Skip to content

Commit 18e8b0e

Browse files
authored
Merge branch 'main' into docs-1285-list-page-release-note
2 parents d5189f3 + a7e8682 commit 18e8b0e

File tree

43 files changed

+635
-143
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

43 files changed

+635
-143
lines changed

.github/workflows/job_trigger-jenkins-pipeline.yml

Lines changed: 9 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -15,26 +15,28 @@ on:
1515
required: true
1616
WEBOPS_JENKINS_HOST:
1717
required: true
18-
WEBOPS_AWS_ACCESS_KEY:
19-
required: true
20-
WEBOPS_AWS_SECRET_KEY:
18+
WEBOPS_AWS_ROLE_JENKINS:
2119
required: true
2220
WEBOPS_WEBHOOK_TOKEN:
2321
required: true
2422

2523
jobs:
2624
trigger-jenkins-pipeline:
2725
runs-on: ubuntu-latest
26+
permissions:
27+
id-token: write
28+
contents: read
2829
steps:
2930
- name: Get runner IP
3031
if: always()
3132
id: ip
3233
uses: haythem/[email protected]
34+
- name: Configure AWS credentials
35+
uses: aws-actions/configure-aws-credentials@00943011d9042930efac3dcd3a170e4273319bc8
36+
with:
37+
role-to-assume: ${{ secrets.WEBOPS_AWS_ROLE_JENKINS }}
38+
aws-region: us-east-1
3339
- name: Add runner to AWS security group ingress
34-
env:
35-
AWS_ACCESS_KEY_ID: ${{ secrets.WEBOPS_AWS_ACCESS_KEY }}
36-
AWS_SECRET_ACCESS_KEY: ${{ secrets.WEBOPS_AWS_SECRET_KEY }}
37-
AWS_DEFAULT_REGION: ${{ secrets.WEBOPS_AWS_REGION }}
3840
run: aws ec2 authorize-security-group-ingress --group-name ${{ secrets.WEBOPS_AWS_SG_NAME }} --protocol tcp --port ${{ secrets.WEBOPS_JENKINS_PORT }} --cidr ${{ steps.ip.outputs.ipv4 }}/32
3941
- name: Trigger Jenkins pipeline
4042
run: |
@@ -43,9 +45,5 @@ jobs:
4345
-X POST \
4446
${{ secrets.WEBOPS_JENKINS_HOST }}:${{ secrets.WEBOPS_JENKINS_PORT || '80' }}/generic-webhook-trigger/invoke?token=${{ secrets.WEBOPS_WEBHOOK_TOKEN }}
4547
- name: Remove runner from AWS security group ingress
46-
env:
47-
AWS_ACCESS_KEY_ID: ${{ secrets.WEBOPS_AWS_ACCESS_KEY }}
48-
AWS_SECRET_ACCESS_KEY: ${{ secrets.WEBOPS_AWS_SECRET_KEY }}
49-
AWS_DEFAULT_REGION: ${{ secrets.WEBOPS_AWS_REGION }}
5048
if: always()
5149
run: aws ec2 revoke-security-group-ingress --group-name ${{ secrets.WEBOPS_AWS_SG_NAME }} --protocol tcp --port ${{ secrets.WEBOPS_JENKINS_PORT }} --cidr ${{ steps.ip.outputs.ipv4 }}/32

.github/workflows/workflow_deploy-to-pantheon-prod.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -2,6 +2,7 @@ name: Deploy to production
22

33
permissions:
44
contents: write
5+
id-token: write
56

67
on:
78
push:
@@ -38,8 +39,7 @@ jobs:
3839
WEBOPS_AWS_SG_NAME: ${{ secrets.WEBOPS_AWS_SG_NAME }}
3940
WEBOPS_JENKINS_PORT: ${{ secrets.WEBOPS_JENKINS_PORT }}
4041
WEBOPS_JENKINS_HOST: ${{ secrets.WEBOPS_JENKINS_HOST }}
41-
WEBOPS_AWS_ACCESS_KEY: ${{ secrets.WEBOPS_AWS_ACCESS_KEY }}
42-
WEBOPS_AWS_SECRET_KEY: ${{ secrets.WEBOPS_AWS_SECRET_KEY }}
42+
WEBOPS_AWS_ROLE_JENKINS: ${{ secrets.WEBOPS_AWS_ROLE_JENKINS }}
4343
WEBOPS_WEBHOOK_TOKEN: ${{ secrets.WEBOPS_WEBHOOK_TOKEN }}
4444
notify-channel:
4545
needs: [build-site,deploy-to-pantheon,trigger-jenkins-pipeline]

blog-cse/2025-12-05-content.md

Lines changed: 96 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,96 @@
1+
---
2+
title: December 05, 2025 - Content Release
3+
image: https://assets-www.sumologic.com/company-logos/_800x418_crop_center-center_82_none/SumoLogic_Preview_600x600.jpg?mtime=1617040082
4+
keywords:
5+
- log mappers
6+
- parsers
7+
- rules
8+
hide_table_of_contents: true
9+
---
10+
11+
This new and updated content is effective as of December 4, 2025.
12+
13+
This content release includes:
14+
- Updates to product naming from "G Suite" to "Google Workspace" across rules, log mappers, and parsers to reflect the current branding.
15+
- Update to product naming from "Dell SonicWall" to "SonicWall Firewall" in parsers and log mappers.
16+
- New support for Asana audit logging.
17+
18+
Additional changes are enumerated below.
19+
20+
## Rules
21+
- [Updated] MATCH-S00630 GCP Audit IAM DeleteServiceAccount Observed
22+
- [Updated] MATCH-S00629 GCP Audit IAM DisableServiceAccount Observed
23+
- [Updated] MATCH-S00117 Google Workspace - Access - Access Transparency
24+
- [Updated] MATCH-S00115 Google Workspace - Admin - User Settings - Turn Off 2SV
25+
- [Updated] MATCH-S00133 Google Workspace - Admin Activity
26+
- [Updated] MATCH-S00125 Google Workspace - Drive - Drive Open To Public
27+
- [Updated] MATCH-S00301 Google Workspace - Excessive OAuth Application Permissions Scope
28+
- [Updated] MATCH-S00128 Google Workspace - Login - Account Warning
29+
- [Updated] MATCH-S00129 Google Workspace - Login - Government Attack Warning
30+
- [Updated] MATCH-S00121 Google Workspace - Mobile - Suspicious Activity
31+
- [Updated] MATCH-S00227 Google Workspace - Unauthorized OAuth Application
32+
- [Updated] MATCH-S00120 Google Workspace - User Accounts - 2SV Disabled
33+
34+
## Log Mappers
35+
- [New] Asana Audit Authentication
36+
- [New] Asana Audit Catch All
37+
- [Updated] Azure ResourceHealth and ServiceHealth
38+
- [Updated] AzureActivityLog AuditLogs
39+
- [Updated] Google Workspace - access_transparency/GSUITE_RESOURCE/ACCESS
40+
- [Updated] Google Workspace - admin
41+
- [Updated] Google Workspace - calendar
42+
- [Updated] Google Workspace - drive.access
43+
- [Updated] Google Workspace - drive.acl_change
44+
- [Updated] Google Workspace - gcp
45+
- [Updated] Google Workspace - gplus
46+
- [Updated] Google Workspace - groups
47+
- [Updated] Google Workspace - groups_enterprise
48+
- [Updated] Google Workspace - login - password_change/recovery_info_change
49+
- [Updated] Google Workspace - login - risky_sensitive_action_allowed
50+
- [Updated] Google Workspace - login challenge
51+
- [Updated] Google Workspace - login-blocked_sender_change
52+
- [Updated] Google Workspace - login-email_forwarding_change
53+
- [Updated] Google Workspace - login.account_warning
54+
- [Updated] Google Workspace - login.gov_attack_warning
55+
- [Updated] Google Workspace - login.login
56+
- [Updated] Google Workspace - logout
57+
- [Updated] Google Workspace - meet
58+
- [Updated] Google Workspace - mobile
59+
- [Updated] Google Workspace - rules
60+
- [Updated] Google Workspace - saml
61+
- [Updated] Google Workspace - token
62+
- [Updated] Google Workspace - user_accounts
63+
- [Updated] Google Workspace Alert Center - AppMaker Editor
64+
- [Updated] Google Workspace Alert Center - Data Loss Prevention
65+
- [Updated] Google Workspace Alert Center - Domain wide takeout
66+
- [Updated] Google Workspace Alert Center - Gmail phishing
67+
- [Updated] Google Workspace Alert Center - Gmail phishing (Misconfigured whitelist)
68+
- [Updated] Google Workspace Alert Center - Google Operations
69+
- [Updated] Google Workspace Alert Center - Google identity
70+
- [Updated] Google Workspace Alert Center - Mobile device management (Device compromised)
71+
- [Updated] Google Workspace Alert Center - Mobile device management (Suspicious activity)
72+
- [Updated] Google Workspace Alert Center - Security Center rules
73+
- [Updated] Google Workspace Alert Center - Sensitive Admin Action
74+
- [Updated] Google Workspace Alert Center - State Sponsored Attack
75+
- [Updated] Google Workspace Alert Center - User Changes
76+
- [Updated] Netskope - Alerts
77+
- Updated action and normalizedAction field mappings.
78+
- [Updated] SonicWall Firewall - Custom Parser
79+
- [Updated] SonicWall Flows
80+
- [Updated] Thinkst Canary Parser - Catch All
81+
- Added additional field mappings.
82+
- [Updated] Windows - Security - 5145
83+
- Removes redundant mapping of `baseimage` and `device_ip` fields.
84+
85+
## Parsers
86+
- [New] /Parsers/System/Asana/Asana Audit
87+
- [New] /Parsers/System/Google/Google Workspace Alert Center
88+
- [New] /Parsers/System/Google/Google Workspace Audit
89+
- [New] /Parsers/System/SonicWall/SonicWall Firewall
90+
- [Updated] /Parsers/System/Dell/Dell SonicWall
91+
- [Updated] /Parsers/System/Google/G Suite Alert Center
92+
- [Updated] /Parsers/System/Google/G Suite Audit
93+
- [Updated] /Parsers/System/Linux/Linux OS Syslog
94+
- Updated parser to drop certain systemd events not useful for security monitoring.
95+
- [Updated] /Parsers/System/Thinkst Canary/Thinkst Canary
96+
- Modified parser to improve field extraction.
Lines changed: 47 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,47 @@
1+
---
2+
title: December 9, 2025 - Application Update
3+
hide_table_of_contents: true
4+
image: https://assets-www.sumologic.com/company-logos/_800x418_crop_center-center_82_none/SumoLogic_Preview_600x600.jpg?mtime=1617040082
5+
keywords:
6+
- automation service
7+
- cloud soar
8+
---
9+
10+
import useBaseUrl from '@docusaurus/useBaseUrl';
11+
12+
## November release
13+
14+
Following are the updates made in November.
15+
16+
### Changes and enhancements
17+
18+
#### Playbooks
19+
20+
* Added user choice variables that let you retrieve user choice data in subsequent playbook actions in a playbook. [Learn more](/docs/platform-services/automation-service/playbooks/create-playbooks/#user-choice-variables).
21+
* Enhanced the user experience when selecting 'and/or' operators between conditions in both condition and filter nodes.
22+
23+
#### Integrations
24+
25+
* Added new integrations:
26+
* [Google Firebase](/docs/platform-services/automation-service/app-central/integrations/google-firebase/)
27+
* [Monday](/docs/platform-services/automation-service/app-central/integrations/monday/)
28+
* [The Cisco Meraki](/docs/platform-services/automation-service/app-central/integrations/cisco-meraki/) integration has been fully upgraded to align with the latest Meraki Dashboard API (v1) and SDK (v2.0.3).
29+
* Added the Convert Time action to [Sumo Logic Automation Tools](/docs/platform-services/automation-service/app-central/integrations/sumo-logic-automation-tools/).
30+
* In [Microsoft OneDrive](/docs/platform-services/automation-service/app-central/integrations/microsoft-onedrive/) added support for downloading file from site document library using hostname and site name parameters.
31+
32+
33+
### Bug Fixes
34+
35+
#### Playbooks
36+
37+
* Added validation to prevent the creation of condition and filter nodes without defined conditions.
38+
* Updated the condition node to restrict the deletion of all conditions, avoiding the creation of empty nodes.
39+
* Fixed the 'split by' functionality in filter nodes to ensure splitting only occurs with array variables.
40+
41+
#### Integrations
42+
43+
In [Microsoft EWS (Graph)](/docs/platform-services/automation-service/app-central/integrations/microsoft-ews-graph/) fixed an issue in the Search Emails Extended action.
44+
45+
#### Misc
46+
47+
Fixed an issue causing duplicate key errors during incident ownership updates.

cid-redirects.json

Lines changed: 7 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -380,6 +380,7 @@
380380
"/05Search/Library/About_AWS_S3_Sources": "/docs/send-data/hosted-collectors/amazon-aws/aws-sources",
381381
"/05Search/Library/Export-and-Import-Content-in-the-Library": "/docs/get-started/library",
382382
"/05Search/Library/Favorites": "/docs/get-started/library",
383+
"/Search": "/docs/search",
383384
"/Search/Library/Library_Keyboard_Shortcuts": "/docs/get-started/keyboard-shortcuts",
384385
"/05Search/Library/Pinned-Searches": "/docs/search/get-started-with-search/search-page/pin-a-search",
385386
"/05Search/Library/Share-a-Saved-Search-from-the-Library": "/docs/get-started/library",
@@ -1498,7 +1499,7 @@
14981499
"/Dashboards-and-Alerts/Dashboards/Get-Started-with-Dashboards-and-Panels/Markdown-Syntax": "/docs/dashboards/panels/markdown-syntax",
14991500
"/Manage/01Account_Usage": "/docs/manage/manage-subscription",
15001501
"/Manage/Connections-and-Integrations/Webhook-Connections/Set-Up-Webhook-Connections/Webhook_for_Opsgenie": "/docs/integrations/saas-cloud/opsgenie/",
1501-
"/Manage/01Account_Usage/Beta_Participation_Opt-In": "/docs/manage/manage-subscription/beta-opt-in",
1502+
"/Manage/01Account_Usage/Beta_Participation_Opt-In": "/docs/beta",
15021503
"/Manage/Search_Optimization_Tools/Manage_Partitions/Create_a_Partition": "/docs/manage/partitions/",
15031504
"/Manage/01Account_Usage/05Manage_Organization": "/docs/manage/manage-subscription/create-and-manage-orgs/manage-org-settings",
15041505
"/Manage/01Account_Usage/01Cloud_Flex_Credits": "/docs/manage/manage-subscription/sumo-logic-credits-accounts",
@@ -3144,7 +3145,7 @@
31443145
"/Knowledge_Base/Parsing/Using_line_breaks_as_an_anchor_within_parse": "/docs/search/search-query-language/parse-operators/parse-predictable-patterns-using-an-anchor",
31453146
"/Knowledge_Base/Search": "/docs/search",
31463147
"/Knowledge_Base/Search/How_to_Prevent_your_Scheduled_Search_from_Timing_Out": "/docs/alerts/scheduled-searches/faq",
3147-
"/Limited_Availability": "/docs/manage/manage-subscription/beta-opt-in",
3148+
"/Limited_Availability": "/docs/beta",
31483149
"/Limited_Availability/Lookup_Tables": "/docs/search/search-query-language/search-operators/lookupcontains",
31493150
"/Limited_Availability/Lookup_Tables/lookupContains_Operator": "/docs/search/search-query-language/search-operators/lookupcontains",
31503151
"/Manage": "/docs/manage",
@@ -3165,10 +3166,10 @@
31653166
"/Manage/01Manage_Subscription/10Create_and_Manage_Orgs_(Service_Providers)": "/docs/manage/manage-subscription/create-and-manage-orgs/create-manage-orgs-service-providers",
31663167
"/Manage/01Manage_Subscription/Create_and_Manage_Orgs_(Service_Providers)": "/docs/manage/manage-subscription/create-and-manage-orgs/create-manage-orgs-service-providers",
31673168
"/Manage/01Manage_Subscription/12Manage_Organizational_Settings": "/docs/manage/manage-subscription/create-and-manage-orgs/manage-org-settings",
3168-
"/Manage/01Manage_Subscription/13Beta_Participation_Opt-In": "/docs/manage/manage-subscription/beta-opt-in",
3169+
"/Manage/01Manage_Subscription/13Beta_Participation_Opt-In": "/docs/beta",
31693170
"/Manage/Manage_Subscription/Manage_Organizational_Settings": "/docs/manage/manage-subscription/create-and-manage-orgs/manage-org-settings",
31703171
"/Manage/01Manage_Subscription/14What_to_do_if_Your_Account_is_Locked": "/docs/manage/users-roles/users/account-locked",
3171-
"/Manage/01Manage_Subscription/16Beta_Participation_Opt-In": "/docs/manage/manage-subscription/beta-opt-in",
3172+
"/Manage/01Manage_Subscription/16Beta_Participation_Opt-In": "/docs/beta",
31723173
"/Manage/01Manage_Subscription/18Close_or_cancel_a_Sumo_Logic_account": "/docs/manage/manage-subscription/close-cancel-sumo-account",
31733174
"/Manage/01Manage_Subscription/Upgrade_a_Cloudflex_Credits_Free_or_Trial_Account": "/docs/manage/manage-subscription/upgrade-account/upgrade-credits-account",
31743175
"/docs/manage/manage-subscription/upgrade-cloud-flex-credits-account": "/docs/manage/manage-subscription/upgrade-account/upgrade-sumo-logic-flex-account",
@@ -4599,5 +4600,6 @@
45994600
"/docs/get-started/training-certification-faq-new": "/docs/get-started/training-certification-faq",
46004601
"/docs/manage/scheduled-views/pausing-inactive-scheduled-views": "/docs/manage/scheduled-views/pause-disable-scheduled-views",
46014602
"/docs/manage/manage-subscription/create-and-manage-orgs/manage-orgs-for-mssps-csiem-rules": "/docs/manage/manage-subscription/create-and-manage-orgs/manage-orgs-for-mssps",
4602-
"/docs/search/mobot-multiturn-beta": "/docs/search/mobot"
4603+
"/docs/search/mobot-multiturn-beta": "/docs/search/mobot",
4604+
"/docs/manage/manage-subscription/beta-opt-in": "/docs/beta"
46034605
}

docs/beta/index.md

Lines changed: 19 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -9,16 +9,27 @@ import useBaseUrl from '@docusaurus/useBaseUrl';
99

1010
<img src={useBaseUrl('img/icons/business/beta.png')} alt="icon" width="55"/>
1111

12-
Learn about our Beta features that are coming soon to general availability. To participate, contact your Sumo account executive.
12+
Beta features are capabilities that are coming soon to general availability. To participate, contact your Sumo account executive.
1313

14-
Betas are different than our generally available services in that they have additional terms and conditions for participation. You can [opt-in to beta terms and conditions](/docs/manage/manage-subscription/beta-opt-in), so that you only need to agree to the terms once.
15-
16-
* We may make available to you a Preview, Limited Release, Alpha, Beta or other pre-release version of the service, applications, or APIs for non-production use (“Beta”).
14+
Betas are different than our generally available services in that they have additional terms and conditions for participation:
15+
* We may make available to you a Preview, Limited Release, Alpha, Beta, or other pre-release version of the service, applications, or APIs for non-production use.
1716
* Betas may have limited features, functions, indexing capacity, storage, data security, data continuity, data retention or other limitations as determined by Sumo Logic.
18-
* Sumo Logic may discontinue the Beta at any time.
19-
* We may also decide never to make the features and functionality in Beta generally available.
20-
* Betas (by their nature) have not been fully tested as they are still under development and may be inoperable or incomplete, including more errors and bugs than our generally available offerings.
17+
* Sumo Logic may discontinue the beta at any time.
18+
* We may also decide never to make the features and functionality in beta generally available.
19+
* Betas (by their nature) have not been fully tested as they are still under development, and may be inoperable or incomplete, including more errors and bugs than our generally available offerings.
2120
* Betas are offered “as is” with no warranties or indemnities.
2221

22+
## Features in open beta
23+
24+
See [Beta Releases](/docs/contributing/style-guide/#beta-releases) for information about how we publish articles for features in closed beta and open beta.
25+
26+
Following are articles for features in open beta:
2327

24-
<DocCardList items={useCurrentSidebarCategory().items}/>
28+
<div className="box-wrapper" markdown="1">
29+
<div className="box smallbox card">
30+
<div className="container">
31+
<a href={useBaseUrl('docs/api/metrics-searches/')}><img src={useBaseUrl('img/icons/metrics.png')} alt="Thumbnail icon" width="40"/><h4>Metrics Search Management APIs</h4></a>
32+
<p>Use Metrics Searches (Beta) API endpoints to save metrics searches in your content library, organize them in a folder hierarchy, and share useful queries with users in your organization.</p>
33+
</div>
34+
</div>
35+
</div>

docs/cse/records-signals-entities-insights/create-custom-entity-type.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -11,7 +11,7 @@ This topic has instructions for how to create custom entity types in Cloud SIEM.
1111

1212
In Cloud SIEM, *entities* are fundamental to the insight generation process. When a Cloud SIEM rule fires, it generates a signal for each “on-entity” attribute configured for the rule. Cloud SIEM correlates signals by entity to create insights. This process is described in the [Insight Generation Process](/docs/cse/get-started-with-cloud-siem/insight-generation-process/) topic.
1313

14-
Cloud SIEM has a number of built-in [entity types](/docs/cse/records-signals-entities-insights/view-manage-entities#about-entities), for example, IP Address, Hostname, and Username.
14+
Cloud SIEM has a number of built-in entity types, for example, IP address, hostname, and username. For a list of fields that Cloud SIEM considers entities and the entity types they map to, see [Schema: Entity Fields](https://github.com/SumoLogic/cloud-siem-content-catalog/blob/master/schema/entity_fields.md) in the Cloud SIEM Content Catalog.
1515

1616
When you create a rule, in the signal configuration section, the rules editor prompts you to select an “on-entity” attribute from a list of all of the Cloud SIEM schema attributes that hold entities. What if you want to correlate signals by something other than an item that is one of Cloud SIEM standard entity types? That’s what custom entity types are for.
1717

docs/cse/records-signals-entities-insights/view-manage-entities.md

Lines changed: 3 additions & 20 deletions
Original file line numberDiff line numberDiff line change
@@ -37,29 +37,12 @@ Watch this micro lesson to learn more about entities.
3737

3838
## About entities
3939

40-
In Cloud SIEM, an entity is a unique actor that a signal fired upon. Cloud SIEM has a number of [built-in entity types](https://github.com/SumoLogic/cloud-siem-content-catalog/blob/master/schema/entity_fields.md):
41-
42-
* Command
43-
* Deployment
44-
* Domain
45-
* Email
46-
* File
47-
* Hash
48-
* Hostname
49-
* IP Address
50-
* MAC Address
51-
* Pod
52-
* Process
53-
* Replica Set
54-
* Resource
55-
* URL
56-
* User Agent
57-
* Username
58-
59-
You can create custom entity types as well. For more information, see [Create a Custom Entity Type](/docs/cse/records-signals-entities-insights/create-custom-entity-type/).
40+
In Cloud SIEM, an entity is a unique actor that a signal fired upon, for example, IP address, hostname, or username.
6041

6142
When a signal is fired, if an entity doesn’t already exist in Cloud SIEM for the item that the signal fired on, Cloud SIEM creates an entity for it. For more information about entities and signal and insight generation, see [Insight Generation Process](/docs/cse/get-started-with-cloud-siem/insight-generation-process).
6243

44+
For a list of fields that Cloud SIEM considers entities and the entity types they map to, see [Schema: Entity Fields](https://github.com/SumoLogic/cloud-siem-content-catalog/blob/master/schema/entity_fields.md) in the Cloud SIEM Content Catalog. To create custom entity types, see [Create a Custom Entity Type](/docs/cse/records-signals-entities-insights/create-custom-entity-type/).
45+
6346
:::note
6447
Entity names have a limit of 512 characters. If an entity's name value is 512 characters or longer, the system discards the log, and as a result, no signal is generated.
6548
:::

0 commit comments

Comments
 (0)