Stay organized with collections
Save and categorize content based on your preferences.
Change log for SYMANTEC_VIP
Date
Changes
2023-03-03
Enhancement- Mapped "userid" to "target.user.userid" for the logs that were not parsed already.
- Mapped "event_type" to "USER_LOGIN" for the logs where "userid" is present
else if "principal.hostname" is present then mapped "event_type" to "STATUS_UPDATE",
else mapped it to "GENERIC_EVENT".
- Parsed the logs that were dropped initially.
2022-08-03
BugFix - Added the grok pattern to handle the unparsed logs having log_type "remove_credentials".
[[["Easy to understand","easyToUnderstand","thumb-up"],["Solved my problem","solvedMyProblem","thumb-up"],["Other","otherUp","thumb-up"]],[["Hard to understand","hardToUnderstand","thumb-down"],["Incorrect information or sample code","incorrectInformationOrSampleCode","thumb-down"],["Missing the information/samples I need","missingTheInformationSamplesINeed","thumb-down"],["Other","otherDown","thumb-down"]],["Last updated 2024-12-12 UTC."],[],[]]