Stay organized with collections
Save and categorize content based on your preferences.
Change log for NETSCOUT_OCI
Date
Changes
2024-02-21
Enhancement:
- Added support for new version of Syslog CEF logs.
- Mapped "url" to "target.url".
- Mapped "app" to "target.application".
- When "src_iporhost" is a valid IP, then mapped it to "principal.ip" or else mapped it to "principal.hostname".
- Mapped "mitreTactic", "mitreTechnique", "srcCount", "dstCount", "srcHostGroupCount", "dstHostGroupCount", "interfaceCount", "violationCount", "dstHostGroup", and "srcHostGroup" to "security_result.detection_fields".
- Removed "desc" mapping to "security_result.description" as it is already being mapped to "metadata.description".
- Mapped "iocDescription" to "security_result.description".
- Mapped "Category" to "security_result.category_details".
- Mapped "Policy" and "Classification" to "additional.fields".
[[["Easy to understand","easyToUnderstand","thumb-up"],["Solved my problem","solvedMyProblem","thumb-up"],["Other","otherUp","thumb-up"]],[["Hard to understand","hardToUnderstand","thumb-down"],["Incorrect information or sample code","incorrectInformationOrSampleCode","thumb-down"],["Missing the information/samples I need","missingTheInformationSamplesINeed","thumb-down"],["Other","otherDown","thumb-down"]],["Last updated 2025-03-13 UTC."],[[["The NETSCOUT_OCI parser was initially created on September 4, 2023."],["On February 21, 2024, the parser was enhanced to support a new version of Syslog CEF logs."],["The February 2024 update included mapping several fields like \"url,\" \"app,\" and \"src_iporhost\" to standardized target fields."],["Multiple fields related to security and network data, such as \"mitreTactic,\" \"srcCount,\" and \"Policy,\" were mapped to specific security or additional fields."],["The mapping of \"desc\" to \"security_result.description\" was removed due to redundancy, while \"iocDescription\" was newly mapped to this field."]]],[]]