Skip to content

Commit 17a2aee

Browse files
authored
Merge branch 'main' into crowdstrike_alerts
2 parents f7f1b04 + 3fc6f73 commit 17a2aee

File tree

125 files changed

+4967
-2731
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

125 files changed

+4967
-2731
lines changed

.clabot

Lines changed: 1 addition & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -5,13 +5,9 @@
55
"JV0812",
66
"jpipkin1",
77
"JainM6",
8-
"swiatekm-sumo",
98
"docsSeema",
10-
"@dependabot[bot]",
11-
"dependabot[bot]",
129
"angadrandhawa1",
1310
"kkujawa-sumo",
14-
"open-source-collection-team",
1511
"mat-rumian",
1612
"perk-sumo",
1713
"jmartini-sumo",
@@ -28,12 +24,10 @@
2824
"agaur",
2925
"bhargavisumo",
3026
"ravipadala-sumo",
31-
"jd-sumo",
3227
"davidcarltonsumo",
3328
"pkazmir-sumo",
3429
"dkarabin-sumo",
3530
"kevin-sumo",
36-
"mgol-sumo",
3731
"crm6718",
3832
"mvirga-sumo",
3933
"tarunk2",
@@ -176,7 +170,7 @@
176170
"antonymartinsumo",
177171
"amee-sumo"
178172
],
179-
"message": "Thank you for your contribution! As this is an open source project, we require contributors to sign our Contributor License Agreement and do not have yours on file. To proceed with your PR, please [sign your name here](https://forms.gle/YgLddrckeJaCdZYA6) and we'll add you to our approved list of contributors.",
173+
"message": "Thank you for your contribution! As this is an open source project, we require contributors to sign our Contributor License Agreement and do not have yours on file. To proceed with your PR, please [sign your name here](https://forms.gle/YgLddrckeJaCdZYA6) and we will add you to our approved list of contributors.",
180174
"label": "cla-signed",
181175
"recheckComment": "The GitHub CLA Bot is rechecking to see that you have signed our CLA."
182176
}

.github/CODEOWNERS

Lines changed: 7 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -1,14 +1,16 @@
1+
# More details: https://help.github.com/articles/about-codeowners
2+
13
# Default owners for everything in the repo.
2-
* @kimsauce @jpipkin1 @JV0812 @mafsumo
4+
* @kimsauce @jpipkin1 @JV0812 @mafsumo @amee-sumo
35

4-
# Owners of all files in the `/docs` directory and its subdirectories.
5-
/docs/ @kimsauce @jpipkin1 @JV0812 @mafsumo
6+
# Owners of all files in the `/docs/integrations` directory.
7+
/docs/integrations/ @SumoLogic/sumoappdev @kimsauce @jpipkin1 @JV0812 @mafsumo @amee-sumo
68

79
# Owners of all files in the `/docs/send-data/kubernetes` directory.
8-
/docs/send-data/kubernetes/ @SumoLogic/open-source-collection-team @kimsauce @jpipkin1 @JV0812 @mafsumo
10+
/docs/send-data/kubernetes/ @SumoLogic/open-source-collection-team @SumoLogic/k8s-developers @kimsauce @jpipkin1 @JV0812 @mafsumo @amee-sumo
911

1012
# Owners of all files in the `/docs/send-data/opentelemetry-collector` directory and its subdirectories.
11-
/docs/send-data/opentelemetry-collector/ @SumoLogic/open-source-collection-team @kimsauce @jpipkin1 @mafsumo @JV0812
13+
/docs/send-data/opentelemetry-collector/ @SumoLogic/open-source-collection-team @kimsauce @jpipkin1 @mafsumo @JV0812 @amee-sumo
1214

1315
# GitHub workflow owners
1416
/.github/workflows/ @SumoLogic/open-source-collection-team @kimsauce

blog-collector/2024-11-26.md

Lines changed: 25 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,25 @@
1+
---
2+
title: Version 19.516-1
3+
hide_table_of_contents: true
4+
image: https://help.sumologic.com/img/sumo-square.png
5+
---
6+
7+
import useBaseUrl from '@docusaurus/useBaseUrl';
8+
9+
<a href="https://help.sumologic.com/release-notes-collector/rss.xml"><img src={useBaseUrl('img/release-notes/rss-orange2.png')} alt="icon" width="50"/></a>
10+
11+
In this release, we've enhanced the security and stability of the Collector with added support for security patches.
12+
13+
### Security Fixes
14+
15+
- Upgraded `Tanuki version` to version 3.5.60 to fix the collector intermittently crashing issue.
16+
- Upgraded collector JRE to **Amazon Corretto Version 8.432.06.1**.
17+
18+
### Troubleshooting
19+
20+
When upgrading this collector version, the collector running as a non-root user (run as mode) or on a Mac operating system cannot be upgraded through the API/Web UI. To resolve these issue, follow the respective steps below:
21+
- **Collector running as a non-root user.** An error message will be displayed indicating that the upgrade is not possible. The upgrade must be performed manually on your machine. Refer to [Upgrade Collectors in Sumo Logic](/docs/send-data/collection/upgrade-collectors/#upgrade-collectors-using-the-command-line) to upgrade the collector manually.
22+
- **Collector running on Mac.** The process will stop while upgrading, and the collector will need to be restarted manually on your machine. Use the code below to restart manually.
23+
```
24+
sudo ./collector start
25+
```

blog-cse/2023/12-31.md

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -247,8 +247,6 @@ The new index is automatically generated and retained for a period of 2 years at
247247

248248
As a result, the optional legacy Signal Forwarding feature in Cloud SIEM will be deprecated on **November 15, 2023**. Existing data will not be deleted, but new Signals generated after that date will no longer be forwarded using that feature and the option will no longer be available. (Signals will continue to be forwarded automatically to `sec_signal`.) Customers leveraging data forwarded using the legacy feature to generate dashboards (or for other use cases) will need to modify those applications to use the new `sec_signal` index before then. Note that the content of the `sec_signal` index is not identical to the content in data forwarded using the legacy option.
249249

250-
For more information about this change, and the differences between the two data sets, refer to our [2023 Cloud SIEM Signal Index Migration FAQ](/docs/cse/records-signals-entities-insights/signal-index-migration-faq/).
251-
252250

253251

254252
---

blog-cse/2024-11-22-content.md

Lines changed: 61 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,61 @@
1+
---
2+
title: November 22, 2024 - Content Release
3+
hide_table_of_contents: true
4+
keywords:
5+
- log mappers
6+
- log parsers
7+
- detection rules
8+
- tag schemas
9+
image: https://help.sumologic.com/img/sumo-square.png
10+
---
11+
12+
import useBaseUrl from '@docusaurus/useBaseUrl';
13+
14+
<a href="https://help.sumologic.com/release-notes-cse/rss.xml"><img src={useBaseUrl('img/release-notes/rss-orange2.png')} alt="icon" width="50"/></a>
15+
16+
This content release includes:
17+
* New mapping support for: Qumulo Core, and Teramind Teraserver.
18+
* Updates to existing parsers for: Code42 Incydr, Palo Alto, and Okta.
19+
* Updates to the existing Okta log mappings to support a new HTTP source log formatting.
20+
* Updates to Code42 Incydr Alerts C2C mapping to support new alert log format.
21+
22+
Changes are enumerated below.
23+
24+
### Rules
25+
* [Deleted] FIRST-S00031 First Seen IP Address Associated with User for a Successful Azure AD Sign In Event
26+
* Consider using FIRST-S00047 (First Seen ASN Associated with User for a Successful Azure AD Sign In Event) in its place.
27+
* [New] THRESHOLD-S00116 Password Attack from IP
28+
* This is a fork of THRESHOLD-S00095 Password Attack to address a bug with null values causing backend issues with detection rules. Rule has been forked to ensure no null values are considered in the entity grouping.
29+
* [Updated] FIRST-S00095 Password Attack from Host
30+
* Updates rule to remove IP entity (now handled in THRESHOLD-S00116) and ensure no null values are considered for the host entity.
31+
* [Updated] FIRST-S00068 Okta - First Seen User Accessing Admin Application
32+
* Baseline retention window size increased from 35 days to the standard 90 day retention.
33+
* Modified the summary description to read as follows: "User: `{{user_username}}` has successfully accessed the Okta Admin Application".
34+
35+
### Log Mappers
36+
* [New] Palo Alto Threat DLP non File - Custom Parser
37+
* Mapping support added for event id pattern: threat-dlp-non-file.
38+
* [New] Qumulo Core - Catch All
39+
* [New] Qumulo Core - Login
40+
* [New] Teramind Authentication
41+
* [New] Teramind Catch All
42+
* [New] Teramind Email
43+
* [Updated] Code42 Incydr Alerts C2C
44+
* [Updated] Okta Authentication - auth_via_AD_agent
45+
* [Updated] Okta Authentication - auth_via_mfa
46+
* [Updated] Okta Authentication - auth_via_radius
47+
* [Updated] Okta Authentication - sso
48+
* [Updated] Okta Authentication Events
49+
* [Updated] Okta Catch All
50+
* [Updated] Okta Security Threat Events
51+
52+
### Parsers
53+
* [New] /Parsers/System/Qumulo/Qumulo Core
54+
* [New] /Parsers/System/Salesforce/Salesforce
55+
* [New] /Parsers/System/Teramind/Teramind Teraserver
56+
* [Updated] /Parsers/System/Code42/Code42 Incydr
57+
* Transform update for a new alert log format for tenantId.
58+
* [Updated] /Parsers/System/Okta/Okta
59+
* Modified event_id from eventType to event_type.
60+
* [Updated] /Parsers/System/Palo Alto/PAN Firewall CSV
61+
* Additional parsing support for a new Palo Alto Threat event format.

blog-csoar/2024-11-20-content.md

Lines changed: 46 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,46 @@
1+
---
2+
title: November 20, 2024 - Content Release
3+
hide_table_of_contents: true
4+
image: https://help.sumologic.com/img/sumo-square.png
5+
keywords:
6+
- automation service
7+
- cloud soar
8+
- soar
9+
---
10+
11+
import useBaseUrl from '@docusaurus/useBaseUrl';
12+
13+
<a href="https://help.sumologic.com/release-notes-csoar/rss.xml"><img src={useBaseUrl('img/release-notes/rss-orange2.png')} alt="icon" width="50"/></a>
14+
15+
This release introduces new integrations, new playbooks, and several updates.
16+
17+
### Integrations
18+
19+
* [New] [Google Chat](/docs/platform-services/automation-service/app-central/integrations/google-chat)
20+
* [New] [Malwarebytes Oneview](/docs/platform-services/automation-service/app-central/integrations/malwarebytes-oneview)
21+
* [New] [Silent Push](/docs/platform-services/automation-service/app-central/integrations/silent-push)
22+
* [New] [Sumo Logic Automation Tools](/docs/platform-services/automation-service/app-central/integrations/sumo-logic-automation-tools)
23+
* [New] [VirusTotal V3](/docs/platform-services/automation-service/app-central/integrations/virustotal-v3)
24+
* [Updated] [APIVoid](/docs/platform-services/automation-service/app-central/integrations/apivoid)
25+
* [Updated] [Atlassian Jira V2](/docs/platform-services/automation-service/app-central/integrations/atlassian-jira-v2)
26+
* [Updated] [Atlassian Opsgenie](/docs/platform-services/automation-service/app-central/integrations/atlassian-opsgenie)
27+
* [Updated] [AWS EC2](/docs/platform-services/automation-service/app-central/integrations/aws-ec2)
28+
* [Updated] [AWS EKS](/docs/platform-services/automation-service/app-central/integrations/aws-eks)
29+
* [Updated] [Azure AD](/docs/platform-services/automation-service/app-central/integrations/azure-ad)
30+
* [Updated] [Cloudflare](/docs/platform-services/automation-service/app-central/integrations/cloudflare)
31+
* [Updated] [ConnectWise Manage](/docs/platform-services/automation-service/app-central/integrations/connectwise-manage)
32+
* [Updated] [Cortex XDR](/docs/platform-services/automation-service/app-central/integrations/cortex-xdr)
33+
* [Updated] [CrowdStrike Falcon](/docs/platform-services/automation-service/app-central/integrations/crowdstrike-falcon)
34+
* [Updated] [Freshservice](/docs/platform-services/automation-service/app-central/integrations/freshservice)
35+
* [Updated] [Gmail](/docs/platform-services/automation-service/app-central/integrations/gmail)
36+
* [Updated] [HTTP Tools](/docs/platform-services/automation-service/app-central/integrations/http-tools)
37+
* [Updated] [IBM X-Force Exchange](/docs/platform-services/automation-service/app-central/integrations/ibm-x-force-exchange)
38+
* [Updated] [Microsoft EWS](/docs/platform-services/automation-service/app-central/integrations/microsoft-ews)
39+
* [Updated] [Microsoft OneDrive](/docs/platform-services/automation-service/app-central/integrations/microsoft-onedrive)
40+
* [Updated] [Microsoft Sentinel](/docs/platform-services/automation-service/app-central/integrations/microsoft-sentinel)
41+
* [Updated] [Netskope V2](/docs/platform-services/automation-service/app-central/integrations/netskope-v2)
42+
* [Updated] [Slack](/docs/platform-services/automation-service/app-central/integrations/slack)
43+
* [Updated] [Sumo Logic Cloud SIEM](/docs/platform-services/automation-service/app-central/integrations/sumo-logic-cloud-siem)
44+
* [Updated] [Sumo Logic Notifications by Gmail](/docs/platform-services/automation-service/app-central/integrations/sumo-logic-notifications-by-gmail)
45+
* [Updated] [URLScan.io](/docs/platform-services/automation-service/app-central/integrations/urlscan.io)
46+
* [Updated] [VirusTotal](/docs/platform-services/automation-service/app-central/integrations/virustotal)
Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,14 @@
1+
---
2+
title: Trend Micro C2C Source (Collection)
3+
image: https://help.sumologic.com/img/sumo-square.png
4+
keywords:
5+
- collection
6+
- trend-micro
7+
hide_table_of_contents: true
8+
---
9+
10+
import useBaseUrl from '@docusaurus/useBaseUrl';
11+
12+
<a href="https://help.sumologic.com/release-notes-service/rss.xml"><img src={useBaseUrl('img/release-notes/rss-orange2.png')} alt="icon" width="50"/></a>
13+
14+
We're excited to announce the release of our new cloud-to-cloud source for Trend Micro. This source helps you to collect alert details from the Trend Micro platform, and ingest them into Sumo Logic for streamlined analysis. [Learn more](/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/trend-micro-source).

cid-redirects.json

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -2004,6 +2004,8 @@
20042004
"/cid/10220": "/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/code42-incydr-source",
20052005
"/cid/25618": "/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/cse-aws-ec-inventory-source",
20062006
"/cid/25619": "/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/cybereason-source",
2007+
"/cid/25779": "/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/mandiant-threat-intel-source",
2008+
"/cid/25719": "/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/trend-micro-source",
20072009
"/cid/25620": "/docs/integrations/security-threat-detection/duo-security",
20082010
"/cid/25621": "/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/microsoft-graph-security-api-source",
20092011
"/cid/25622": "/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/mimecast-source",
@@ -2636,6 +2638,7 @@
26362638
"/cid/16323": "/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/druva-source",
26372639
"/cid/13428": "/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/kandji-source",
26382640
"/cid/17343": "/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/automox-source",
2641+
"/cid/17344": "/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/smartsheet-source",
26392642
"/cid/20172": "/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/cisco-vulnerability-management-source",
26402643
"/cid/19880": "/docs/metrics/metrics-operators/predict",
26412644
"/cid/19881": "/docs/metrics/metrics-operators/accum",

docs/alerts/monitors/create-monitor.md

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -370,7 +370,9 @@ If your data is coming from the [Amazon CloudWatch Source for Metrics](/docs/s
370370

371371
## Step 3. Notifications (optional)
372372

373-
Configure who gets notified when the monitor triggers an alert. When a trigger condition is met, you can send notifications to other people and services. Metrics monitors have an option to send notifications either as a group or separately. **Group Notifications** define whether you want single notifications per time series that match the Monitor query or you want group notifications where you receive a single notification for the entire Monitor. Log monitors always group notifications.
373+
Configure who gets notified when the monitor triggers an alert. When a trigger condition is met, you can send notifications to other people and services.
374+
375+
Notifications will be sent when the monitor is triggered as configured in the [Alert Grouping](/docs/alerts/monitors/alert-grouping/) section of the monitor.
374376

375377
<img src={useBaseUrl('img/alerts/monitors/new-monitor-notifications.png')} alt="Screenshot of the Notifications section in Sumo Logic's 'New Monitor' setup page. It includes an option to select the preferred notification time zone, set to (GMT-06:00) America/Chicago. Below is a section to configure connection types for notifications, with options for Critical, Alert, Recovery, Warning, and Missing Data. There is also a button to add a new notification." style={{border: '1px solid gray'}} width="800"/>
376378

docs/alerts/monitors/settings.md

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -116,9 +116,10 @@ Click the **Mute** button mute the monitor. See also: [Muting Schedules](/docs/
116116
Click the **More Actions** menu to view more options, including:
117117

118118
* **Copy Path**. Copies the path of the monitor to your computer clipboard.
119-
* **Duplicate**. Makes another monitor based on the same settings.
119+
* **Duplicate**. Copies the monitor and gives you creator permissions on the duplicated monitor.
120120
* **Move**. Moves the monitor to a different path.
121121
* **Export**. Provides JSON of the monitor, allowing you to transfer content within Sumo Logic by copying this JSON, then pasting it into the import dialog in the [Library](/docs/get-started/library) location you choose. This JSON format may change without notice. 
122+
* **Copy Link**. Copies a link to the monitor. Provide the link to any Sumo Logic user in your organization so they can view the monitor. While this option doesn't allow you to share the monitor in the same way you can share a dashboard, you can use this option to quickly allow others in your Sumo Logic organization to view the monitor details.
122123

123124
<img src={useBaseUrl('img/alerts/monitors/more-actions.png')} alt="monitor more actions" style={{border: '1px solid gray'}} width="600"/>
124125

0 commit comments

Comments
 (0)