Stay organized with collections
Save and categorize content based on your preferences.
Change log for HADOOP
Date
Changes
2023-06-05
Enhancemment - Added new Grok pattern to parse new syslog format logs.
- Changed "event_type" from "GENERIC_EVENT" to "NETWORK_CONNECTION" when both "principal" and "target" fields are present, otherwise set it to "STATUS_UPDATE".
- Mapped "ugi" to "target.ip".
- Mapped "tip" to "target.hostname".
- Mapped "cmd" to "principal.process.command_line".
- Mapped the "hostname" and IP address already mapped to "observer.hostname and observer.ip" to "principal.hostname" and "principal.ip" as well to meet validation requirements.
[[["Easy to understand","easyToUnderstand","thumb-up"],["Solved my problem","solvedMyProblem","thumb-up"],["Other","otherUp","thumb-up"]],[["Hard to understand","hardToUnderstand","thumb-down"],["Incorrect information or sample code","incorrectInformationOrSampleCode","thumb-down"],["Missing the information/samples I need","missingTheInformationSamplesINeed","thumb-down"],["Other","otherDown","thumb-down"]],["Last updated 2025-03-13 UTC."],[[["A new Grok pattern was added to support parsing logs in the new syslog format."],["The \"event_type\" field was updated to be either \"NETWORK_CONNECTION\" when both \"principal\" and \"target\" fields are populated or \"STATUS_UPDATE\" in other cases."],["Several fields were remapped for improved data structure: \"ugi\" to \"target.ip,\" \"tip\" to \"target.hostname,\" \"cmd\" to \"principal.process.command_line,\" and \"hostname/IP\" to both \"observer\" and \"principal\" for validation."],["In May 2022 the IP was mapped to observer.ip."]]],[]]