Change log for KEMP_LOADBALANCER
Date | Changes |
---|---|
2025-08-25 | Enhancement:
- Added support Grok pattern for syslog logs. - event.idm.read_only_udm.principal.application: Newly mapped `process_name` raw log field to event.idm.read_only_udm.principal.application. - event.idm.read_only_udm.metadata.product_log_id: Newly mapped `sequenceId` raw log field to event.idm.read_only_udm.metadata.product_log_id. - event.idm.read_only_udm.target.url: Newly mapped `http_path` raw log field to event.idm.read_only_udm.target.url. - event.idm.read_only_udm.additional.fields: Newly mapped `hlen` and `nhdrs` raw log field to event.idm.read_only_udm.additional.fields. - event.idm.read_only_udm.security_result.summary: Newly mapped `log_level` raw log field to event.idm.read_only_udm.security_result.summary. - event.idm.read_only_udm.security_result.detection_fields: Newly mapped `http_version` raw log field to event.idm.read_only_udm.security_result.detection_fields. |
2025-04-02 | Enhancement:
- Added Grok patterns to parse the unparsed logs. - event.idm.read_only_udm.additional.fields: Newly mapped `meta_sequenceId` raw log field with `event.idm.read_only_udm.additional.fields` UDM field - Added a gsub to replace '\\r\\n' with ' ' on "message" to parse the logs. - Added a condition check to map event_type to "USER_UNCATEGORIZED" if des_ip is not equal to null, else mapped "event_type" to "GENERIC_EVENT" - Added a condition check before mapping "sshd" to "target.application". - Added a condition check before mapping "pid" to "target.process.pid". |
2025-01-13 | Enhancement:
- Added support for a new pattern of syslog logs. - Mapped "event_type" to "USER_UNCATEGORIZED" and "STATUS_UPDATE". |
2023-05-31 | Enhancement: Parsed logs with events as "Connected", "Slave accept", "Block access to host".
- Mapped "srcip" to "principal.ip". - Mapped "dstip" to "target.ip". - Mapped "vs" to "target.ip". - Mapped "srcport" to "principal.port". - Mapped "dstport" to "target.port". - Mapped "resource" to "target.url". - Mapped "event" to "metadata.product_event_type". - Parsed failing syslog logs. |