Release notes¶
This page lists release notes for KX Sensors, in reverse chronological order.
When you upgrade, read the upgrade notes for every version between the one you're on and the one you're moving to. A release without an Upgrade notes section needs no action. For the upgrade procedure itself, see Before you begin.
3.3.0¶
Release date: 2026-09-23
Upgrade notes¶
- The version of RT changes in v3.3. See RT upgrades.
- Moving RT out of Docker is a manual part of the 3.2 to 3.3 upgrade: stop every node in the cluster, perform a hard reset of RT, and delete the RT Docker containers by hand. Because a hard reset discards RT log and state data, back up the contents of
emsLogDiron each node first. You can remove the Docker Swarm overlay network and uninstall Docker at any point during or after the upgrade. See Move RT from Docker to the host. - The
rtLogDir,rtSeqDir, andrtSesDirsystem parameters are removed. All RT log and state directories now derive fromemsLogDir. Remove these entries from yoursystemParams.yamlwhen you upgrade. See RT log files. rtoRetryFreqis renamed tortoRetryInterval, with its default changing from1000to2500, andrtoRetryLimittortoMaxRetries, with its default changing from10to25. Rename these entries in yoursystemParams.yamlwhen you upgrade.- The
rtoDockerLogMaxSize,rtoDockerLogMaxFile, andrtoDockerLogCompresssystem parameters are removed, since RT logs now follow normal KX Sensors application-log rotation. Remove these entries from yoursystemParams.yamlwhen you upgrade. - The
networkfield inems.yamlis deprecated and no longer used. No action is required: leave it in place and blank, since it's retained to avoid problems during dynamic upgrade. - RT now listens on host ports. The range from
KXS_BASE_PORT+ 800 toKXS_BASE_PORT+ 1000 is reserved for RT, with 30 ports allocated per stream; make sure these are free and permitted by your firewall rules before you upgrade. The Docker Swarm ports that the RT overlay network required — 2377/TCP, 4789/UDP, and 7946/TCP — are no longer needed. See Network requirements. - If any EMS stream enables TLS, the
KX_SSL_CA_CERT_FILE,KX_SSL_CERT_FILE, andKX_SSL_KEY_FILEvariables must point to certificate files that exist on the host. RTO validates them at startup and exits without restarting if any are missing. See Configure TLS for ingestion from an external client through RT. - v3.3 includes required changes to the KX-supplied packages. Review your custom packages against the updated versions and merge the changes before you upgrade.
- If a package in your deployment enables REST by setting
isRESTtotrue, make sure the REST port is free before you upgrade. By default the REST bridge listens on the SGW process port + 6; override it by settingKXS_REST_PORTinkxsenv. - Row-level retention is off by default, so no action is required on upgrade. Before you enable
dbmRetention, check that each table'sretentionDurationis shorter than the whole-partition retention that applies to it, otherwise the partition is deleted before the clause is ever applied. See Row-level retention.
KDB-X¶
Upgrades the underlying database from kdb+ 4.1 to KDB-X, which provides the module framework that future KX Sensors releases build on. Your existing license continues to work, but depending on the features you use, it may need to be reissued with additional feature flags.
REST¶
Reinstates REST support, which exposes your public APIs as JSON-over-HTTP endpoints without requiring changes to the APIs themselves. Endpoints are generated automatically from the SAPI registry and hosted by the SGW service class. REST is disabled by default; enable it by setting isREST to true in systemParams.yaml. See Call APIs over REST.
RT without Docker¶
RT no longer runs as a Docker container, so Docker and the Docker Swarm overlay network are no longer prerequisites for multi-node deployments. All RT processes now run directly on the host, and RTO remains responsible for starting, stopping, and monitoring them on each node.
RT is now a service class in its own right, so you inspect its processes with kxsctl status RT rather than with container tooling, and its application logs are written to the KX Sensors application log directory like those of any other process. The RT implementation ships as a q package instead of a container image, and RT listens on host ports rather than on container ports forwarded from the host.
Row-level retention¶
Adds row-level retention, which removes selected rows from aging HDB partitions instead of deleting whole partitions. Give a table a functional where clause and an age in days, and DBM prunes the rows the clause doesn't select once a partition reaches that age. You can apply different retention periods to groups of rows in the same table. For example, you can retain most readings for 100 days and a subset for 400 days.
Configure a policy with the new retentionDuration and retentionWC table properties in your schema files. A table can define several stages, each with its own age and clause. Row-level retention reuses the existing DBM tier-migration pipeline. A partition that needs both a tier move and a prune can have both applied in a single rewrite, and the same disk, memory, and EOD-yield safeguards apply. Enable it with the new dynamic system parameter dbmRetention.
kxsctl CLI enhancements¶
v3.3.0 includes several enhancements to kxsctl, the command-line interface for KX Sensors v3. For more information, see About kxsctl.
- Three new commands.
kxsctl refreshregenerates the systemd unit files from the current templates and manifest,kxsctl historyshows the commands previously run throughkxsctlon a node, andkxsctl manifestreplaceskxsctl exportandkxsctl import, adding the ability to edit a manifest interactively or programmatically. kxsctl logreplaceskxsctl show log. You can now view the logs of a process on any node, list the available logs for selection, and follow the current log across an hourly rollover. The-a/--age,-e/--no-less, and-n/--linesflags are removed.kxsctl statusis more concise and now colourised, highlights problem states, and includes disabled and inactive nodes rather than omitting them.- Enable, disable, start, stop, and restart behave consistently, and exit non-zero when a target never reaches the requested state. See Start and stop nodes individually and Start and stop service class instances.
- Discovery errors now name the key and the underlying cause, and
kxsctl show nodeStateprints timestamps in a readable form with their time zone. kxsctl-clientreports TLS certificate errors and unreachable discovery more clearly, forwardskxsctl-client userarguments individually so that values containing spaces are preserved, and unpacks any.qpkarchives found under adepsdirectory after a directory upload.- The
-pand-npassword shorthands are removed fromkxsctl userandkxsctl-client user. Use--passwordand--new-passwordinstead, and update any scripts that use the short forms.
Documentation site¶
KX Sensors product documentation is now published as a documentation site at code.kx.com/sensors, launching alongside this release. It replaces the Runbook that was previously distributed as a PDF.
The site is searchable and versioned, and it isn't tied to the product release cycle, so corrections and new content can be published as they're ready rather than waiting for the next release. Start at the Overview, or browse by section: Architecture, Develop, Configure and Deploy, and Operate.
3.2.11¶
Upgrade notes¶
There are no upgrade considerations when upgrading from v3.2.10.
Fixes and enhancements¶
- Fixed message ID handling in external TPs to prevent messages from being incorrectly discarded as duplicates.
- Updated SP request handling to send only one response when a request is deferred multiple times.
- Added retries for
requestSchemaUpgradewhen a request times out. - Converted local timestamps to UTC in
IdbStatusandHdbStatus. - Improved accounting of dynamic upgrade for in-memory delta partitions in
partitionedMDB.q. - Updated Dynamic Upgrade to handle an edge case in a custom layer.
- Prevented a domain error when missed EOD events occur after a dynamic upgrade that adds new MD tables.
- Improved message handling after the buffer size is exceeded.
- Removed direct reads of
processVersionfrom disk after a dynamic upgrade.
3.2.10¶
Upgrade notes¶
There are no upgrade considerations when upgrading from v3.2.9.
Fixes and enhancements¶
- Added an EOI offset to SM, avoiding disk contention when hosting multiple environments.
- Fixed an RT sequencer issue that could cause it to skip ahead in the merged log.
- Fixed
updPubSubto prevent a regression of thelocitable in DBW. - Added a default
initcolumn for migratednxDbTblsduring v2-to-v3 upgrades. - Changed the default of
ctx.pubtofalse, correcting behavior in SPs. - Improved the
getDataAPI. - Updated the system commands used by RTO to support RHEL 10.
3.2.9¶
Upgrade notes¶
There are no upgrade considerations when upgrading from v3.2.8.
Fixes and enhancements¶
- Fixed the response for
isSequencedrequests that require deferral. - Fixed
seedNode, which could leave unexpected state if the etcd write needed to be retried. - Fixed dynamic upgrade so it renames and deletes
#files for nested columns, and so the revision no longer jumps from 1 to 3 after an upgrade. - Fixed DBC reverse-channel replies selecting a peer with
first, added a retry to the DBC handshake, and updated DBC to usecomm. - Fixed
archiveLogsrunning before TP processes had started.
3.2.8¶
This patch merges in fixes relating to the Utilities vertical. The fixes originated in the v2 stream of the product and are ported to v3 where applicable.
Upgrade notes¶
There are no upgrade considerations when upgrading from v3.2.7.
Fixes and enhancements¶
- Added the
ktblhelper function. .dbw.hdbtrimdatesnow operates on a static link directory.- Improved
etcd.shin the installer. - Enhanced ChannelSMP.
- Optimized DBCONV:
aploperations now run withpeach, and adding new tables is faster. - Revived the
getDataAPI and fixed it for non-partitioned tables. - Added a
filterCalcshook toprocessReadingsindc.q. - Fixed VEE issues, including a deferral bug,
MSGIDnot remaining an int, and a type error when an SP received an addition to the deferral buffer after the deferral had resumed. - TP-specific fields can now be configured at the stream level.
- Fixed
wdurbeing incorrectly reset to 0 in the low-priority Gateway queue, and correctedgwMaxDurWttuning that could leave the Gateway blocked waiting for requests to finish. - Disabled retention-based archival everywhere.
3.2.7¶
Upgrade notes¶
- The OpenSSL 1.0 dependency is factored out of
kxs-core. The installer no longer requires or supports the-oflag; see the updated Deployment Guide. - If upgrading from v3.2.5 or earlier, the version of RT changes, which requires a rolling upgrade. See RT upgrades.
Fixes and enhancements¶
- Fixed a bug introduced in v3.2.6 that could cause messages from external clients to be incorrectly discarded as duplicates in single-node deployments. The origin is now stamped on the TP message payload.
- Fixed an EOD notify timeout that could cause long-running queries to fail around EOD.
- Updated kdb+ to 4.1-2026.07.06.
- Removed the OpenSSL 1.0 dependency from the SI library.
3.2.6¶
Upgrade notes¶
- This release includes an updated RT version, which requires a rolling upgrade. See RT upgrades.
Fixes and enhancements¶
kxsctl-clientnow supports calling any nativekxsctlcommand remotely, rather than a subset. See About kxsctl.- Various fixes and small feature requests.
3.2.5¶
Upgrade notes¶
- The SAPI
aifield type has been reverted toObject, matching its v2 behavior. This may require minor code changes in SAPI clients. -
After upgrading from a previous v3 version, restart the DBW and MON service classes. This step won't be required for future upgrades.
kxsctl restart DBW kxsctl restart MON
Fixes and enhancements¶
- Added the MONIDB and MONHDB service classes, which surface persisted monitoring data via
getMonStats. - Fixed a bug in
.wm.resvenqwmtthat returned incorrect watermarks. - Processes stopped gracefully with
kxsctl stopno longer restart on server reboot. - Optimized DBCONV and EOD processing.
- Fixed reloadable scripts so they're correctly reloaded during a dynamic upgrade.
- Aligned qetcd log rollover with KX Sensors q processes.
3.2.4¶
Fixes and enhancements¶
- Improved
nxdiagsscripts to support retrieving logs for specific dates. - Disabled retention-based archival for EMS logs by default.
- Made
.dbw.runEpilogtiming configurable. - Added handling for missing files in
.dbw.fillhdbtsrangesduring v2-to-v3 upgrades.
3.2.3¶
Upgrade notes¶
tpLogDirandrtLogDirare simplified into a single system parameter,emsLogDir. Update existing entries insystemParams.yamlwhen upgrading from a previous v3 version.- Since the default value of
isCompressedis nowfalse, review your existing v3 compression settings in your schema. - Installer flags have changed:
--master-keysupplies the master key (used to encrypt the user credential database) from the command line instead ofinstall.profile, and the installer prompts for one and offers to generate it if neither is provided.--root-usersupplies root user credentials from the command line instead ofinstall.profile, and the installer also prompts for credentials so you can avoid storing them in plain text.
Fixes and enhancements¶
- Added
getDataAPI functionality. - Fixed minor EMS issues and configuration changes.
- Added support for re-rooting database files.
- Used the DBW thread count when
eoxSubtaskThreadsis null. - Changed the default value of
isCompressedtofalse, matching v2. - Optimized DBCONV for adding new tables.
- Avoided a redundant upsert for MRU.
- Updated the installer to prompt for missing authentication variables.
3.2.2¶
TP+ enhancements¶
- Added TLS support for encrypting data in transit.
- Improved robustness against data log corruption.
- Validated integration with single-instance HA.
- Added metrics generation for monitoring.
- Added support for backing up data logs.
CLI enhancements¶
- Updated
kxsctl-clienthelp output to include previously missing commands. kxsctl,kxsctl-client, andkxsctl-agentnow correctly display their versions in help output and via theversionsubcommand or--versionflag.
3.2.1¶
Fixes and enhancements only, including improvements to MDQ weighting, API timeout handling, multi-table filtering, and EMS ping frequency, plus reliability improvements to VEE message tracking.
3.2.0¶
TP+¶
Introduces TP+, a new service class that replaces Reliable Transport (RT) as the default EMS for single-node deployments. It's topologically similar to TP in v2, with enhancements including subscription to arbitrary points in the log, asynchronous log replay on startup, message deduplication, and the ability to pause and resume subscriptions. TP+ is for single-node deployments only; use RT for multi-node, non-HA topologies.
TLS encryption of etcd traffic¶
etcd traffic between nodes and clients can now be encrypted with TLS, including client certificate validation.
Scheduled tasks¶
Reinstates the ability to schedule tasks for execution by a native q process, useful for log archival and cleanup, and for custom tasks that need awareness of KX Sensors application state.
Strong data consistency¶
Queries can now request strong data consistency (all preceding writes guaranteed to be reflected in the result) using a flag, at the cost of some additional latency. By default, KX Sensors provides eventual consistency.
Query-only nodes¶
You can now provision query-only nodes that serve queries without ingestion. Query-only nodes still receive data in real time, can use different HDB storage tiers, and can be targeted with custom query routing.
Multicast alternative¶
A new service class, MC_BRIDGE, provides an alternative to multicast for networks where multicast isn't supported, such as some cloud environments. Multicast is still recommended by default where available.
Persistence of monitoring data¶
Monitoring data is now subscribed to and written by DBW, so it can be retained for analysis in production systems.
Installer update for MTU¶
The installer now accepts DOCKER_NETWORK_MTU in install.profile to set the correct MTU when creating the Docker network.
3.1.2¶
Pacemaker integration¶
Adds support for integrating KX Sensors with Pacemaker for single-instance HA deployments.
Documentation improvements¶
Closed several documentation gaps and consolidated related documents.
Fixes and enhancements¶
Added hourly rollover of application logs, new MDQ weighting parameters, and support for DBC on a single date, plus fixes to diffDB, sub-request timeouts, and Gateway routing when nodes are marked as failed.
3.1.1¶
kdb+ 4.1¶
Upgrades the underlying kdb+ version from 4.0 to 4.1.
Authentication¶
Reintroduces username and password authentication, configurable independently per process (qetcd, kxsctl-agent, and q processes such as the Gateway). Installation requires a master encryption key to encrypt the credential database, stored in etcd, and credentials for an initial admin user. Manage additional users with kxsctl user commands.
Fixes and enhancements¶
EOD can now be configured to use the local time zone, and log file timestamps can use a configurable time zone.
3.1.0¶
Encryption, compression, TLS, and REPL — all available in KX Sensors v2 — are reintroduced in v3.
Encryption¶
Supports encryption of on-disk HDB and IDB data (RDB data isn't eligible), based on kdb+ encryption with a password-protected master key. You can selectively encrypt individual tables, columns, table categories, database tiers, and the symbol table.
Compression¶
You can select individual table columns for compression to improve query performance.
TLS¶
Connections from SAPI clients to q processes, and between q processes, support TLS encryption. TLS isn't yet supported between RT nodes.
SAPI discovery without Go¶
SAPI's discovery layer is reimplemented natively in C, removing the Go-based etcd client library used previously (which was incompatible with C# SAPI and .NET on Linux). SAPI clients now send discovery requests to the qetcd process on each node instead of connecting directly to etcd, using the base port + 3 for non-TLS connections and the base port + 4 for TLS connections.
REPL¶
The REPL service class replicates selected tables in CSV format via file copy, for consumption by an external system such as a SQL database or Hadoop.
Bridge mode¶
External SAPI clients can now publish directly to RT bridge, eliminating the need for local log files and child publishing processes on the client side. Bridge mode is recommended by KX but disabled by default, since it shifts responsibility for handling out-of-order delivery, message loss, and duplication to the client application.
Topic filtering¶
RT subscribers can now filter messages by topic via a new sub_server process, instead of each node persisting a full copy of the merged log. This reduces disk and CPU usage and improves HA stability at high ingestion rates, at the cost of some additional network I/O.
3.0.10¶
Minor fixes across Dynamic Upgrade, the CLI, the Gateway, and Discovery.
3.0.9¶
Minor fixes, an optimization for Reliable Transport in single-node systems, and improved system health checks.
3.0.8¶
CLI error handling and reporting improvements; installer improvements for air-gapped environments; various fixes and a new EMS version.
3.0.7¶
Official support for upgrading from v2 to v3, and the diffDB tool for detecting and remediating data mismatches across nodes.
3.0.6¶
Reinstated Most Recently Used (MRU) tables, integrated with the SP EMS and deferral framework.
3.0.5¶
SP EMS integration with VEE and MQ for reliable message recovery during failover, and high availability support for the MQ service class.
3.0.4¶
Minor core and installer fixes, plus support for converting individual v2 q files, not just full packages, to the v3 format.
3.0.3¶
Introduced the SP EMS framework, a consistent interface for streaming processors such as SDL; completed the dynamic upgrade implementation; added support for splitting large master tables; and improved IDB purviews for high-ingestion-volume systems.