Release Notes SevOne NMS 8.0.0
Below please find the Release Notes for SevOne NMS 8.0.0 (Release Date: July 24, 2025). Please contact your Technical Account Manager (if applicable) or Systems Engineering Team or Support Team to discuss and plan the installation. Thank you for being a customer.
Browser Requirements
Minimum Resolution: 1200x768 Browsers:
- Modern, standards-compliant browser
- JavaScript enabled
- Pop-up blocker disabled for hostname/IP
The following browsers are supported in the current versions of SevOne. SevOne recommends use of the latest version of your preferred (supported) browser.
| Vendor | Family | SevOne NMS 8.0 |
|---|---|---|
| Chrome (latest) | Tested, Supported, & Recommended | |
| Mozilla | Firefox (latest) | Tested & Supported |
| Microsoft | Edge (latest) | Supported (with limited testing performed) |
| Apple | Safari (latest) | Supported |
Tested = Complete UI regression testing completed prior to release of updates.
Supported = Developer-led testing and resolution of any customer reported defects. No complete UI regression test is performed.
Version Compatibility
SevOne Data Insight and SevOne NMS are compatible when they are within + / - 1 major version of each other. However, for the best experience and to ensure full feature availability and optimal performance, we strongly recommend keeping both Data Insight and NMS on the same version. When the versions do not match, some features may be limited or may not function as expected.
Containers
As of SevOne NMS 7.0.0, SevOne is distributed using container technology, allowing a more confident deployment of the software. To run administrative commands on a SevOne appliance, the administrator must now execute commands in the context of the intended container.
By default, the container deployment of SevOne is set to be read-only.
- The host and the container each has its own ssh config; both for the server and the client.
- To ssh as root, you must use the sudo command.
For additional details, please refer to SevOne NMS System Administration Guide and / or SevOne NMS User Guide.
Other Notices
/opt/patches is a reserved directory; please refrain from making any modifications.
During the initial deployment, when you execute SevOne-fix-ssh-keys, it produces /root/.ssh/authorized_keys file which contains your cluster's public keys.
If you have custom keys, the keys must be added to /root/.ssh/custom_keys.pub file.
- if /root/.ssh/custom_keys.pub file does not exist, using a text editor of your choice, add the new custom key(s) to it.
- if /root/.ssh/custom_keys.pub file already exists, concatenate the new custom key(s) after the existing custom keys in the file.
To persist the custom keys added in /root/.ssh/custom_keys.pub file, run SevOne-fix-ssh-keys script for the keys in /root/.ssh/custom_keys.pub file to be automatically added in /root/.ssh/authorized_keys file. The /root/.ssh/authorized_keys file will now contain your cluster's public keys along with a set of custom keys stored locally in /root/.ssh/custom_keys.pub file.
Retains 'all' keys - cluster's public keys & custom keys
SevOne-fix-ssh-keys
Third-Party Packages / Resources Required
The following are third-party packages updated to address security.
| Package | Version | |
|---|---|---|
|
General |
Kafka | For SevOne Data Bus 8.0.0,
Upstream package used for Kafka, provided by RedHat: OpenJDK v21.0.7 |
| Kernel |
4.18.0-553.60.1.el8_10.x86_64 NOTE: The kernel will automatically get installed as part of the upgrade and will be loaded after the reboot of the appliance. |
|
| MySQL | 10.6.22-MariaDB | |
| nginx | 1.24.0 | |
| PHP |
8.3.23 NOTE: To consume PHP 8, please contact Expert Labs if assistance is needed. |
|
| REST API | 2.1.47 | |
| xStats Adapter | 2.1.11 | |
| Signature Tools |
Note: The latest files can be downloaded from IBM Passport Advantage (https://www.ibm.com/software/passportadvantage/pao_download_software.html) via Passport Advantage Online. However, if you are on a legacy / flexible SevOne contract and do not have access to IBM Passport Advantage but have an active Support contract, please contact SevOne Support Team for the file.
Once you have downloaded the package, unpack the fix / upgrade packs to obtain the required files.
|
|
| Artifacts |
Note: For new installs / upgrades / downgrades,
the latest TAR and CHECKSUM files can be downloaded from IBM Passport Advantage (https://www.ibm.com/software/passportadvantage/pao_download_software.html) via Passport Advantage Online. However, if you are on a legacy / flexible SevOne contract and do not have access to IBM Passport Advantage but have an active Support contract, please contact SevOne Support Team for the file. Once you have downloaded the package, unpack the fix / upgrade packs to obtain the required files.
|
|
| Fabric | Azure | Windows 2008 (modified) |
| Hypervisor | OpenStack | >= 10.a |
| VMware |
|
Planning & Preparation
- Prior to applying the patch, system creates a backup of the files and puts them into an archived file to be reverted.
-
Total Upgrade Time and Polling Outage: On a cluster consisting of 20 x (PAS 200Ks, DNCs, HSAs), upgrade takes approximately 58 minutes. The polling outage on this cluster ranged from 2 minutes to 5 minutes. Polling outages can be slightly higher when a MySQL restart is required and it does not include the time it takes for the reboot of a new kernel. Depending on the cluster and load per appliance, times will vary. The total Netflow outage for this cluster ranged from 10 minutes to 15 minutes. Netflow outage can be up to 2 hours since the Netflow shortterm tables which hold 2 hours of data, do not get backed up when MySQL is restarted.
Important: When a new flow interface is setup with a DNC at capacity, the system collects all existing allowed flows and denies any new flows. - The number of peers in a cluster must not exceed 200 peers; this includes the HSAs. This limit is due to MySQL replication maintainer.
-
On large deployments, Object Groups may take 15 minutes to update.
Forward / Reverse Migrations
Please refer to SevOne NMS Upgrade Process Guide published with this release for details on forward / reverse (upgrade / downgrade) migrations. The latest tarball files can be downloaded from IBM Passport Advantage via Passport Advantage Online. However, if you are on a legacy / flexible SevOne contract and do not have access to IBM Passport Advantage but have an active Support contract, please contact SevOne Support Team for the forward / reverse migration files.
Once you have downloaded the package, unpack the fix / upgrade packs to obtain the required files.
Useful Guides
From IBM's Documentation Portal (https://www.ibm.com/docs/en/sevone-npm), please refer to NMS guides for this release for details.
Deprecated Components / Fields
- S1NPM-115178
The following components have been deprecated for SevOne NMS 8.0.0 and above for a fresh install. If you have upgraded from SevOne NMS 7.2.x and below to SevOne NMS 8.0.0 and above, it will be available, and its content will remain intact.
- Create Report
- Report Manager
- Instant Graphs
- Status Map Manager
- Forced Login
- Cluster Manager > Cluster Settings > FTP
- Cluster Manager > Cluster Settings > SFTP
The following fields have been deprecated SevOne NMS 8.0.0 and above for a fresh install. If you have upgraded from SevOne NMS 7.2.x and below to SevOne NMS 8.0.0 and above, these fields will be available, and the settings will be intact.- Cluster Manager > Cluster Settings > Email > fields Reports Email Subject, Compress Emailed Reports, Compress Reports Larger Than, and Image Quality.
- Cluster Manager > Cluster Settings > General > field Reports Restricted By Default.
- Cluster Manager > Cluster Settings > Graphs > all fields except Display Units in TopN CSV have been deprecated.
Detach button / icon have been deprecated for SevOne NMS 8.0.0 and above for a fresh install. If you have upgraded from SevOne NMS 7.2.x and below to SevOne NMS 8.0.0 and above, the button / icon will be available.- Alerts
- Alert Archives
- Alert Summary
- Device Manager
- Device Summary
- FlowFalcon Reports
- TopN Report Interactions
When you click on the graph in Object Summary or click on the graph / table in Report Interactions, the attachments do not launch in a new browser tab; this feature has been deprecated for SevOne NMS 8.0.0 and above for a fresh install. If you have upgraded from SevOne NMS 7.2.x and below to SevOne NMS 8.0.0 and above, this feature will be available, and its content will remain intact.
- APIs - Statement of Direction (NPM 8.0)
New Features & Enhancements
- Vendor, Prisma Palo Alto, has been added to IBM SevOne’s SD-WAN solution; support for this has been added in SevOne NMS' SDWAN Plugin.
- S1NPM-114392: Cloud AWS: PrivateLink support added so that all communication between NMS and AWS remains entirely within the AWS infrastructure in an air-gapped environment.
- S1NPM-116059: Google Cloud Platform (GCP)
- Added support for new devices, GCP Kubernetes Engine and GCP Load Balancer.
- Added GCP Interconnect MACsec metrics.
- TopN Views are now automatically installed.
- Support for Tag collection added.
- upgrade from SevOne NMS version below SevOne NMS 6.1 to SevOne NMS 6.7
- then, upgrade from SevOne NMS 6.7 to SevOne NMS 6.8 or SevOne NMS 7.0.1+
- now, from SevOne NMS 7.0.1+ you can upgrade to 8.0.
Resolved Issues
| Component/s | Key | Resolved Issues |
|---|---|---|
| Platform Operations | S1NPM-77802 | Policy Import / Export: SevOne-import and SevOne-export functionalities can manage multiple Webhook Definitions optimally during import/export operations across diverse configurations. For instance, if a policy, encompassing numerous webhook definitions, is initially exported, and subsequently, one or more of these webhook definitions are deleted, a subsequent import operation completes successfully. |
| Platform | S1NPM-79915 | SNMP: When SNMPv3 credentials are updated, polld cache is updated without a restart. |
| Platform | S1NPM-95554 | Platform: PHP SMTP mailer sends the hostname for the EHLO message but, it defaults to localhost.localdomain. This can result in the Alert Mailer not working under some SMTP server configurations.
Use a specific name when connecting to mail servers or set the system to autodetect the FQDN of the system sending the mail and use that as the host name. Run the following query on the Cluster Master.
By default the setting will be localhost.localdomain to match existing behavior. If the setting is set to an empty value, the OS hostname will be used instead.
|
| NMS | S1NPM-110968 | Device Manager: When SNMP devices are imported in bulk using a .csv file or bulk imported via the API, the load of the devices no longer targets only the least load peer. The new distribution method distributes the devices more evenly based on their current load so that the new devices are less likely to push any peer over capacity once they are fully discovered. |
| NMS | S1NPM-112542 | Platform: To ensure that dex and samplicator restart after a reboot, you must execute the following commands from NMS host.
|
| Grouping + Metadata | S1NPM-113240 | Platform: Can now add devices to Device Groups successfully. |
| NMS | S1NPM-113761 | Platform: Devices where only the ICMP Availability object is created, either by intent or by inability to discover objects from other plugins, will automatically be labeled as Managed Client Devices so that customers are charged at a lower licensing rate for basic availability monitoring. |
| NMS | S1NPM-113959 |
SDP: Support for SASL / OAUTHBEARER authentication added. Please refer to FAQ How to set up Kafka using SASL OAUTHBEARER authentication? for details. NOTE: The steps in this FAQ apply only when you are running SDP on Microsoft Azure and authenticating with an OAUTHBEARER token. |
| NMS | S1NPM-114248 | Platform: The NMS pod health check now correctly reports the health of the nms-nms-nms pod when HTTPS is required and HTTP on port 80 is disabled. |
| NMS | S1NPM-114545 | SevOne-trapd can now process traps with high CPU load. |
| NMS | S1NPM-114631 | Discovery: SNMP discovery completes successfully and devices in the cluster are discovered as expected. |
| NMS | S1NPM-114698 | Platform: Even when memory was unused, MariaDB was allocating too much virtual memory resulting in health check errors. This issue has been resolved. |
| NMS | S1NPM-114715 | Platform: When a device is moved, only the new mappings exist; old mappings get deleted. |
| NMS | S1NPM-114769 | Platform: Global Search - Advanced Search feature has been removed. |
| NMS | S1NPM-114892 | REST API: The /api/v3/alerts{id} endpoint now supports retrieval of archived alerts. |
| NMS | S1NPM-115123 | Platform: The self-monitoring object for metering metrics has been updated to track devices that are ICMP only - it will track devices where there is only one object and that object is ICMP Availability. This indicator can track devices that are either being monitored as up / down or devices where other plugins are configured but not working. |
| NMS | S1NPM-115306 | Platform: TopN requests for flow are now processing as expected. |
| NMS | S1NPM-115327 | Platform: A new self-monitoring indicator has been added to track devices that only have objects that are associated with Group Poller. Group Poller license type is applied to devices that only have objects from the Group Poller plugins. |
| NMS | S1NPM-115328 | Platform: Every SevOne Device will be automatically assigned a Device:LicenceType metadata attribute of Managed Device if a value is not already present. This metadata will be used for metadata-based querying and to ensure accurate tracking of device license type for product metering metrics. |
| NMS | S1NPM-115332 | Platform: Encryption 3DES is not supported as this method is no longer allowed by NIST. |
| NMS | S1NPM-115393 |
REST API: The following endpoints added for Support > MustGather.
|
| NMS | S1NPM-115411 |
REST API: Endpoint POST /api/v3/auth/client/token added to fetch tokens for the following static clients.
|
| NMS | S1NPM-115497 | Platform: Topology with BGP allows 1-to-many relationships. |
| NMS | S1NPM-115566 | Platform: Topology graph displays the interface details correctly in the topology report. |
| NMS | S1NPM-115615 | REST API: Endpoints related to objects, object groups, topology, permissions, and roles work without any permissions issue. |
| NMS | S1NPM-115748 | Webhook Definition Manager: $closureMessage variable added to the CP4AIOPS Webhook template to improve its usability as an integration. |
| NMS | S1NPM-115768 | Platform: When object group rules are applied against one particular group, it now applies towards that group instead of applying it to many groups. |
| NMS | S1NPM-116022 |
Platform: For certificates that are expiring, the following rules are followed.
|
| NMS | S1NPM-116390 | Platform: If custom logo is set, the login page displays the custom logo. |
| NMS | S1NPM-116946 |
Flows: To prevent unintended flow matches, user must avoid configuring overlapping App Profiles. The more fields defined, the higher the precedence. The hierarchy is as follows: IP + PORT > IP only > PORT only By aligning the configuration's hierarchy, accurate and predictable flow classification can be ensured. |
29 issues
CVEs / CWEs
| CVEs | CVEs (continued) | CVEs (continued) |
|---|---|---|
|
|
|
Known Issues
This section lists issues that SevOne is aware of in the 8.0.0 release. Most of these issues were discovered during quality assurance testing and are published here to provide you with information that may be relevant when you plan your update. This list does not include feature requests or low impact issues that do not affect functionality. If you have questions, comments, or concerns, please contact us.
- If you have a scenario where adding HSA has failed during the masterslave console, format slave step, you may execute the following steps as a workaround.
- Using a text editor of your choice, edit /config/cron.d/mode file.
- Search for the line containing discover-netflow.
- Comment this line by adding a # at the start of this line.
- Save /config/cron.d/mode file.
- Add the HSA.
- Using a text editor of your choice, edit /config/cron.d/mode file again.
- Search for the line containing discover-netflow.
- Uncomment this line by removing the # that is at the start of this line.
- Save /config/cron.d/mode file.
- REST API docs are unavailable when the domain name has an underscore. For example, http://sevone_test1/api/docs/ or http://sevone_test1.sevone.com/api/docs/.
| Component/s | Key | Known Issues |
|---|---|---|
| Platform Operations | S1NPM-77927 | Platform: SevOne import/export does not work with the AWS plugin device. |
| Platform | S1NPM-110201 | SevOne Data Publisher: When configuring the kerberos config krb5.conf file, SDP will not work if variable dns_canonicalize_hostname is set. |
| Platform | S1NPM-110549 | xStats: In SevOne NMS 7.0 and above, the configuration of the xStats adapters based on ADK is not migrated properly after the upgrade from a prior release.
Workaround: The following steps must be executed manually post-upgrade.
|
| Platform | S1NPM-112463 | Platform: Peering does not properly distribute ssh keys in Hub-and-Spoke setup.
NMS supports a Hub-and-Spoke setup, where some peers cannot reach each other across the network, as long as the cluster master / cluster leader is fully reachable by all peers. The objective is to make a best-effort attempt to support functions that do not strictly require connectivity to other peers. One case where this standard is not reached is during peering. If a new peer is being added to the cluster which lacks connectivity to just one other peer (not even the cluster master / cluster leader) then, while peering will succeed, the distribution of ssh keys will fail, and no keys will be distributed.
This prevents ssh communication even between peers that are connected across the network, including the cluster master / cluster leader. Running SevOne-fix-ssh-keys manually from the new peer also fails.
The reason is simply that the operation bails entirely if keys are failed to be obtained from even a single peer. Workaround: Run SevOne-fix-ssh-keys manually on the Cluster Master / Cluster Leader after peering. |
| NMS | S1NPM-113539 | xStats: If you have upgraded your SevOne NMS from version 6.x to 7.x, you must set the following variables from Command Line Interface before running /opt/sevone-xstats/GenericCSVTransform/bin/console.php script.
|
| NMS | S1NPM-113572 | WiFi Plugin: By default, Wi-Fi plugin poll frequency is set to 5 minutes. If it is changed to let's say 3 minutes, it will poll at every 3 minutes, as expected. However, if you refresh New Device / Edit Device page, the user interface will show Wi-Fi plugin poll frequency is set to 5 minutes (its default value) again. Internally, it will continue to poll at every 3 minutes but the user interface is not reflecting the correct value set for field Wi-Fi plugin poll frequency. |
| SDN | S1NPM-116751 | SDN: Certain metadata fields are not populated as they are not provided in ACI API responses for virtual machines, hypervisors, nodes, and external switch. |
| WiFi | S1NPM-116893 | WiFi: During WLC polling, the WLC Collector encounters an HTTP 400 (Bad Request) response from endpoint /api/v3/devices/bulkUpdate, which may result in incomplete device updates. |
| SDN | S1NPM-116910 | SDN: Device Type name does not get updated post-upgrade. |
| WiFi | S1NPM-116928 | WiFi: In SevOne NMS versions 8.0.0 through 8.0.6, after integrating Wireless LAN Controllers (WLCs) with a large number of Access Points, WiFi collector polling on the NMS peer may become interrupted or stop unexpectedly, impacting data collection.
Workaround: From the SevOne NMS command line interface, restart the WiFi collector container.
Note: This issue is resolved in SevOne NMS version 8.0.7 and later.
|
| WiFi | S1NPM-118130 |
Platform: After upgrading SevOne NMS, the following fields are missing from the cluster leader. However, the fields contain the values in its peer(s). Actual behavior:
Expected behavior:
|
| WiFi | S1NPM-118130 | Platform: When upgrading SevOne NMS from 7.0.1 or 7.1.0 to 8.0.0, the following fields are missing in /config/collectors/wifi/configuration/advanced_config.env file.
Observed behavior post-upgrade
Expected behavior
Note: By default, DEL_OBJECTS must be set to True. However, if the value is False, please contact IBM Support Team.
|
12 issues