Skip to content

Commit 3336d71

Browse files
authored
Merge branch 'main' into scheduled-views-timezone
2 parents b47bc4f + 897eb5b commit 3336d71

File tree

15 files changed

+202
-146
lines changed

15 files changed

+202
-146
lines changed

blog-cse/2025-06-26-content.md

Lines changed: 41 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,41 @@
1+
---
2+
title: June 26, 2025 - Content Release
3+
image: https://help.sumologic.com/img/sumo-square.png
4+
keywords:
5+
- log mappers
6+
- parsers
7+
hide_table_of_contents: true
8+
---
9+
10+
11+
This content release includes:
12+
- Device support for AWS VPN and VMware Avi Load Balancer.
13+
- Updates to Cisco ASA and Umbrella parsers to support additional log pattern variations.
14+
- Bug fix for year timestamp parsing with the potential of creating incorrect timestamps around the new year for records.
15+
16+
## Log Mappers
17+
- [New] AWS VPN
18+
- [New] VMware Avi Load Balancer Catch All
19+
20+
## Parsers
21+
- [New] /Parsers/System/AWS/AWS VPN
22+
- [New] /Parsers/System/VMware/VMware Avi Load Balancer
23+
- [Updated] /Parsers/System/Atlassian/Atlassian Audit Events
24+
- [Updated] /Parsers/System/Microsoft/Azure Storage Analytics
25+
- [Updated] /Parsers/System/Cisco/Cisco ASA
26+
- [Updated] /Parsers/System/Cisco/Cisco Umbrella CSV
27+
- [Updated] /Parsers/System/Cylance/Cylance Syslog
28+
- [Updated] /Parsers/System/Cylance/Cylance Threat JSON
29+
- [Updated] /Parsers/System/JumpCloud/JumpCloud Directory Insights
30+
- [Updated] /Parsers/System/Miro/Miro Audit C2C
31+
- [Updated] /Parsers/System/Palo Alto/PAN Firewall LEEF
32+
- [Updated] /Parsers/System/Pulse Secure/Pulse Secure Appliance
33+
- [Updated] /Parsers/System/RSA/RSA SecurID SinglePoint
34+
- [Updated] /Parsers/System/Symantec/Symantec Endpoint Protection/Symantec Endpoint Protection-Syslog
35+
- [Updated] /Parsers/System/Tanium/Tanium CEF
36+
- [Updated] /Parsers/System/Trellix/Trellix MVision EPO
37+
- [Updated] /Parsers/System/Twistlock/Twistlock
38+
- [Updated] /Parsers/System/Zeek/Zeek
39+
- [Updated] /Parsers/System/Zscaler/Zscaler Nanolog Streaming Service/Zscaler Nanolog Streaming Service-CEF
40+
- [Updated] /Parsers/System/Zscaler/Zscaler Nanolog Streaming Service/Zscaler Nanolog Streaming Service-JSON
41+
- [Updated] /Parsers/System/Zscaler/Zscaler Nanolog Streaming Service/Zscaler Nanolog Streaming Service-LEEF

blog-service/2025-06-27-manage.md

Lines changed: 19 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,19 @@
1+
---
2+
title: Manage Libraries for MSSPs - Beta (Manage)
3+
image: https://help.sumologic.com/img/sumo-square.png
4+
keywords:
5+
- manage
6+
- organizations
7+
- mssps
8+
hide_table_of_contents: true
9+
---
10+
11+
import useBaseUrl from '@docusaurus/useBaseUrl';
12+
13+
We are excited to announce the ability to manage library content on the new **Manage Content** tab. Now MSSP administrators can conveniently push content in the **Library** folder to multiple child organizations at once, including dashboards, saved searches, and scheduled searches. [Learn more](/docs/manage/manage-subscription/create-and-manage-orgs/manage-orgs-for-mssps/).
14+
15+
:::note
16+
This feature is in Beta. To participate, contact your Sumo Logic account executive or our Support Team.
17+
:::
18+
19+
<img src={useBaseUrl('img/manage/subscriptions/mssp-orgs-sync-selected-items.png')} alt="Update Selected Items button" style={{border: '1px solid gray'}} width="800"/>

docs/cloud-soar/introduction.md

Lines changed: 0 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -64,7 +64,6 @@ Finally, you can take the Insights from Cloud SIEM and automatically respond to
6464
Sumo Logic’s Cloud SOAR is a cloud-based web application available as an add-on to existing Sumo Logic deployments. Some of Cloud SOAR’s key features include:
6565

6666
* **War Room**. A central location for all the information, analysis, and actions related to an incident. This includes notes, documentation, and knowledge transfer as well as tools for collecting data and assessing, investigating, and correlating different incidents.
67-
* **ARK**. The Automated Responder Knowledge (ARK) learns from past incidents and threat intel to recommend relevant playbooks for future incidents.
6867
* **App Central**. A large out-of-the-box library of playbooks, integrations, and use cases for different threats to get you started.
6968
* **Cybersecurity best practices**. Cloud SOAR’s design and architecture meets many cybersecurity industry standards, regulatory frameworks, and best practices from organizations like ISO, GDPR, OASIS, NIST, and many others.
7069

@@ -210,12 +209,6 @@ Here are some other workflows you could automate with a playbook:
210209

211210
Cloud SOAR has hundreds of prebuilt playbooks and templates, so you can quickly and easily automate any of these tasks, or create new custom playbooks to suit your specific business needs. Normally, playbooks are automatically attached to incidents based on information like entities and severity scores.
212211

213-
##### ARK suggestions
214-
215-
Playbooks automate the individual tasks of incident response. But Cloud SOAR's Automated Responder Knowledge (ARK) suggestions take things one step further. ARK uses machine learning to suggest the most appropriate playbook for your incidents based on what you've done on similar incidents in the past. This frees up even more resources for analysts, as they don't have to spend time choosing a playbook before responding.
216-
217-
When ARK suggests a playbook to you, you have the option to add the playbook to the incident, run it, or dismiss the suggestion.
218-
219212
#### App Central, custom integrations, and other automations
220213

221214
Cloud SOAR has hundreds of pre-built playbooks which you can use as-is or customize. You can also build your own custom playbooks, which you can learn about in the Cloud SIEM Administration class.

docs/cloud-soar/legacy/legacy-cloud-soar-architecture.md

Lines changed: 0 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -25,11 +25,3 @@ All multi-tenant installations offer:
2525
- Isolation of external actions (e.g., enrichment of indicators of compromise, containment actions prescribed to a host)
2626

2727
<img src={useBaseUrl('img/cloud-soar/image5.png')} alt="Multiple database symbols" width="600"/>
28-
29-
## Automated Responder Knowledge (DF-ARK)
30-
31-
Cloud SOAR's Automated Responder Knowledge (DF-ARK) module utilizes machine
32-
learning through historical responses to past incidents and threat
33-
intelligence feeds to enrich new incidents. This enrichment allows
34-
Cloud SOAR to recommend relevant Playbooks and plans of action to expedite
35-
detection and response times.

docs/cloud-soar/legacy/legacy-global-functions-menu.md

Lines changed: 0 additions & 43 deletions
Original file line numberDiff line numberDiff line change
@@ -32,49 +32,6 @@ When a search result is located within an incident, the incident number will be
3232

3333
<img src={useBaseUrl('img/cloud-soar/image12.png')} alt="Global Search Results" style={{border: '1px solid gray'}} width="800"/>
3434

35-
## Automation
36-
37-
### ARK
38-
39-
ARK or Automated Responder Knowledge is the Machine Learning component of Cloud SOAR which implements the Supervised learning in Case-Based Reasoning (CBR) algorithm.
40-
CBR solves new problems by adapting previously successful solutions to similar problems. In Cloud SOAR, this can be leveraged by analyzing solved incidents to hint steps and procedures to operators in new similar threats.<br/> <img src={useBaseUrl('img/cloud-soar/image15e.png')} alt="Automation menu" style={{border: '1px solid gray'}} width="250"/>
41-
42-
ARK assists operators during investigations in two main areas: Automatically suggesting/prompting next actions/tasks in Playbooks (until version 5) and Correlation/ Deduplication of similar threats into 1 unique incident.
43-
44-
#### Enable ARK
45-
46-
To enable ARK, click the cog icon, then **Settings** > **ARK** and make sure you have it set to **ON**.
47-
48-
From this page, it’s possible to configure also other ARK Settings such as the Neighbor incidents considered for each recommendation and an age relevance threshold. Those two parameters will allow you to tune the incidents that the Machine Learning algorithm will consider.
49-
50-
<img src={useBaseUrl('img/cloud-soar/image16b.png')} alt="ARK Settings" style={{border: '1px solid gray'}} width="800"/>
51-
52-
When an incident is created in Cloud SOAR, the Incident Type field will be the one defining which Playbooks you can attach to that incident.
53-
54-
#### ARK Usage
55-
56-
ARK has a correlation and deduplication or merging mechanism you can use with the ARK OIF.
57-
58-
ARK 2.0 OIF is a custom Sumo Logic integration which allows investigators to implement a mechanism for deduplication and correlation of ingested alerts and Cloud SOAR incidents.
59-
60-
<img src={useBaseUrl('img/cloud-soar/image16d.png')} alt="ARK OIF" style={{border: '1px solid gray'}} width="800"/>
61-
62-
<img src={useBaseUrl('img/cloud-soar/image16e.png')} alt="Test Action" style={{border: '1px solid gray'}} width="800"/>
63-
64-
OIF ARK enrichment action “Get parents for incident” allows you to retrieve every incident (as proposed parents) that is similar to the analyzed one.
65-
66-
Each optional field allows you to fine tune the weight of the fields, acceptance thresholds and of the algorithm which needs to be trained and fine-tuned in order to get correct and reliable results.
67-
68-
<img src={useBaseUrl('img/cloud-soar/image16f.png')} alt="Field Weight" style={{border: '1px solid gray'}} width="800"/>
69-
70-
Alert deduplication or merging can be achieved by utilizing ARK OIF enrichment actions and Cloud SOAR’s unique Triage capability.
71-
72-
Triage is a customizable section which can be used for enriching and preprocessing multiple different scenarios.
73-
74-
By dispatching the ingested alerts into Triage events, Cloud SOAR can automatically enrich each event, deduplicate them based on the logic configured in our associated Playbooks (which can invoke Ark OIF enrichment) and decide if Cloud SOAR should aggregate multiple entries in one unique incident, create multiple incidents for each event or if a similar incident has already been created, to update the existing incident with updated information.
75-
76-
Cloud SOAR can also correlate existing incidents to check if specific data is already present in the Cloud SOAR Database. It is crucial that all merging or deduplication must be done prior to conversion of an alert into incident. For example, a Triage event that allows you to invoke one or multiple playbooks for each Triage event created.
77-
7835
## Settings
7936

8037
### General Settings

docs/cloud-soar/overview.md

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -402,8 +402,6 @@ Cloud SOAR has been designed with Interoperability for Cybersecurity Industry st
402402

403403
Cloud SOAR design and architecture follows Cybersecurity Industry standards and regulatory frameworks, and adheres to best Industry practices to meet best Cybersecurity practices followed by ISO, GDPR, OASIS, NIST, Sec Regulations, and more.
404404

405-
Cloud SOAR offers a patent-pending Automated Responder Knowledge (DF-ARK) module which applies machine learning to historical responses and threats. It recommends relevant Playbooks, paths of action to expedite the process, and responses to manage and mitigate similar incidents with better response time.
406-
407405
Cloud SOAR provides static egress for Cloud executions. IP addresses can be entered into the allowlist. For a list of Cloud SOAR addresses by region, contact [Support](https://support.sumologic.com/support/s/).
408406

409407
<img src={useBaseUrl('img/cloud-soar/image3.png')} alt="Cloud SOAR architecture diagram" style={{border: '1px solid gray'}} width="800"/>

docs/integrations/amazon-aws/index.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -348,8 +348,8 @@ This guide has documentation for all of the apps that Sumo provides for Amazon a
348348
<div className="box smallbox card">
349349
<div className="container">
350350
<img src={useBaseUrl('img/integrations/amazon-aws/security-qs.png')} alt="Thumbnail icon" width="50"/>
351-
<h4><a href="/docs/integrations/amazon-aws/security-hub">AWS Security Hub</a></h4>
352-
<p>A guide to the Sumo Logic app for AWS Security Hub.</p>
351+
<h4><a href="/docs/integrations/amazon-aws/security-hub">AWS Security Hub CSPM</a></h4>
352+
<p>A guide to the Sumo Logic app for AWS Security Hub CSPM.</p>
353353
</div>
354354
</div>
355355
<div className="box smallbox card">

0 commit comments

Comments
 (0)