Stay organized with collections
Save and categorize content based on your preferences.
Change log for ESET_EDR
Date
Changes
2024-04-08
Enhancement:
- Mapped "Detectiontype" to "security_result.category_details".
- Mapped "Time_of_occurrence" to "additional.fields".
2024-03-12
Enhancement:
- Added Grok patterns to parse new log.
- Mapped "Detectiontype" to "security_result.category_details".
- Mapped "Detection_name" to "security_result.threat_name".
- Mapped "Scanner" to "security_result.description".
- Mapped "Action_performed" to "security_result.action_details".
- Mapped "Computer_name" to "principal.hostname".
- Mapped "Computer_name" to "principal.asset.hostname".
- Mapped "Logged_user" to "principal.user.userid".
- Mapped "app" to "principal.application".
- Mapped "process_id" to "principal.process.pid".
[[["Easy to understand","easyToUnderstand","thumb-up"],["Solved my problem","solvedMyProblem","thumb-up"],["Other","otherUp","thumb-up"]],[["Hard to understand","hardToUnderstand","thumb-down"],["Incorrect information or sample code","incorrectInformationOrSampleCode","thumb-down"],["Missing the information/samples I need","missingTheInformationSamplesINeed","thumb-down"],["Other","otherDown","thumb-down"]],["Last updated 2025-03-13 UTC."],[[["This changelog details updates for ESET_EDR, focusing on enhancements to log parsing and field mapping."],["On April 8, 2024, updates mapped \"Detectiontype\" to \"security_result.category_details\" and \"Time_of_occurrence\" to \"additional.fields\"."],["On March 12, 2024, Grok patterns were added, and multiple fields were mapped, including \"Detection_name,\" \"Scanner,\" \"Computer_name,\" and \"Logged_user,\" to relevant security and principal fields."],["On May 10, 2022, multiple fields such as userid, file.full_path, processName, threat_name, and more were added or modified to increase log parsing accuracy."]]],[]]