Skip to content

Commit 282dd30

Browse files
authored
Merge branch 'main' into azure-events-hub-doc-changes
2 parents a9d8dfa + b61db4c commit 282dd30

File tree

8 files changed

+346
-12
lines changed

8 files changed

+346
-12
lines changed
Lines changed: 20 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,20 @@
1+
---
2+
title: December 31, 2024 - Application Update
3+
keywords:
4+
- sumo logic
5+
- cloud soar
6+
image: https://help.sumologic.com/img/sumo-square.png
7+
hide_table_of_contents: true
8+
---
9+
10+
import useBaseUrl from '@docusaurus/useBaseUrl';
11+
12+
<a href="https://help.sumologic.com/release-notes-csoar/rss.xml"><img src={useBaseUrl('img/release-notes/rss-orange2.png')} alt="icon" width="50"/></a>
13+
14+
### Sumo Logic On-Premises SOAR Solution End-of-Life
15+
16+
Effective today, **December 31, 2024**, Sumo Logic’s on-premises SOAR solution has reached end-of-life and is obsolete. Beginning today, it no longer receives applicable support entitled by active support contracts or by applicable warranty terms and conditions.
17+
18+
We [previously announced](/release-notes-csoar/2023/12/31/#november-1-2023---application-update) that as of November 15, 2023, Sumo Logic's on-premises SOAR solution no longer received updates, and Sumo Logic Engineering no longer developed, repaired, maintained, or tested the software as of that date.
19+
20+
To upgrade to Sumo Logic’s [Cloud SOAR](https://help.sumologic.com/docs/cloud-soar/) offering, reach out to your Sumo Logic representative.

blog-service/2024-12-31-apps.md

Lines changed: 73 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,73 @@
1+
---
2+
title: Apps, Solutions, and Collection Integrations - December Release (Observability)
3+
image: https://help.sumologic.com/img/sumo-square.png
4+
keywords:
5+
- apps
6+
- releases-notes
7+
hide_table_of_contents: true
8+
---
9+
10+
import useBaseUrl from '@docusaurus/useBaseUrl';
11+
12+
<a href="https://help.sumologic.com/release-notes-service/rss.xml"><img src={useBaseUrl('img/release-notes/rss-orange2.png')} alt="icon" width="50"/></a>
13+
14+
### New release
15+
16+
We’re excited to announce the release of new Azure Service Bus, Azure API Management, Azure Event Grid, and AWS Serverless Application Models for Sumo Logic.
17+
18+
- **Azure Service Bus**. Azure Service Bus is a fully managed enterprise message broker with message queues and publish-subscribe topics (in a namespace) used for decoupling applications and services from each other. This integration helps in monitoring incoming/outgoing messages, connections, throttled requests, and resource usage of your Service Bus namespace. [Learn more](/docs/integrations/microsoft-azure/azure-service-bus/).
19+
- **Azure API Management**. Azure API Management is a hybrid multicloud platform for managing APIs across different environments. As a platform-as-a-service, it supports the entire API lifecycle and provides near real-time visibility into API status and health, offering essential API Management operations and details for auditing. [Learn more](/docs/integrations/microsoft-azure/azure-api-management/).
20+
- **Azure Event Grid**. Azure Event Grid is a highly scalable, fully managed Pub Sub message distribution service that offers flexible message consumption patterns using the MQTT and HTTP protocols. This integration helps in monitoring data plane requests, delivery failures and publish failures of Event Grid resources - custom topics, system topics and domains. [Learn more](/docs/integrations/microsoft-azure/azure-event-grid/)
21+
- **AWS Serverless Application Models**. Released the following four SAMs with Python v3.13 and updated the AWS Lambda runtime with latest libraries:
22+
- `sumologic-securityhub-connector-aws-org` - SAM SemanticVersion: 1.0.8.
23+
- `sumologic-s3-logging-auto-enable` - SAM SemanticVersion: 1.0.15.
24+
- `sumologic-aws-cloudtrail-benchmark` - SAM SemanticVersion: 1.0.18.
25+
- `sumologic-app-utils` - SAM SemanticVersion: 2.0.19.
26+
27+
### Enhancements
28+
29+
- **Added Monitors**. We have added new pre-configured monitors to the [Cassandra - OpenTelemetry](/docs/integrations/databases/opentelemetry/cassandra-opentelemetry/#cassandra-alerts), [Couchbase - OpenTelemetry](/docs/integrations/databases/opentelemetry/couchbase-opentelemetry/#couchbase-alerts), [HAProxy - OpenTelemetry](/docs/integrations/web-servers/opentelemetry/haproxy-opentelemetry/#haproxy-alerts), [IIS - OpenTelemetry](/docs/integrations/web-servers/iis-10), [Linux - OpenTelemetry](/docs/integrations/microsoft-azure/opentelemetry/sql-server-linux-opentelemetry/#sql-server-linux-alerts), [MariaDB - OpenTelemetry](/docs/integrations/databases/opentelemetry/mariadb-opentelemetry/#mariadb-alerts), [Memcached - OpenTelemetry](/docs/integrations/databases/opentelemetry/memcached-opentelemetry/#memcached-alerts), [MongoDB - OpenTelemetry](/docs/integrations/databases/opentelemetry/mongodb-opentelemetry/#mongodb-alerts), [Oracle - OpenTelemetry](/docs/integrations/databases/opentelemetry/oracle-opentelemetry/#oracle-alerts), [RabbitMQ - OpenTelemetry](/docs/integrations/containers-orchestration/opentelemetry/rabbitmq-opentelemetry/#rabbitmq-alerts), [Redis - OpenTelemetry](/docs/integrations/databases/opentelemetry/redis-opentelemetry/#redis-alerts), [Squid Proxy - OpenTelemetry](/docs/integrations/web-servers/opentelemetry/squid-proxy-opentelemetry/#squidproxy-alerts), [Varnish - OpenTelemetry](/docs/integrations/web-servers/opentelemetry/varnish-opentelemetry/#varnish-alerts), [JFrog Artifactory - OpenTelemetry](/docs/integrations/app-development/opentelemetry/jfrog-artifactory-opentelemetry), [VMWare - OpenTelemetry](/docs/integrations/containers-orchestration/opentelemetry/vmware-opentelemetry), and [Active Directory JSON - OpenTelemetry](/docs/integrations/microsoft-azure/opentelemetry/active-directory-json-opentelemetry) apps.
30+
- **Azure Blob Storage (block blobs) Collection**. Updated the Block Blob collection to support collection for Network Flow logs. The Network Security Group (NSG) flow logs will be removed on 30 September 2027. **From 30 June 2025, you will no longer be able to generate new NSG flow logs as part of this retirement**. For more details, refer to the Azure [documentation](https://learn.microsoft.com/en-us/azure/network-watcher/flow-logs-read?tabs=nsg).
31+
- The apps listed below have been updated, and as part of the app installation flow, you can now create Cloud-to-Cloud sources:
32+
- [1Password](/docs/integrations/saas-cloud/1password/#collection-configuration-and-app-installation)
33+
- [Abnormal Security](/docs/integrations/saas-cloud/abnormal-security/#collection-configuration-and-app-installation)
34+
- [Airtable](/docs/integrations/saas-cloud/airtable/#collection-configuration-and-app-installation)
35+
- [Akamai Security Events](/docs/integrations/security-threat-detection/akamai-security-events/#collection-configuration-and-app-installation)
36+
- [Atlassian](/docs/integrations/saas-cloud/atlassian/#collection-configuration-and-app-installation)
37+
- [Box](/docs/integrations/saas-cloud/box/#set-up-collection)
38+
- [Cato Networks](/docs/integrations/saas-cloud/cato-networks/#collection-configuration-and-app-installation)
39+
- [Cisco Meraki](/docs/integrations/saas-cloud/cisco-meraki-c2c/#collection-configuration-and-app-installation)
40+
- [CrowdStrike - Falcon Endpoint Protection](/docs/integrations/security-threat-detection/crowdstrike-falcon-endpoint-protection/#collection-configuration-and-app-installation)
41+
- [CrowdStrike FDR Host Inventory](/docs/integrations/saas-cloud/crowdstrike-fdr-host-inventory/#collection-configuration-and-app-installation)
42+
- [CrowdStrike Spotlight](/docs/integrations/saas-cloud/crowdstrike-spotlight/#collection-configuration-and-app-installation)
43+
- [Duo Security](/docs/integrations/security-threat-detection/duo-security/#collection-configuration-and-app-installation)
44+
- [KnowBe4](/docs/integrations/saas-cloud/knowbe4/#collection-configuration-and-app-installation)
45+
- [LastPass](/docs/integrations/saas-cloud/lastpass/#collection-configuration-and-app-installation)
46+
- [Microsoft Azure AD Inventory](/docs/integrations/saas-cloud/microsoft-azure-ad-inventory/#collection-configuration-and-app-installation)
47+
- [Microsoft Graph Azure AD Reporting](/docs/integrations/saas-cloud/microsoft-graph-azure-ad-reporting/#collection-configuration-and-app-installation)
48+
- [Microsoft Graph Security](/docs/integrations/saas-cloud/microsoft-graph-security-v1/#collection-configuration-and-app-installation)
49+
- [Netskope](/docs/integrations/security-threat-detection/netskope/#collection-configuration-and-app-installation)
50+
- [Okta](/docs/integrations/saml/okta/#collection-configuration-and-app-installation)
51+
- [Proofpoint On Demand](/docs/integrations/saas-cloud/proofpoint-on-demand/#collection-configuration-and-app-installation)
52+
- [Proofpoint TAP](/docs/integrations/saas-cloud/proofpoint-tap/#collection-configuration-and-app-installation)
53+
- [Qualys VMDR](/docs/integrations/saas-cloud/qualys-vmdr/#collection-configuration-and-app-installation)
54+
- [Rapid7](/docs/integrations/saas-cloud/rapid7/#collection-configuration-and-app-installation)
55+
- [Salesforce](/docs/integrations/saas-cloud/salesforce/#collection-configuration-and-app-installation)
56+
- [SentinelOne](/docs/integrations/saas-cloud/sentinelone/#collection-configuration-and-app-installation)
57+
- [Slack](/docs/integrations/saas-cloud/slack/#collection-configuration-and-app-installation)
58+
- [Sophos](/docs/integrations/saas-cloud/sophos/#collection-configuration-and-app-installation)
59+
- [Tenable](/docs/integrations/saas-cloud/tenable/#collection-configuration-and-app-installation)
60+
- [Workday](/docs/integrations/saas-cloud/workday/#collection-configuration-and-app-installation)
61+
62+
### Bug fixes
63+
64+
- Minor *query* fixes in the following [Next-Gen Apps](/docs/get-started/apps-integrations/#next-gen-apps):
65+
- Kubernetes
66+
- EKS Control Plane app
67+
- Doppel Vision
68+
69+
- Minor fixes in the *monitors* in the following [Classic Apps (Legacy)](/docs/get-started/apps-integrations/#classic-apps-legacy):
70+
- AWS WAF
71+
- AWS WAF - Cloud Security Monitoring and Analytics
72+
73+
- **Flex app**. Minor changes in the variable name.

docs/integrations/app-development/opentelemetry/jfrog-artifactory-opentelemetry.md

Lines changed: 23 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -15,11 +15,15 @@ The Sumo Logic app for Artifactory provides insight into your [JFrog Artifactory
1515

1616
<img src='https://sumologic-app-data-v2.s3.amazonaws.com/dashboards/Artifactory-OpenTelemetry/Artifactory-Schematics.png' alt="Artifactory-Schematics" />
1717

18+
:::info
19+
This app includes [built-in monitors](#jfrog-artifactory-alerts). For details on creating custom monitors, refer to the [Create monitors for JFrog Artifactory app](#create-monitors-for-jfrog-artifactory-app).
20+
:::
21+
1822
## Fields creation in Sumo Logic for Artifactory
1923

2024
Following are the Tags which will be created as part of Artifactory app install if not already present.
2125

22-
* `sumo.datasource`. Has fixed value of **artifactory**
26+
* `sumo.datasource`. Has fixed value of **artifactory**.
2327

2428
## Prerequisites
2529

@@ -244,3 +248,21 @@ import JfrogReq from '../../../reuse/apps/jfrog/artifactory-request-access.md';
244248
import JfrogTr from '../../../reuse/apps/jfrog/artifactory-traffic.md';
245249

246250
<JfrogTr/>
251+
252+
## Create monitors for JFrog Artifactory app
253+
254+
import CreateMonitors from '../../../reuse/apps/create-monitors.md';
255+
256+
<CreateMonitors/>
257+
258+
### JFrog Artifactory alerts
259+
260+
| Name | Description | Alert Condition | Recover Condition |
261+
|:--|:--|:--|:--|
262+
| `Artifactory - Excessive Denied Login Attempts` | This alert is triggered when there are multiple denied login attempts from the same IP or user. | Count `>` 5 | Count `<=` 5 |
263+
| `Artifactory - High 4xx Status Codes` | This alert is triggered when there's a high number of HTTP 4xx error responses. | Count `>` 10 | Count `<=` 10 |
264+
| `Artifactory - High 5xx Status Codes` | This alert is triggered when there's a high number of HTTP 5xx error responses. | Count `>` 10 | Count `<=` 10 |
265+
| `Artifactory - High Denied Deploys to Cached Repos` | This alert is triggered when there's a high number of denied deploy attempts to cached repositories. | Count `>` 5 | Count `<=` 5 |
266+
| `Artifactory - High Denied Deploys to Non-Cached Repos` | This alert is triggered when there's a spike in denied deploy attempts to non-cached repositories. | Count `>` 5 | Count `<=` 5 |
267+
| `Artifactory - High Denied Downloads` | This alert is triggered when there's a high number of denied download attempts. | Count `>` 5 | Count `<=` 5 |
268+
| `Artifactory - Slow HTTP Response Times` | This alert is triggered when Artifactory response times are high. | Count `>` 5 | Count `<=` 5 |

docs/integrations/containers-orchestration/opentelemetry/vmware-opentelemetry.md

Lines changed: 24 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -21,7 +21,12 @@ See the [vSphere product page](https://www.vmware.com/products/vsphere.html) for
2121

2222
<img src='https://sumologic-app-data-v2.s3.amazonaws.com/dashboards/VMWare-OpenTelemetry/VMWare-Schematics.png' alt="Schematics" />
2323

24+
:::info
25+
This app includes [built-in monitors](#vmware-alerts). For details on creating custom monitors, refer to the [Create monitors for JFrog Artifactory app](#create-monitors-for-vmware-app).
26+
:::
27+
2428
## Prerequisites
29+
2530
VMWare metrics are collected through the [vCenter Receiver](https://github.com/open-telemetry/opentelemetry-collector-contrib/tree/main/receiver/vcenterreceiver) of OpenTelemetry.
2631

2732
This receiver has been built to support ESXi and vCenter versions:
@@ -276,3 +281,22 @@ The **VMWare - VM Details** dashboard provides a detailed analysis of VM metrics
276281
- **Top 25 VMs Network Packet Rate**. Top 25 VMs Network transmitted/received packet rate.
277282
- **Top 25 VMs Network Packet Drop Rate**. Top 25 VMs Network transmitted/received packet drop rate.
278283
- **Top 25 VMs Memory Swapped**. Top 25 VMs Memory swapped.
284+
285+
## Create monitors for VMWare app
286+
287+
import CreateMonitors from '../../../reuse/apps/create-monitors.md';
288+
289+
<CreateMonitors/>
290+
291+
### VMWare alerts
292+
293+
| Name | Description | Alert Condition | Recover Condition |
294+
|:--|:--|:--|:--|
295+
| `VMware - Datastore High Utilization` | This alert is triggered when datastore usage is approaching capacity. | Count `>=` 90 | Count `<` 90 |
296+
| `VMware - High Virtual Disk Read Latency` | This alert gets triggered on high virtual datastore read latency indicating storage performance issues. | Count `>=` 20 | Count `<` 20 |
297+
| `VMware - High Virtual Disk Write Latency` | This alert gets triggered on high virtual datastore write latency indicating storage performance issues. | Count `>=` 20 | Count `<` 20 |
298+
| `VMware - Host CPU High Utilization` | This alert is triggered when host CPU utilization is consistently high, which may impact VM performance. | Count `>=` 90 | Count `<` 90 |
299+
| `VMware - Host Memory Utilization` | This alert is triggered when host memory utilization is consistently high. | Count `>=` 95 | Count `<` 95 |
300+
| `VMware - VM CPU Ready Time High` | This alert gets triggered when VMs are waiting too long for CPU resources, indicating CPU contention. | Count `>=` 10 | Count `<` 10 |
301+
| `VMware - VM Memory Balloon Pressure` | This alert gets triggered when VMs are experiencing significant memory ballooning. | Count `>=` 1024 | Count `<` 1024 |
302+

0 commit comments

Comments
 (0)