Change log for IMPERVA_ABP
Date | Changes |
---|---|
2024-12-05 | Enhancement:
- Added support to parse requested fields. - Changed mapping of "url.path" from "target.url" to "network.http.referral_url". |
2024-11-07 | Enhancement:
- If the value of the "monitor_action" field is neither 'block' nor 'allow', then mapped it to "security_result.action_details". |
2024-10-10 | Enhancement:
- Mapped "metadata.vendor_name" to "Imperva ABP". |
2024-03-23 | Enhancement:
- Added a JSON block to parse additional logs. - Mapped "event.provider" to "principal.user.userid". - Mapped "client.ip" to "principal.ip". - Mapped "client.domain" to "principal.hostname". - Mapped "imperva.abp.request_type" to "principal.labels". - Mapped "imperva.abp.pid" to "principal.process.pid". - Mapped "client.geo.country_iso_code" to "principal.location.country_or_region". - Mapped "server.domain" to "target.hostname". - Mapped "server.geo.name" to "target.location.name". - Mapped "url.path" to "target.process.file.full_path". - Mapped "imperva.abp.customer_request_id" to "network.session_id". - Mapped "imperva.abp.token_id" to "target.resource.product_object_id". - Mapped "imperva.abp.random_id" to "additional.fields". - Mapped "http.request.method" to "network.http.method". - Mapped "user_agent.original" to "network.http.parsed_user_agent". - Mapped "imperva.abp.headers_referer" to "network.http.referral_url". - Mapped "imperva.abp.zuid" to "additional.fields". - Mapped "imperva.ids.site_name" to "additional.fields". - Mapped "imperva.ids.site_id" to "additional.fields". - Mapped "imperva.ids.account_name" to "metadata.product_event_type". - Mapped "imperva.ids.account_id" to "metadata.product_log_id". - Mapped "imperva.abp.headers_accept_encoding" to "security_result.detection_fields". - Mapped "imperva.abp.headers_accept_language" to "security_result.detection_fields". - Mapped "imperva.abp.headers_connection" to "security_result.detection_fields" - Mapped "imperva.abp.policy_id" to "security_result.detection_fields". - Mapped "imperva.abp.policy_name" to "security_result.detection_fields". - Mapped "imperva.abp.selector_derived_id" to "security_result.detection_fields". - Mapped "imperva.abp.monitor_action" to "security_result.action". - Mapped "http.request.body.bytes" to "network.sent_bytes". - Mapped "imperva.abp.tls_fingerprint" to "security_result.description". - Mapped "imperva.abp.session_length_seconds", "imperva.abp.requests_per_session", "imperva.abp.requests_per_minute", "imperva.abp.token_expire", "imperva.abp.seconds_with_expired_token", "imperva.abp.requests_with_expired_token", "imperva.abp.requests_with_no_token", "imperva.abp.seconds_with_no_token", "imperva.ids.site_name", and "imperva.ids.site_id" to "additional.fields". |
2023-07-21 | Newly created parser. |