Version 13.1
- Last Updated: September 16, 2026
- 11 minute read
- Flowmon Products
- Flowmon Anomaly Detection System
- Documentation
Introduction
We are excited to announce the features and enhancements implemented in version 13.1 of Flowmon ADS. This release:
- AI event summary to generate contextual reports and explanations of detected events
- Event detail PDF export to easily export and share the Event Detail
- Assisted configuration of filters to help you keep ADS configuration up-to-date
- ADS filters can be used in the Monitoring Center > Analysis to accelerate your investigations
- IDS configuration in the ADS UI to easily configure and tune detection on one or more Flowmon IDS Probes
- Event triggered investigations to automatically start root-cause analysis
- Configuration Wizard visual overhaul to improve on-boarding experience
- Other quality-of-life improvements and new customizations
Flowmon ADS 13.1.0 release date: 16th September 2026
Let us know your feedback
Customers helped to choose and validate some of the features that went into this release. We want to hear from you to continue to improve Flowmon ADS. You can request to join and participate in pre-release activities on the Flowmon Customer Validation Program (CVP) and vote on and submit your product ideas on our ideas portal. Thank you for helping to make Flowmon ADS better!
What's New in Flowmon ADS 13.1?
AI Event Summary
Flowmon ADS 13.1 introduces AI Event Summary, a new interpretive layer that turns raw, technical event data into a clear, human-readable narrative directly in Event Detail. Instead of manually correlating flows, related events, and external intelligence, you can now generate a summary on demand with a dedicated action button in Event Detail, explaining what happened, why it matters, and what to do next. Once generated, the summary is stored with the event and remains available for later review.
The summary fuses local event context — Event Evidence (flow data), event attributes, and related events — with optional global threat intelligence, such as external IP reputation, geolocation, and other data, to produce a richer, risk-aware explanation. Event data originating in ADS is sent to the Threat Hub server, where it is enriched with global threat intelligence that supplements the existing ADS information, and further enriched using an internal knowledge base to help explain the event more clearly and provide additional context. It is generated in the language currently selected in the UI, and IP addresses and Event IDs mentioned in the text are clickable, linking directly to the relevant analysis or event detail. Individual sections can also be copied to the clipboard using a dedicated copy icon. The summary can also be exported together with other Event information using the new Export to PDF option.
The number of AI summaries you can generate depends on your support tier and is currently set to:
- 1 per week with no support,
- 10 per week with Standard Support,
- 100 per week with Extended Support.
The limit resets weekly on Sunday. These limits may change in the future.
This limit currently applies per ADS instance and cannot be split or allocated between individual users or tenants.
Sensitive data can be pseudonymized before being sent for processing. Your local IP addresses are automatically pseudonymized. Your public IP addresses and domain names can be pseudonymized as well. Pseudonymization behavior can be configured by ADS Administrators in Settings > System Settings > Threat Hub where you can select IP filter and domain names that will be pseudonymized. By default, the filter is set to "LAN", which in general should contain your public addresses as well (if not, add them to the "LAN" filter in Settings > Processing > Filters). Domain names must be entered manually and may contain '*' wildcards. For more information, refer to the User Guide.
This feature requires Flowmon ADS to have access to the Flowmon services portal and leverages a managed LLM service, operated within an isolated environment contracted and controlled by Progress. For more information about how customer data is protected and processed, refer to the User Guide.
This feature is enabled by default, but requires your appliance to have internet access and External services to be enabled in Settings > System Settings > General Settings.
Event Detail PDF Export
This version makes it easy to share event findings outside the application by letting you export the Event Detail view directly to PDF. The generated document includes the top summary section, the full content of the selected tabs (Info and Attributes), and the first twenty event targets. If an AI Event Summary has been generated for the event, it is included in the export as well, making it simple to hand over a clear, professional report to colleagues or management without needing access to ADS itself.
Assisted Filter Configuration
Keeping ADS filters up to date requires manual review of false positives and periodic fine-tuning. With Assisted Filter Configuration, ADS now analyzes detection events and automatically suggests updates to your atomic filters based on recurring Event Source IPs. This feature will help ADS Administrators improve the configuration when important IP addresses are omitted during the initial Configuration Wizard setup and help keep the configuration up to date during standard operation (for example, when a new DNS server on the network causes a lot of detections because the "DNS" filter was not updated).
This feature currently suggests filter optimizations only for atomic filters, based on detections for a limited set of supported methods. Only Event Source IPs are considered in this version.
You can review the suggested optimizations in the Settings > Optimizations > IP Filters page (ADS Admin role required). On the Pending tab, you can approve or decline the optimizations. To facilitate the optimization investigation, check the "Reasoning" or "show related events" action in the context menu. You may also open the Monitoring Center and analyze the IP communications (flows). Notes you add to optimizations are visible in the Processed tab and will also appear as IP comments inside the filter if the optimization is approved. Declined optimizations will not be suggested in the future.
Always thoroughly review the suggestions before accepting them as it will affect further detection (for example, "are these really false positives caused by legitimate DNS server that was not added to suggested filter?").
This feature is enabled by default, but requires that you have used Configuration Wizard in the past to create and assign filters to detection methods (done automatically during Configuration Wizard walkthrough). Moreover, a minimal number of events per Event Source IP must be exceeded to create a suggestion. The value can be configured in Settings > Optimizations > Scanning. The Analysis Summary will notify you if there are any pending filter optimizations unless the corresponding Summary section is disabled in Settings > System Settings > General settings.
ADS Filters in the Analysis of the Monitoring Center
ADS filters can now be reused directly in the Analysis module of the Monitoring Center (FMC), behaving like native FMC filters in selection and usage. This removes the need to recreate the same logical network topology twice and lets you apply consistent filtering when querying statistics or flow data.
ADS filters can only be used in the Monitoring Center > Analysis. They cannot be used, for example, in Profiles, Alerts, or Chapters.
IDS Configuration UI
Flowmon ADS now brings direct management of Flowmon IDS Probes and their rules right into the ADS user interface, so you no longer need SSH or command-line access to perform basic detection tuning. The new IDS Configuration section in ADS settings lets you create, edit, and delete configurations, assign individual IDS probes to them, and manage the full set of rules and classifications directly from your browser.
You can disable individual signatures using their name or numeric Signature ID, making it much easier to quickly tune the IDS detection. You can also add your own detection rules and classifications. Each probe can be assigned to only one configuration at a time, and the interface actively prevents conflicts where the same probe would end up assigned to more than one configuration.
Any change to a configuration – whether an addition, edit, or removal – is automatically pushed to the assigned probes as an updated configuration, so probes always operate with the latest settings without any manual intervention. Removing a probe from a configuration, deleting the probe, or deleting the whole configuration also clears the corresponding settings on that probe.
Exporting and importing ADS configurations now includes the IDS probe settings as well, so moving a configuration between environments carries over the complete IDS setup, and after import it is automatically reapplied to the relevant probes.
IDS Configuration is currently available only to the base tenant administrator. This feature requires Flowmon IDS Probe 13.1.0 or higher.
Moreover, filters for IDS Probes in Configuration Center > Monitoring Ports were extended. You can now also use other filter categories, such as ports, protocols, MPLS labels, and MAC addresses, as well as the operators not, and, and or. These improvements allow you to define the exact network traffic to be processed by the IDS. For more information about filters, see the Flowmon User Guide.
Event Triggered Investigations
Flowmon ADS can now automatically launch a multi-step investigation the moment it detects a security event, instead of requiring analysts to manually switch to Monitoring Center and piece together the flow analysis themselves. You can assign a specific playbook to a detection method, and whenever that method fires an event, ADS automatically hands off the relevant event context, such as the Event Source IP, Event Targets, and other Event Attributes, to trigger the investigation.
Triggered investigations can be configured in the Dashboard and Reports module on the Investigations page. You can either use an available Playbook or Automation trigger, or create your own. The Investigation tab then provides a list of triggered investigations based on your settings. After you click a finished investigation, you can view the results in the Monitoring Center > Analysis for each step of the investigation.
To learn more about how to create Playbooks and Automations see Flowmon 13.1 release notes or Flowmon User Guide.
Flowmon will provide example playbooks and automation triggers with the Flowmon ADS 13.1 Stable.
Configuration Wizard visual overhaul
The Configuration Wizard was redesigned to make initial setup faster and more intuitive. The welcome screen has also been refreshed to match the new look. Throughout the wizard, step descriptions have been rewritten to more clearly explain what each input affects, including which filters and detection methods it impacts. The filter input now also supports the format IP,comment; to allow you to insert notes and comments for the IP addresses shown later in the Filters.
Other Changes
- More options are available for customizing Syslog messages. You can select and order the optional Common Event Format (CEF) fields to include in the syslog message. Moreover, the tenant name was added to the CEF fields.
- Direct links to Flowmon Packet Investigator were added to the Traffic Recording tab. Clicking on the recording ID will open the filtered Packet Investigator page allowing you to smoothly transition from one module to another.
- A new option shows third-party data in detected events. A REST API endpoint and CLI command for adding a comment to an ADS event are now available. For example, you can run a script on event detection that automatically fetches data from a third-party system, such as the community score from VirusTotal, and adds it directly to the BLACKLIST event comments. For more details, refer to the User Guide and Flowmon REST API documentation.
Event tables can be customized to display comments containing the retrieved information directly in the event tables.
-
Added copy to clipboard option for the hostnames shown in the Attached Flows and Event Evidence flow tables.
Improved HIGHTRANSF (High Volume of Transferred Data) events query to the collector in order to show more relevant flows in the Event Evidence.
Atomic filters can now be imported together with the note in the Settings > Filters.
Vendor icons are shown next to the MAC addresses.
Removed "Delete events marked as false positive" option in the False Positive form.
Known Issues
The compatible Flowmon QRadar Application is not available yet.
Release information
Flowmon Anomaly Detection System
Version: 13.1.0
Date: 16th September 2026
This package can be used for new installation or to upgrade Flowmon ADS on a Flowmon appliance.
Copyright notice
Copyright © 2007 - 2026 Progress Software Corporation and/or its subsidiaries or affiliates. All Rights Reserved.
Support information
If you need help, contact our Support team at the Flowmon Support and Learning Hub.
Compatibility
This package is compatible with Flowmon 13.1.0 or higher. This package is compatible with Flowmon IDS Probe 13.1.0 or higher. This package is compatible with Flowmon Packet Investigator 13.1.0 or higher.
Dependencies
The following table summarizes the minimum required versions of Flowmon and Flowmon ADS for various versions of the package.
The table only lists versions with dependency changes.
| Flowmon ADS version | Minimum required version of Flowmon | Minimum required version of ADS | Notes |
|---|---|---|---|
| 13.1.0 | 13.1.0 | 13.0.0* | *ADS 13.0.0+ is needed when upgrading FM to 13.1.0 |
| 13.0.0 | 13.0.0 | 12.5.2 | |
| 12.4.0 | 12.4.0 | 12.3.0 | |
| 12.3.0 | 12.3.5 | 12.2.0 | |
| 12.2.0 | 12.3.0 | 11.1.1* | *ADS 12.0.4+ is needed when upgrading FM to 12.3.0 |
| 12.1.0 | 12.2.0 | 11.1.1* | *ADS 12.0.4+ is needed when upgrading FM to 12.2.0 |
| 12.0.0 | 12.0.0 | 11.1.1* | *ADS 11.2.4+ is needed when upgrading FM to 12.0.0 |
| 11.4.1 | 11.1.9 | 10.0.0* | *ADS 11.1.1+ is needed when upgrading FM to 11.1.9 |
| 11.3.2 | 11.1.7 | 10.0.0* | *ADS 11.1.1+ is needed when upgrading FM to 11.1.7 |
| 11.3.0 | 11.1.6 | 10.0.0* | *ADS 11.1.1+ is needed when upgrading to 11.1.6 |
| 11.2.0 | 11.1.0 | 10.0.0* | *ADS 11.1.1+ is needed when upgrading FM to 11.1.0 |
| 11.0.4 | 11.0.1 | 10.0.0 |
Installation
The installation requires a Flowmon ADS license. To upgrade from previous major versions, a license with the Standard or Extended Support is required.
The first installation and uninstallation of Flowmon ADS restarts the flow collector for a short period of time, during which flow data is not collected. This affects traffic charts in the Flowmon Monitoring Center and the event chart in Flowmon ADS.
- Download the package from the Support portal. Do NOT unpack it.
- Log in to Flowmon Configuration Center on your Flowmon appliance.
- Open the Version page.
- Click Import package and choose the installation package.
- Wait until a notification is displayed informing you that the update was successful.
After upgrading from a previous major version, the web User Interface (UI) may display incorrectly with visual issues like missing text. If that happens, try to clear the browser cache.
Cleaning local storage in Firefox/Chrome browser:
- Press F12 on your keyboard to open developer tools.
- Select the Console tab.
- Type the following command: localStorage.clear();
- Press enter to confirm the command.