sockets are no longer created as Multipath TCP, avoiding MD5 authentication incompatibility and spurious detections in network monitoring tools.
  • Traffic widget data for Ixia IBP100: Ixia IBP100 devices now report bit-rate metrics, so the Traffic widget is no longer empty for them.