Stay organized with collections
Save and categorize content based on your preferences.
Change log for EXTREME_SWITCH
Date
Changes
2023-12-19
Enhancement:
- Added a new Grok pattern to support new type of SYSLOG logs.
- Added new Grok patterns to parse "description".
- Mapped "protocol", "VrId", "SlppRxVlan", "SlppIncomingVlanId", "Type", "Cause" to "additional.fields".
- Mapped "session_id" to "network.session_id"
- Mapped "SlppSrcMacAddress" to "principal.mac".
- Mapped "intermediary_ip" to "intermediary.ip.
- Mapped "ver" to "metadata.version".
- Mapped "rcPortVLacpAdminEnable", "rcSyslogHostMapFatalSeverity", "rcSyslogHostMapWarningSeverity", "rcSyslogHostRowStatus", "rcSyslogHostFacility", "rcSyslogHostAddressType", "rcSyslogHostMapErrorSeverity", "rcSyslogHostMapInfoSeverity", "rcSyslogHostSeverity", "rcSyslogHostEnable" to "security_result.detection_fields".
- Mapped "port" to "principal.port".
- Mapped "rcSyslogHostAddress" to "principal.hostname".
[[["Easy to understand","easyToUnderstand","thumb-up"],["Solved my problem","solvedMyProblem","thumb-up"],["Other","otherUp","thumb-up"]],[["Hard to understand","hardToUnderstand","thumb-down"],["Incorrect information or sample code","incorrectInformationOrSampleCode","thumb-down"],["Missing the information/samples I need","missingTheInformationSamplesINeed","thumb-down"],["Other","otherDown","thumb-down"]],["Last updated 2025-03-13 UTC."],[[["The EXTREME_SWITCH parser was newly created as of December 11, 2023."],["On December 19, 2023, enhancements were made, including adding new Grok patterns for SYSLOG logs and parsing descriptions."],["Multiple fields were mapped to new or existing fields, such as \"session_id\" to \"network.session_id\" and \"SlppSrcMacAddress\" to \"principal.mac\"."],["Several \"rcSyslogHost\" fields were mapped to \"security_result.detection_fields\", and \"port\" was mapped to \"principal.port\"."]]],[]]