Skip to content

Commit 09974c8

Browse files
committed
Merge branch 'main' into DOCS-1118
2 parents cda2807 + fb85384 commit 09974c8

File tree

49 files changed

+587
-19
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

49 files changed

+587
-19
lines changed

docs/api/data-deletion-rules.md

Lines changed: 44 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,44 @@
1+
---
2+
id: data-deletion-rules
3+
title: Data Deletion Rules APIs
4+
sidebar_label: Data Deletion Rules
5+
description: Data Deletion Rules APIs allow you to delete ingested data from Sumo Logic.
6+
---
7+
8+
<head>
9+
<meta name="robots" content="noindex" />
10+
</head>
11+
12+
<p><a href="/docs/beta"><span className="beta">Beta</span></a></p>
13+
14+
import useBaseUrl from '@docusaurus/useBaseUrl';
15+
import ApiIntro from '../reuse/api-intro.md';
16+
import ApiRoles from '../reuse/api-roles.md';
17+
18+
<img src={useBaseUrl('img/icons/dashboards.png')} alt="icon" width="50"/>
19+
20+
Data Deletion Rules allow you to quickly and easily request the removal of ingested data from Sumo Logic. This helps you with removal of inadvertently ingested sensitive data.
21+
22+
## Documentation
23+
24+
<ApiIntro/>
25+
26+
|Deployment|Documentation URL |
27+
|:----------|:-------------------|
28+
|AU |https://api.au.sumologic.com/docs/#tag/dataDeletionRules |
29+
|CA |https://api.ca.sumologic.com/docs/#tag/dataDeletionRules |
30+
|DE |https://api.de.sumologic.com/docs/#tag/dataDeletionRules |
31+
|EU |https://api.eu.sumologic.com/docs/#tag/dataDeletionRules |
32+
|FED |https://api.fed.sumologic.com/docs/#tag/dataDeletionRules |
33+
|JP |https://api.jp.sumologic.com/docs/#tag/dataDeletionRules |
34+
|KR |https://api.kr.sumologic.com/docs/#tag/dataDeletionRules |
35+
|US1 |https://api.sumologic.com/docs/#tag/dataDeletionRules |
36+
|US2 |https://api.us2.sumologic.com/docs/#tag/dataDeletionRules |
37+
38+
## Required role capabilities
39+
40+
<ApiRoles/>
41+
42+
* Review Deletion Requests
43+
* Manage Deletion Requests
44+
* View Deletion Requests

docs/cse/schema/username-and-hostname-normalization.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -44,7 +44,7 @@ The following fields of the schema are normalized.
4444
| `srcDevice_hostname` | hostname |
4545
| `user_username` | username |
4646

47-
When a username is normalized, the original, un-normalized name is placed in a `_raw` name attribute, for example,  `user_useraname_raw`. The normalized name is placed in the attribute field `user_username`. The rules engine allows the `_raw` username forms to be used in rule creation.
47+
When a username is normalized, the original, un-normalized name is placed in a `_raw` name attribute, for example,  `user_username_raw`. The normalized name is placed in the attribute field `user_username`. The rules engine allows the `_raw` username forms to be used in rule creation.
4848

4949
If a name normalization configuration exists, the name attribute will be populated with the form `<username>:<friendly_domain>` where the `<friendly domain name>` portion is not populated for the normalized default domain.  When name normalization is enabled all name fields (not-raw) will be lowercase. For more information, see [Single domain example](#single-domain-example) and [Multiple domains example](#multiple-domains-example) below.
5050

@@ -182,4 +182,4 @@ Following is an example configuration for a case where the customer has a domain
182182

183183
## Additional resources
184184

185-
Blog: [What’s going on? The power of normalization in Cloud SIEM](https://www.sumologic.com/blog/whats-going-on-normalization-cloud-siem)
185+
Blog: [What’s going on? The power of normalization in Cloud SIEM](https://www.sumologic.com/blog/whats-going-on-normalization-cloud-siem)

docs/integrations/saml/onelogin.md

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -24,6 +24,7 @@ To use this feature, you'll need to enable access to your OneLogin logs and inge
2424
:::
2525

2626
Once you begin uploading data, your daily data usage will increase. It's a good idea to check the **Account** page in Sumo Logic to ensure that you have enough quota to accommodate additional data in your account. If you need additional quota, you can [upgrade your account](/docs/manage/manage-subscription/upgrade-account/upgrade-cloud-flex-legacy-account) at any time.
27+
- **OneLogin Enterprise** or **Unlimited** plan subscription.
2728

2829
### Configure an event broadcaster for event logs
2930

docs/manage/deletion-requests.md

Lines changed: 27 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -25,6 +25,10 @@ Key features:
2525
- **Customizable filters**. Tailor deletion to your needs.
2626
- **Robust auditing mechanisms**. Ensure thorough tracking.
2727

28+
:::info
29+
To know about Deletion requests API, refer to the [Data Deletion Rules APIs](/docs/api/data-deletion-rules).
30+
:::
31+
2832
## Create a deletion request
2933

3034
:::warning
@@ -34,6 +38,7 @@ After a data deletion request is approved, data will be deleted from the organiz
3438
:::note
3539
- During the data deletion process, existing messages may temporarily appear duplicated for a few seconds. These duplicated messages will automatically disappear once the data deletion is complete.
3640
- Pinned queries may continue to display data identified for deletion for up to 24 hours from the initial run, prior to the data deletion request approval.
41+
- Data deletion requests are automatically canceled after 30 days if no action is taken.
3742
:::
3843

3944
:::info
@@ -52,7 +57,11 @@ Data cannot be recovered once it gets deleted. Ensure that you have appropriatel
5257
:::
5358
1. Select the **Time Range** when the data was ingested.
5459
1. When you're done, click **Save**.
55-
1. Your request will go to a Sumo Logic Customer Support Manager (CSM) for review and approval. You can check on your request in the **Status** column. <br/><img src={useBaseUrl('img/search/get-started-search/deletion-request-status.png')} alt="deletion request status" style={{border: '1px solid gray'}} width="400"/>
60+
1. An email about your request will be sent to 50 most recently active approval users with [approval access](#approve-the-deletion-request). You can check on your request in the **Status** column.
61+
:::note
62+
If you require an approval apart from this 50 users, you can forward the deletion request approval email to the required users.
63+
:::
64+
<img src={useBaseUrl('img/search/get-started-search/deletion-request-status.png')} alt="deletion request status" style={{border: '1px solid gray'}} width="400"/>
5665

5766
### From a Log Search
5867

@@ -88,12 +97,27 @@ To cancel a data deletion request:
8897

8998
<img src={useBaseUrl('img/search/get-started-search/deletion-request-cancel.png')} alt="screenshot showing how to cancel a deletion request" style={{border: '1px solid gray'}} width="800"/>
9099

100+
## Approve the deletion request
101+
102+
:::note
103+
To approve or reject a request, ensure you have the **Review Deletion Requests** [role capability](/docs/manage/users-roles/roles/role-capabilities/). By default, **Manage Deletion Requests** and **View Deletion Requests** capabilities will be added if you have the **Review Deletion Requests** capability.
104+
:::
105+
106+
Once the deletion request is created, an email notification will be sent to the users who have approval access. To approve or reject the request, follow the steps below:
107+
108+
1. [**Classic UI**](/docs/get-started/sumo-logic-ui-classic). Go to **Manage Data > Logs > Deletion Requests**.<br/>[**New UI**](/docs/get-started/sumo-logic-ui). In the Sumo Logic main menu select **Data Management**, and then under **Logs** select **Deletion Requests**.
109+
1. Filter for the status with **Pending review**. <img src={useBaseUrl('img/search/get-started-search/pending-requests.png')} alt="filter for pending deletion requests" style={{border: '1px solid gray'}} width="800"/>
110+
1. Click the deletion request to review it.
111+
1. **Approve** or **Reject** the request based on your requirement.<br/><img src={useBaseUrl('img/search/get-started-search/approve-reject-deletion-request.png')} alt="Approve/Reject deletion requests side panel" style={{border: '1px solid gray'}} width="400"/>
112+
- **Approve**. Enter **Delete** in the **Approve Deletion Request** pop-up to permanently delete the data, and click the **Delete Data** button. <br/><img src={useBaseUrl('img/search/get-started-search/approve-deletion-request.png')} alt="Approve deletion requests pop-up" style={{border: '1px solid gray'}} width="400"/>
113+
- **Reject**. Enter the reason for rejection in the **Reject Deletion Request** pop-up to help the requester understand the reason for rejection and take any necessary actions, and click the **Reject Request** button.<br/><img src={useBaseUrl('img/search/get-started-search/reject-deletion-request.png')} alt="Reject deletion requests pop-up" style={{border: '1px solid gray'}} width="400"/>
114+
91115
## Limitations
92116

93117
- Deletion requests will be processed one by one.
94118
- You can create upto 100 deletion requests at a time.
95119
- Each deletion request can include up to 1 petabyte (PB) of scanned data.
96-
- You can delete up to 1,000,000 messages per request.
120+
- You can delete up to 1,000,000 messages per request.
97121
- The maximum time range for each deletion request is one year.
98122
- Your system can support up to 10 active concurrent deletion tasks across different customers.
99123
- Ensure that the requests initiated are not deleting the data prior to `1st February 2024`. Any request before this timestamp will fail in creation.
@@ -106,7 +130,7 @@ Customers must manage the future ingestion of sensitive data using [processing r
106130

107131
### Deletion scope
108132

109-
Deletion is restricted to partitions and the default view (sumologic_default) in Sumo Logic. Deletion is currently not supported for other view types, such as [Scheduled Views](/docs/manage/scheduled-views) or ad hoc views created using the save view operator. Sensitive data may still be present in these unsupported views.
133+
Deletion is restricted to [Partitions](/docs/manage/partitions/), Default view (sumologic_default), [Scheduled Views](/docs/manage/scheduled-views), [Scheduled Search](/docs/alerts/scheduled-searches/), and ad hoc views in Sumo Logic. Deletion is currently not supported for audit indexes, security indexes, and other view types. Sensitive data may still be present in these unsupported views.
110134

111135
### Supported operators
112136

docs/metrics/metrics-queries/index.md

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -66,4 +66,10 @@ In this section, we'll introduce the following concepts:
6666
<p>Learn how to share a saved or unsaved metric query.</p>
6767
</div>
6868
</div>
69+
<div className="box smallbox card">
70+
<div className="container">
71+
<a href="/docs/metrics/metrics-queries/metric-query-best-practices"><img src={useBaseUrl('img/icons/operations/queries.png')} alt="icon" width="40"/><h4>Metric Query Best Practices</h4></a>
72+
<p>Learn tips for getting the most out of your metric queries.</p>
73+
</div>
74+
</div>
6975
</div>

0 commit comments

Comments
 (0)