Change log for SNARE_SOLUTIONS
Date | Changes |
---|---|
2024-11-14 | Enhancement:
- Added support for a new format of SYSLOG+JSON logs. - Mapped "event_id" to "additional.fields". - Mapped "log_name" to "principal.application". - Mapped "workstation_name" to "target.hostname". - Mapped "keyword" to "security_result.summary". - Mapped "event_action" to "security_result.description". |
2024-07-31 | Enhancement:
- Added support for a new format of SYSLOG logs. |
2024-06-06 | Enhancement:
- Mapped "network_information_workstation_name" to "target.hostname". - Mapped "intermediary.ip". - Mapped "target.user.userid". |
2024-06-04 | Enhancement:
- Added a new Grok pattern to parse the "SYSLOG + KV" format logs. - Mapped "EventCategory" and "EventlogType" to "additional.fields". - Mapped "filter_runtime_id", "layer_name", and "layer_runtime_id" to "security_result.detection_fields". |
2024-05-31 | Enhancement:
- Mapped "target.user.userid" to have the second part of value. - Mapped event IDs to "metadata.product_event_type". |
2024-05-20 | Enhancement:
- Mapped "logon type" to "extensions.auth.auth_details". |
2024-04-17 | Enhancement:
- Supported new Microsoft Windows event logs. |
2024-01-24 | Enhancement:
- Added Grok patterns to parse dropped "SYSLOG + KV" format logs. - Mapped "ts" to "metadata.event_timestamp". - Mapped "hostname" and "src_host" to "principal.asset.hostname". - Mapped "src_ip" to "principal.asset.ip". - Mapped "Namespace" to "principal.user.userid". - Mapped "ClientProcessID" to "principal.process.pid". - Mapped "HostApplication" to "principal.application". - Mapped "Id" to "principal.resource.product_object_id". - Mapped "ip_protocol" to "network.ip_protocol". - Mapped "event_id" and "Component" to "additional.fields". - Mapped "NotificationQuery", "PossibleCause", "Operation" and "ResultCode" to "security_result.detection_fields". - Mapped "ProviderName", "NewProviderState", "SequenceNumber", "HostName", "HostVersion", "HostId", ""EngineVersion", "RunspaceId", "PipelineId", "CommandName", "ScriptName", "CommandPath", "Volume_GUID", and "Volume_name" to "principal.resource.attribute.labels". |
2022-07-29 | Newly created parser
|