Skip to main content

Search Anywhere Framework 6.1 release

July 31, 2026
On July 31, 2026 we shipped SAF 6.1. In this article we walk through the main changes this version brings. For the full list of changes, see our documentation.

Streaming Correlator

SAF now includes a beta release of the Streaming Correlator. It processes events from your sources in real time, builds correlations, and performs active response actions with minimal latency.
A new Streaming Jobs section lets you process a data stream with three kinds of rules. A declarative rule fires when a signal occurs a set number of times within an interval. An imperative rule tracks stages and uncovers entire chains of violations. Aggregation collects metrics and checks them against your conditions.
We've also added Active Lists with auto-population and TTL-based cleanup, so you can quickly check for values even across millions of records.
New dedicated pages are available too: ingestion and processing statistics with cluster status, rule performance with a trigger log, and configuration of the sources being processed.

ML Studio

ML Studio is a Core component for managing the full lifecycle of machine-learning models. It lets you register algorithms, deploy them to compute environments, train models, and apply them to your data. Everything is managed from the SAF interface, while the computation runs on the sm-ml-service.

AI Observability

The new AI Observability module extends SAF's observability to your AI infrastructure. It brings telemetry from LLM services, GPUs, AI agents, and local AI clients into a single view of status, cost, and performance — with ready-made scenarios for operations, ML, and FinOps teams.

AI Security

AI Security equips SAF with threat detection for the AI perimeter. The module helps SOC and DevSecOps teams keep LLM services and AI agents in check: seeing detections mapped to the OWASP Top 10 for LLMs, auditing agent permissions, spotting signs of data disclosure, and investigating incidents in a single interface.

Job Scheduler

We've redesigned how run statistics are collected for the scheduler. The job list now shows run history and statuses, and you can drill into detailed stats for each active action.
There's also a new automatic run balancer with load visualization — it spreads jobs out evenly and suggests optimal schedule options.

Incident Manager

We've added SLA support. You can now configure incident-handling deadlines for different scenarios. An SLA breach can trigger scripts automatically, and stats for all SLAs are available on a dedicated dashboard.
We've also added a simplified partial-match incident search — you can now search on part of a word without the * characters.

Service Monitor Toolkit

There's a new interface for configuring maintenance windows. You can now define time intervals during which a metric won't affect your services.
We've also added an interface for managing adaptive-metric calculations: track calculation statuses and history, and start or re-run a calculation for the period you need.

Lookup Manager

We've redesigned the pages for creating a lookup and viewing its data. The data table is better than ever, with quick filtering, array support, change highlighting, column reordering, and more.

Index Management

We've added a delete action based on the total size of an index group: Delete By Max Size. It helps you keep disk usage in check — once the specified limit is exceeded, some of the oldest indices are removed.

User Behavior Analytics

We've expanded the toolset for managing profiling policies. A policy can now be canceled mid-run, and its calculation restarted if it finished with an error or a warning.
There's finer-grained control too: you can stop and restart individual algorithms, and stop, restart, or launch calculations for objects you select from the list.

If you are interested in the Search Anywhere Framework, you can contact us to discuss the details 🔥