Skip to content

Commit 16b281f

Browse files
committed
Merge branch 'main' into DOCS-811
2 parents 66033ac + 1dab0b8 commit 16b281f

File tree

218 files changed

+2751
-2410
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

218 files changed

+2751
-2410
lines changed
File renamed without changes.

blog-collector/2025-05-14.md

Lines changed: 17 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,17 @@
1+
---
2+
title: Version 19.525-42
3+
hide_table_of_contents: true
4+
image: https://help.sumologic.com/img/sumo-square.png
5+
---
6+
7+
import useBaseUrl from '@docusaurus/useBaseUrl';
8+
9+
In this release, we've enhanced the security and stability of the Collector with added support for security patches and a bug fix.
10+
11+
## Security Fix
12+
13+
- Upgraded `com.google.crypto.tink` to version 1.16.0 to address protobuf-java DOS vulnerability (CVE-2024-7254).
14+
15+
## Bug Fix
16+
17+
- Fixed the improper filtering of `AD` objects when `Exclude Distinguished Name Suffixes` filter is configured.

blog-cse/2025-05-09-content.md

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -21,7 +21,6 @@ This release includes:
2121

2222
Changes are enumerated below.
2323

24-
2524
### Rules
2625
- [New] OUTLIER-S00033 AWS DynamoDB Outlier in PutItem Events from User
2726
- [Disabled by Default] This rule detects an unusual amount of PutItem events to a DynamoDB resource within an hour time period (DynamoDB data events are required). Verify the user is authorized to modify the DynamoDB tables and instances. This rule is disabled by default due to potential volume of signals, before enabling consider excluding authorized users via match lists, and adjust floor value and model sensitivity as needed.

blog-service/2025-05-12-apps.md

Lines changed: 12 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,12 @@
1+
---
2+
title: Sysdig Secure (Apps)
3+
image: https://help.sumologic.com/img/sumo-square.png
4+
keywords:
5+
- apps
6+
- sysdig-secure
7+
hide_table_of_contents: true
8+
---
9+
10+
import useBaseUrl from '@docusaurus/useBaseUrl';
11+
12+
We're excited to introduce the new Sysdig Secure app for Sumo Logic. With this app, you can gain real-time insights into vulnerabilities, compliance, and threats, making it easier to understand risks, respond quickly, and maintain continuous security and compliance to protect your containerized environments. [Learn more](/docs/integrations/saas-cloud/sysdig-secure).

blog-service/2025-05-13-apps.md

Lines changed: 12 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,12 @@
1+
---
2+
title: Bitwarden (Apps)
3+
image: https://help.sumologic.com/img/sumo-square.png
4+
keywords:
5+
- apps
6+
- bitwarden
7+
hide_table_of_contents: true
8+
---
9+
10+
import useBaseUrl from '@docusaurus/useBaseUrl';
11+
12+
We're excited to introduce the new Bitwarden app for Sumo Logic. This app enables threat detection and identification of high-risk events such as vault exports or SSO deactivation, supporting continuous monitoring and accelerating incident response for credential and secret management workflows. [Learn more](/docs/integrations/saas-cloud/bitwarden).

cid-redirects.json

Lines changed: 14 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -87,6 +87,7 @@
8787
"/Start_Here/Customize_Your_Sumo_Logic_Experience": "/docs/get-started",
8888
"/Start_Here/Getting_Started": "/docs/get-started",
8989
"/Start_Here/Getting_Started/Analyst_or_Administrator": "/docs/get-started/onboarding-checklists",
90+
"/Start_Here/Getting_Started/Get_Help": "/docs/get-started",
9091
"/Start_Here/Quick_Start_Tutorial": "/docs/get-started/quickstart",
9192
"/Start-Here/09Customize-Your-Sumo-Logic-Experience/Preferences-Page": "/docs/get-started/account-settings-preferences",
9293
"/Start-Here/02Getting-Started/Glossary": "/docs/contributing/glossary",
@@ -443,6 +444,7 @@
443444
"/Search/Live-Tail": "/docs/search/live-tail/about-live-tail",
444445
"/Search/Live-Tail/About-Live-Tail": "/docs/search/live-tail/about-live-tail",
445446
"/Search/Live_Tail/Live_Tail_CLI": "/docs/search/live-tail/live-tail-cli",
447+
"/Search/Live_Tail/About_Live_Tail": "/docs/search/live-tail/about-live-tail",
446448
"/05Search/Live-Tail/Filter-Live-Tail": "/docs/search/live-tail/filter-live-tail",
447449
"/05Search/Live-Tail/Live-Tail-CLI": "/docs/search/live-tail/live-tail-cli",
448450
"/05Search/Live-Tail/Live-Tail-Highlighting": "/docs/search/live-tail/live-tail-highlighting",
@@ -629,6 +631,7 @@
629631
"/05Search/Search-Query-Language/Transaction-Analytics/Transactionize-operator": "/docs/search/search-query-language/transaction-analytics/transactionize-operator",
630632
"/05Search/Subqueries": "/docs/search/subqueries",
631633
"/05Search/Time-Compare": "/docs/search/time-compare",
634+
"/Search/Time_Compare": "/docs/search/time-compare",
632635
"/docs/Time-Compare": "/docs/search/time-compare",
633636
"/07Sumo-Logic-Apps": "/docs/integrations",
634637
"/07Sumo-Logic-Apps/01Amazon_and_AWS/Amazon_Aurora_MySQL_ULM": "/docs/integrations/amazon-aws/rds",
@@ -1445,6 +1448,7 @@
14451448
"/Archive": "/docs/release-notes",
14461449
"/Archive/Collector_Release_Notes_Archive": "/release-notes-collector",
14471450
"/docs/api/collectors": "/docs/api/collector-management",
1451+
"/docs/api/cse": "/docs/api/cloud-siem-enterprise",
14481452
"/docs/api/fields": "/docs/api/field-management",
14491453
"/docs/api/folders": "/docs/api/folder-management",
14501454
"/docs/api/monitors": "/docs/api/monitors-management",
@@ -1632,6 +1636,8 @@
16321636
"/cid/6024": "/docs/integrations/saas-cloud/vmware-workspace-one",
16331637
"/cid/6025": "/docs/integrations/saas-cloud/cisco-vulnerability-management",
16341638
"/cid/6026": "/docs/integrations/saas-cloud/sumo-collection",
1639+
"/cid/6027": "/docs/integrations/saas-cloud/sysdig-secure",
1640+
"/cid/6028": "/docs/integrations/saas-cloud/bitwarden",
16351641
"/cid/10112": "/docs/integrations/app-development/jfrog-xray",
16361642
"/cid/10113": "/docs/observability/root-cause-explorer",
16371643
"/cid/10116": "/docs/manage/fields",
@@ -3587,6 +3593,7 @@
35873593
"/Search/Search_Cheat_Sheets/Search_Operators_Cheat_Sheet": "/docs/search/search-cheat-sheets",
35883594
"/Search/Search_Job_API/Search_Job_API": "/docs/api/search-job",
35893595
"/Search/Search_Optimization": "/docs/search/optimize-search-performance",
3596+
"/Search/Search_Optimization/Field_Extraction": "/docs/api/field-extraction-rules",
35903597
"/Search/Search_Optimization/Scheduled_Views": "/docs/manage/scheduled-views",
35913598
"/Solutions/AWS_Observability_Solution": "/docs/observability",
35923599
"/Send_Data/Sources/03Use_JSON_to_Configure_Sources": "/docs/send-data/use-json-configure-sources",
@@ -3941,12 +3948,14 @@
39413948
"/Search/Search-Query-Language/Search-Operators/filter-operator": "/docs/search/search-query-language/search-operators/filter",
39423949
"/Search/Search-Query-Language/Search-Operators/format": "/docs/search/search-query-language/search-operators/formatdate",
39433950
"/Search/Search_Query_Language/Search_Operators/Geo_Lookup": "/docs/search/search-query-language/search-operators/geo-lookup-map",
3951+
"/Search/Search-Query-Language/Search-Operators/Geo-Lookup-(Map)": "/docs/search/search-query-language/search-operators/geo-lookup-map",
39443952
"/Search/Search_Query_Language/Search_Operators/num": "/docs/search/search-query-language/search-operators/num",
39453953
"/Search/Search_Query_Language/Search_Operators/outlier": "/docs/search/search-query-language/search-operators/outlier",
39463954
"/Search/Search_Query_Language/Search_Operators/where": "/docs/search/search-query-language/search-operators/where",
39473955
"/Search/Search_Query_Language/Transaction_Analytics": "/docs/search/search-query-language/transaction-analytics",
39483956
"/Search/Search_Query_Language/Search_Operators/join": "/docs/search/search-query-language/search-operators/join",
39493957
"/Search/Search_Query_Language/Search_Operators/lookup": "/docs/search/search-query-language/search-operators/lookup",
3958+
"/Search/Search_Query_Language/Search_Operators/smooth": "/docs/search/search-query-language/search-operators/smooth",
39503959
"/Search/Search_Query_Language/Search_Operators/toLowerCase_and_toUpperCase": "/docs/search/search-query-language/search-operators/tolowercase-touppercase",
39513960
"/Search/Search-Cheat-Sheets/General-Search-Examples-Cheat-Sheet": "/docs/search/search-cheat-sheets/general-search-examples",
39523961
"/Search/Search-Cheat-Sheets/Log-Operators-Cheat-Sheet": "/docs/search/search-cheat-sheets/log-operators",
@@ -4001,6 +4010,7 @@
40014010
"/Send_Data/Installed_Collectors/Supporting_Information_for_Collector_Installation/Set_a_Collector_as_Ephemeral": "/docs/send-data/installed-collectors/collector-installation-reference/set-collector-as-ephemeral",
40024011
"/Send_Data/Sources/02Sources_for_Hosted_Collectors/AWS_S3_Source": "/docs/send-data/hosted-collectors/amazon-aws/aws-s3-source",
40034012
"/Send_Data/Sources/02Sources_for_Hosted_Collectors/AWS_IP_Address_Range": "/docs/send-data/hosted-collectors/amazon-aws",
4013+
"/Send_Data/Sources/02Sources_for_Hosted_Collectors/Grant_Access_to_an_AWS_S3_Bucket": "/docs/send-data/hosted-collectors/amazon-aws/grant-access-aws-product",
40044014
"/Send_Data/Sources/02Sources_for_Hosted_Collectors/HTTP_Source": "/docs/send-data/hosted-collectors/http-source",
40054015
"/Send_Data/Sources/02Sources_for_Hosted_Collectors/Cloud_Syslog_Source": "/docs/send-data/hosted-collectors/cloud-syslog-source",
40064016
"/Send_Data/Sources/HTTP_Source": "/docs/send-data/hosted-collectors/http-source",
@@ -4067,6 +4077,7 @@
40674077
"/Send-Data/Data-Types/Docker": "/docs/send-data/installed-collectors/sources/docker-sources",
40684078
"/Send-Data/Data-Types/Docker/Docker-App-Dashboards": "/docs/integrations/containers-orchestration/docker-ulm",
40694079
"/Send-Data/Data-Types/Docker/02-Install-the-Docker-App": "/docs/integrations/containers-orchestration/docker-ulm",
4080+
"/Send-Data/Data-Types/Linux": "/docs/send-data/installed-collectors/linux",
40704081
"/Send-Data/Data-Types/Threat_Intel_Quick_Analysis/Threat_Intel_Optimization": "/docs/integrations/security-threat-detection/threat-intel-quick-analysis",
40714082
"/Send-Data/Data_Types/Salesforce": "/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/salesforce-source",
40724083
"/Send-Data/01-Design-Your-Deployment/Best-Practices:-Good-Source-Category,-Bad-Source-Category": "/docs/send-data/best-practices",
@@ -4284,8 +4295,9 @@
42844295
"/docs/cse/automation-service/automation-service-bridge": "/docs/platform-services/automation-service/automation-service-bridge",
42854296
"/docs/cloud-soar/cloud-soar-bridge": "/docs/platform-services/automation-service/automation-service-bridge",
42864297
"/docs/cloud-soar/audit-event-index": "/docs/platform-services/automation-service/automation-service-audit-logging/",
4287-
"/docs/cse/automation-service/automation-service-integration-framework": "/docs/platform-services/automation-service/automation-service-integration-framework",
4288-
"/docs/cloud-soar/cloud-soar-integration-framework": "/docs/platform-services/automation-service/automation-service-integration-framework",
4298+
"/docs/cse/automation-service/automation-service-integration-framework": "/docs/platform-services/automation-service/integration-framework",
4299+
"/docs/cloud-soar/cloud-soar-integration-framework": "/docs/platform-services/automation-service/integration-framework",
4300+
"/docs/platform-services/automation-service/automation-service-integration-framework": "/docs/platform-services/automation-service/integration-framework",
42894301
"/docs/send-data/collect-from-other-data-sources/kubernetes": "/docs/send-data/kubernetes",
42904302
"/docs/send-data/kubernetes/v4": "/docs/send-data/kubernetes",
42914303
"/docs/send-data/collect-from-other-data-sources/azure-blob-storage/collect-logs-azure-blob-storage": "/docs/send-data/collect-from-other-data-sources/azure-blob-storage/block-blob/collect-logs",

docs/cloud-soar/automation.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -20,7 +20,7 @@ Because Cloud SOAR provides automation functionality to the [Automation Service]
2020
* [Playbooks](/docs/platform-services/automation-service/automation-service-playbooks/)
2121
* [Integrations](/docs/platform-services/automation-service/automation-service-integrations/)
2222
* [Automation bridge](/docs/platform-services/automation-service/automation-service-bridge)
23-
* [Integration framework](/docs/platform-services/automation-service/automation-service-integration-framework/)
23+
* [Integration framework](/docs/platform-services/automation-service/integration-framework/)
2424
* [Audit logging](/docs/platform-services/automation-service/automation-service-audit-logging)
2525

2626
The following sections describe automation features only used in Cloud SOAR.

docs/cloud-soar/compared-to-automation-service.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -21,7 +21,7 @@ The Automation Service doesn't include any of Cloud SOAR’s case management or
2121

2222
### Daemon and trigger action types
2323

24-
The Automation Service does not support [daemon](/docs/platform-services/automation-service/automation-service-integration-framework/#daemon-action-definitions) and [trigger](/docs/platform-services/automation-service/automation-service-integration-framework/#trigger-action-definitions) action types. The Automation Service can only use triggers built into Cloud SIEM and the Log Analytics platform. So you can’t configure a playbook in the Automation Service to monitor an external process or file and fire a trigger in response like you can with Cloud SOAR. A trigger can only fire in the Automation Service for limited events, such as when an Insight is created in Cloud SIEM.
24+
The Automation Service does not support [daemon](/docs/platform-services/automation-service/integration-framework/about-integration-framework/#daemon-action-definitions) and [trigger](/docs/platform-services/automation-service/integration-framework/about-integration-framework/#trigger-action-definitions) action types. The Automation Service can only use triggers built into Cloud SIEM and the Log Analytics platform. So you can’t configure a playbook in the Automation Service to monitor an external process or file and fire a trigger in response like you can with Cloud SOAR. A trigger can only fire in the Automation Service for limited events, such as when an Insight is created in Cloud SIEM.
2525

2626
### Additional features
2727

docs/cloud-soar/introduction.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -409,7 +409,7 @@ Within Automation, you’ll see subsections for:
409409
* [App Central](/docs/platform-services/automation-service/app-central/). A large out-of-the-box library of playbooks, integrations, and use cases for different threats to get you started with orchestrating and automating your SOC.
410410
* [Playbooks](/docs/platform-services/automation-service/automation-service-playbooks/). Allows you to create new playbooks and edit, delete, and manage existing ones.
411411
* [Template](/docs/cloud-soar/automation/#incident-templates). Allows you to create new incident templates and edit, delete, and manage existing ones.
412-
* [Integrations](/docs/platform-services/automation-service/automation-service-integration-framework/). Lets you connect third party tools through APIs.
412+
* [Integrations](/docs/platform-services/automation-service/automation-service-integrations/). Lets you connect third party tools through APIs.
413413
* [Rules](/docs/cloud-soar/automation/#automation-rules). Lets you create new automation rules.
414414
* [Bridge](/docs/platform-services/automation-service/automation-service-bridge/). Contains configuration details on any installed bridges.
415415

docs/cloud-soar/overview.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -62,7 +62,7 @@ Gain complete insight into incident response performance with customizable dashb
6262

6363
### Open Integration Framework (OIF)
6464

65-
Choose from hundreds of out-of-the-box actions and playbooks or ask the Sumo Logic team to develop the connectors you need. Anyone can access the API code to quickly integrate tools without any coding experience required. For more information, see [Integrations](/docs/platform-services/automation-service/automation-service-integrations/) and [Integration Framework](/docs/platform-services/automation-service/automation-service-integration-framework/).
65+
Choose from hundreds of out-of-the-box actions and playbooks or ask the Sumo Logic team to develop the connectors you need. Anyone can access the API code to quickly integrate tools without any coding experience required. For more information, see [Integrations](/docs/platform-services/automation-service/automation-service-integrations/) and [Integration Framework](/docs/platform-services/automation-service/integration-framework/).
6666

6767
<img src={useBaseUrl('img/cloud-soar/overview-openI-itegration.png')} alt="Integrations" style={{border: '1px solid gray'}} width="800" />
6868

0 commit comments

Comments
 (0)