Skip to content

Commit 351cd17

Browse files
authored
Merge branch 'main' into dependabot/npm_and_yarn/express-4.22.1
2 parents d8bbafb + f3804cf commit 351cd17

39 files changed

+436
-88
lines changed

.github/workflows/job_trigger-jenkins-pipeline.yml

Lines changed: 9 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -15,26 +15,28 @@ on:
1515
required: true
1616
WEBOPS_JENKINS_HOST:
1717
required: true
18-
WEBOPS_AWS_ACCESS_KEY:
19-
required: true
20-
WEBOPS_AWS_SECRET_KEY:
18+
WEBOPS_AWS_ROLE_JENKINS:
2119
required: true
2220
WEBOPS_WEBHOOK_TOKEN:
2321
required: true
2422

2523
jobs:
2624
trigger-jenkins-pipeline:
2725
runs-on: ubuntu-latest
26+
permissions:
27+
id-token: write
28+
contents: read
2829
steps:
2930
- name: Get runner IP
3031
if: always()
3132
id: ip
3233
uses: haythem/[email protected]
34+
- name: Configure AWS credentials
35+
uses: aws-actions/configure-aws-credentials@00943011d9042930efac3dcd3a170e4273319bc8
36+
with:
37+
role-to-assume: ${{ secrets.WEBOPS_AWS_ROLE_JENKINS }}
38+
aws-region: us-east-1
3339
- name: Add runner to AWS security group ingress
34-
env:
35-
AWS_ACCESS_KEY_ID: ${{ secrets.WEBOPS_AWS_ACCESS_KEY }}
36-
AWS_SECRET_ACCESS_KEY: ${{ secrets.WEBOPS_AWS_SECRET_KEY }}
37-
AWS_DEFAULT_REGION: ${{ secrets.WEBOPS_AWS_REGION }}
3840
run: aws ec2 authorize-security-group-ingress --group-name ${{ secrets.WEBOPS_AWS_SG_NAME }} --protocol tcp --port ${{ secrets.WEBOPS_JENKINS_PORT }} --cidr ${{ steps.ip.outputs.ipv4 }}/32
3941
- name: Trigger Jenkins pipeline
4042
run: |
@@ -43,9 +45,5 @@ jobs:
4345
-X POST \
4446
${{ secrets.WEBOPS_JENKINS_HOST }}:${{ secrets.WEBOPS_JENKINS_PORT || '80' }}/generic-webhook-trigger/invoke?token=${{ secrets.WEBOPS_WEBHOOK_TOKEN }}
4547
- name: Remove runner from AWS security group ingress
46-
env:
47-
AWS_ACCESS_KEY_ID: ${{ secrets.WEBOPS_AWS_ACCESS_KEY }}
48-
AWS_SECRET_ACCESS_KEY: ${{ secrets.WEBOPS_AWS_SECRET_KEY }}
49-
AWS_DEFAULT_REGION: ${{ secrets.WEBOPS_AWS_REGION }}
5048
if: always()
5149
run: aws ec2 revoke-security-group-ingress --group-name ${{ secrets.WEBOPS_AWS_SG_NAME }} --protocol tcp --port ${{ secrets.WEBOPS_JENKINS_PORT }} --cidr ${{ steps.ip.outputs.ipv4 }}/32

.github/workflows/workflow_deploy-to-pantheon-prod.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -2,6 +2,7 @@ name: Deploy to production
22

33
permissions:
44
contents: write
5+
id-token: write
56

67
on:
78
push:
@@ -38,8 +39,7 @@ jobs:
3839
WEBOPS_AWS_SG_NAME: ${{ secrets.WEBOPS_AWS_SG_NAME }}
3940
WEBOPS_JENKINS_PORT: ${{ secrets.WEBOPS_JENKINS_PORT }}
4041
WEBOPS_JENKINS_HOST: ${{ secrets.WEBOPS_JENKINS_HOST }}
41-
WEBOPS_AWS_ACCESS_KEY: ${{ secrets.WEBOPS_AWS_ACCESS_KEY }}
42-
WEBOPS_AWS_SECRET_KEY: ${{ secrets.WEBOPS_AWS_SECRET_KEY }}
42+
WEBOPS_AWS_ROLE_JENKINS: ${{ secrets.WEBOPS_AWS_ROLE_JENKINS }}
4343
WEBOPS_WEBHOOK_TOKEN: ${{ secrets.WEBOPS_WEBHOOK_TOKEN }}
4444
notify-channel:
4545
needs: [build-site,deploy-to-pantheon,trigger-jenkins-pipeline]

blog-collector/2025-12-03-otel.md

Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,14 @@
1+
---
2+
title: OpenTelemetry Collector
3+
image: https://assets-www.sumologic.com/company-logos/_800x418_crop_center-center_82_none/SumoLogic_Preview_600x600.jpg?mtime=1617040082
4+
keywords:
5+
- otel-collector
6+
- install-collector
7+
- remote-management
8+
hide_table_of_contents: true
9+
---
10+
11+
12+
We’re pleased to announce the following updates for OpenTelemetry collectors:
13+
- Collectors can now be installed on Windows using [Ansible](/docs/send-data/opentelemetry-collector/install-collector/ansible/), [Chef](/docs/send-data/opentelemetry-collector/install-collector/chef/), and [Puppet](/docs/send-data/opentelemetry-collector/install-collector/puppet/).
14+
- Remote management is now supported for Ansible, Chef, and Puppet collectors, offering improved flexibility and customization.

blog-cse/2025-12-05-content.md

Lines changed: 96 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,96 @@
1+
---
2+
title: December 05, 2025 - Content Release
3+
image: https://assets-www.sumologic.com/company-logos/_800x418_crop_center-center_82_none/SumoLogic_Preview_600x600.jpg?mtime=1617040082
4+
keywords:
5+
- log mappers
6+
- parsers
7+
- rules
8+
hide_table_of_contents: true
9+
---
10+
11+
This new and updated content is effective as of December 4, 2025.
12+
13+
This content release includes:
14+
- Updates to product naming from "G Suite" to "Google Workspace" across rules, log mappers, and parsers to reflect the current branding.
15+
- Update to product naming from "Dell SonicWall" to "SonicWall Firewall" in parsers and log mappers.
16+
- New support for Asana audit logging.
17+
18+
Additional changes are enumerated below.
19+
20+
## Rules
21+
- [Updated] MATCH-S00630 GCP Audit IAM DeleteServiceAccount Observed
22+
- [Updated] MATCH-S00629 GCP Audit IAM DisableServiceAccount Observed
23+
- [Updated] MATCH-S00117 Google Workspace - Access - Access Transparency
24+
- [Updated] MATCH-S00115 Google Workspace - Admin - User Settings - Turn Off 2SV
25+
- [Updated] MATCH-S00133 Google Workspace - Admin Activity
26+
- [Updated] MATCH-S00125 Google Workspace - Drive - Drive Open To Public
27+
- [Updated] MATCH-S00301 Google Workspace - Excessive OAuth Application Permissions Scope
28+
- [Updated] MATCH-S00128 Google Workspace - Login - Account Warning
29+
- [Updated] MATCH-S00129 Google Workspace - Login - Government Attack Warning
30+
- [Updated] MATCH-S00121 Google Workspace - Mobile - Suspicious Activity
31+
- [Updated] MATCH-S00227 Google Workspace - Unauthorized OAuth Application
32+
- [Updated] MATCH-S00120 Google Workspace - User Accounts - 2SV Disabled
33+
34+
## Log Mappers
35+
- [New] Asana Audit Authentication
36+
- [New] Asana Audit Catch All
37+
- [Updated] Azure ResourceHealth and ServiceHealth
38+
- [Updated] AzureActivityLog AuditLogs
39+
- [Updated] Google Workspace - access_transparency/GSUITE_RESOURCE/ACCESS
40+
- [Updated] Google Workspace - admin
41+
- [Updated] Google Workspace - calendar
42+
- [Updated] Google Workspace - drive.access
43+
- [Updated] Google Workspace - drive.acl_change
44+
- [Updated] Google Workspace - gcp
45+
- [Updated] Google Workspace - gplus
46+
- [Updated] Google Workspace - groups
47+
- [Updated] Google Workspace - groups_enterprise
48+
- [Updated] Google Workspace - login - password_change/recovery_info_change
49+
- [Updated] Google Workspace - login - risky_sensitive_action_allowed
50+
- [Updated] Google Workspace - login challenge
51+
- [Updated] Google Workspace - login-blocked_sender_change
52+
- [Updated] Google Workspace - login-email_forwarding_change
53+
- [Updated] Google Workspace - login.account_warning
54+
- [Updated] Google Workspace - login.gov_attack_warning
55+
- [Updated] Google Workspace - login.login
56+
- [Updated] Google Workspace - logout
57+
- [Updated] Google Workspace - meet
58+
- [Updated] Google Workspace - mobile
59+
- [Updated] Google Workspace - rules
60+
- [Updated] Google Workspace - saml
61+
- [Updated] Google Workspace - token
62+
- [Updated] Google Workspace - user_accounts
63+
- [Updated] Google Workspace Alert Center - AppMaker Editor
64+
- [Updated] Google Workspace Alert Center - Data Loss Prevention
65+
- [Updated] Google Workspace Alert Center - Domain wide takeout
66+
- [Updated] Google Workspace Alert Center - Gmail phishing
67+
- [Updated] Google Workspace Alert Center - Gmail phishing (Misconfigured whitelist)
68+
- [Updated] Google Workspace Alert Center - Google Operations
69+
- [Updated] Google Workspace Alert Center - Google identity
70+
- [Updated] Google Workspace Alert Center - Mobile device management (Device compromised)
71+
- [Updated] Google Workspace Alert Center - Mobile device management (Suspicious activity)
72+
- [Updated] Google Workspace Alert Center - Security Center rules
73+
- [Updated] Google Workspace Alert Center - Sensitive Admin Action
74+
- [Updated] Google Workspace Alert Center - State Sponsored Attack
75+
- [Updated] Google Workspace Alert Center - User Changes
76+
- [Updated] Netskope - Alerts
77+
- Updated action and normalizedAction field mappings.
78+
- [Updated] SonicWall Firewall - Custom Parser
79+
- [Updated] SonicWall Flows
80+
- [Updated] Thinkst Canary Parser - Catch All
81+
- Added additional field mappings.
82+
- [Updated] Windows - Security - 5145
83+
- Removes redundant mapping of `baseimage` and `device_ip` fields.
84+
85+
## Parsers
86+
- [New] /Parsers/System/Asana/Asana Audit
87+
- [New] /Parsers/System/Google/Google Workspace Alert Center
88+
- [New] /Parsers/System/Google/Google Workspace Audit
89+
- [New] /Parsers/System/SonicWall/SonicWall Firewall
90+
- [Updated] /Parsers/System/Dell/Dell SonicWall
91+
- [Updated] /Parsers/System/Google/G Suite Alert Center
92+
- [Updated] /Parsers/System/Google/G Suite Audit
93+
- [Updated] /Parsers/System/Linux/Linux OS Syslog
94+
- Updated parser to drop certain systemd events not useful for security monitoring.
95+
- [Updated] /Parsers/System/Thinkst Canary/Thinkst Canary
96+
- Modified parser to improve field extraction.

blog-service/2025-12-03-manage.md

Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,11 @@
1+
---
2+
title: Manage Org Details (Manage)
3+
image: https://assets-www.sumologic.com/company-logos/_800x418_crop_center-center_82_none/SumoLogic_Preview_600x600.jpg?mtime=1617040082
4+
keywords:
5+
- scheduled-views
6+
- manage
7+
- autopause
8+
hide_table_of_contents: true
9+
---
10+
11+
We're excited to announce that organization managers can now edit a child organization's name, subdomain, and account owner directly from the organizations pages. [Learn more](/docs/manage/manage-subscription/create-and-manage-orgs/).

cid-redirects.json

Lines changed: 6 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -1498,7 +1498,7 @@
14981498
"/Dashboards-and-Alerts/Dashboards/Get-Started-with-Dashboards-and-Panels/Markdown-Syntax": "/docs/dashboards/panels/markdown-syntax",
14991499
"/Manage/01Account_Usage": "/docs/manage/manage-subscription",
15001500
"/Manage/Connections-and-Integrations/Webhook-Connections/Set-Up-Webhook-Connections/Webhook_for_Opsgenie": "/docs/integrations/saas-cloud/opsgenie/",
1501-
"/Manage/01Account_Usage/Beta_Participation_Opt-In": "/docs/manage/manage-subscription/beta-opt-in",
1501+
"/Manage/01Account_Usage/Beta_Participation_Opt-In": "/docs/beta",
15021502
"/Manage/Search_Optimization_Tools/Manage_Partitions/Create_a_Partition": "/docs/manage/partitions/",
15031503
"/Manage/01Account_Usage/05Manage_Organization": "/docs/manage/manage-subscription/create-and-manage-orgs/manage-org-settings",
15041504
"/Manage/01Account_Usage/01Cloud_Flex_Credits": "/docs/manage/manage-subscription/sumo-logic-credits-accounts",
@@ -3144,7 +3144,7 @@
31443144
"/Knowledge_Base/Parsing/Using_line_breaks_as_an_anchor_within_parse": "/docs/search/search-query-language/parse-operators/parse-predictable-patterns-using-an-anchor",
31453145
"/Knowledge_Base/Search": "/docs/search",
31463146
"/Knowledge_Base/Search/How_to_Prevent_your_Scheduled_Search_from_Timing_Out": "/docs/alerts/scheduled-searches/faq",
3147-
"/Limited_Availability": "/docs/manage/manage-subscription/beta-opt-in",
3147+
"/Limited_Availability": "/docs/beta",
31483148
"/Limited_Availability/Lookup_Tables": "/docs/search/search-query-language/search-operators/lookupcontains",
31493149
"/Limited_Availability/Lookup_Tables/lookupContains_Operator": "/docs/search/search-query-language/search-operators/lookupcontains",
31503150
"/Manage": "/docs/manage",
@@ -3165,10 +3165,10 @@
31653165
"/Manage/01Manage_Subscription/10Create_and_Manage_Orgs_(Service_Providers)": "/docs/manage/manage-subscription/create-and-manage-orgs/create-manage-orgs-service-providers",
31663166
"/Manage/01Manage_Subscription/Create_and_Manage_Orgs_(Service_Providers)": "/docs/manage/manage-subscription/create-and-manage-orgs/create-manage-orgs-service-providers",
31673167
"/Manage/01Manage_Subscription/12Manage_Organizational_Settings": "/docs/manage/manage-subscription/create-and-manage-orgs/manage-org-settings",
3168-
"/Manage/01Manage_Subscription/13Beta_Participation_Opt-In": "/docs/manage/manage-subscription/beta-opt-in",
3168+
"/Manage/01Manage_Subscription/13Beta_Participation_Opt-In": "/docs/beta",
31693169
"/Manage/Manage_Subscription/Manage_Organizational_Settings": "/docs/manage/manage-subscription/create-and-manage-orgs/manage-org-settings",
31703170
"/Manage/01Manage_Subscription/14What_to_do_if_Your_Account_is_Locked": "/docs/manage/users-roles/users/account-locked",
3171-
"/Manage/01Manage_Subscription/16Beta_Participation_Opt-In": "/docs/manage/manage-subscription/beta-opt-in",
3171+
"/Manage/01Manage_Subscription/16Beta_Participation_Opt-In": "/docs/beta",
31723172
"/Manage/01Manage_Subscription/18Close_or_cancel_a_Sumo_Logic_account": "/docs/manage/manage-subscription/close-cancel-sumo-account",
31733173
"/Manage/01Manage_Subscription/Upgrade_a_Cloudflex_Credits_Free_or_Trial_Account": "/docs/manage/manage-subscription/upgrade-account/upgrade-credits-account",
31743174
"/docs/manage/manage-subscription/upgrade-cloud-flex-credits-account": "/docs/manage/manage-subscription/upgrade-account/upgrade-sumo-logic-flex-account",
@@ -4599,5 +4599,6 @@
45994599
"/docs/get-started/training-certification-faq-new": "/docs/get-started/training-certification-faq",
46004600
"/docs/manage/scheduled-views/pausing-inactive-scheduled-views": "/docs/manage/scheduled-views/pause-disable-scheduled-views",
46014601
"/docs/manage/manage-subscription/create-and-manage-orgs/manage-orgs-for-mssps-csiem-rules": "/docs/manage/manage-subscription/create-and-manage-orgs/manage-orgs-for-mssps",
4602-
"/docs/search/mobot-multiturn-beta": "/docs/search/mobot"
4602+
"/docs/search/mobot-multiturn-beta": "/docs/search/mobot",
4603+
"/docs/manage/manage-subscription/beta-opt-in": "/docs/beta"
46034604
}

docs/beta/index.md

Lines changed: 19 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -9,16 +9,27 @@ import useBaseUrl from '@docusaurus/useBaseUrl';
99

1010
<img src={useBaseUrl('img/icons/business/beta.png')} alt="icon" width="55"/>
1111

12-
Learn about our Beta features that are coming soon to general availability. To participate, contact your Sumo account executive.
12+
Beta features are capabilities that are coming soon to general availability. To participate, contact your Sumo account executive.
1313

14-
Betas are different than our generally available services in that they have additional terms and conditions for participation. You can [opt-in to beta terms and conditions](/docs/manage/manage-subscription/beta-opt-in), so that you only need to agree to the terms once.
15-
16-
* We may make available to you a Preview, Limited Release, Alpha, Beta or other pre-release version of the service, applications, or APIs for non-production use (“Beta”).
14+
Betas are different than our generally available services in that they have additional terms and conditions for participation:
15+
* We may make available to you a Preview, Limited Release, Alpha, Beta, or other pre-release version of the service, applications, or APIs for non-production use.
1716
* Betas may have limited features, functions, indexing capacity, storage, data security, data continuity, data retention or other limitations as determined by Sumo Logic.
18-
* Sumo Logic may discontinue the Beta at any time.
19-
* We may also decide never to make the features and functionality in Beta generally available.
20-
* Betas (by their nature) have not been fully tested as they are still under development and may be inoperable or incomplete, including more errors and bugs than our generally available offerings.
17+
* Sumo Logic may discontinue the beta at any time.
18+
* We may also decide never to make the features and functionality in beta generally available.
19+
* Betas (by their nature) have not been fully tested as they are still under development, and may be inoperable or incomplete, including more errors and bugs than our generally available offerings.
2120
* Betas are offered “as is” with no warranties or indemnities.
2221

22+
## Features in open beta
23+
24+
See [Beta Releases](/docs/contributing/style-guide/#beta-releases) for information about how we publish articles for features in closed beta and open beta.
25+
26+
Following are articles for features in open beta:
2327

24-
<DocCardList items={useCurrentSidebarCategory().items}/>
28+
<div className="box-wrapper" markdown="1">
29+
<div className="box smallbox card">
30+
<div className="container">
31+
<a href={useBaseUrl('docs/api/metrics-searches/')}><img src={useBaseUrl('img/icons/metrics.png')} alt="Thumbnail icon" width="40"/><h4>Metrics Search Management APIs</h4></a>
32+
<p>Use Metrics Searches (Beta) API endpoints to save metrics searches in your content library, organize them in a folder hierarchy, and share useful queries with users in your organization.</p>
33+
</div>
34+
</div>
35+
</div>

docs/cloud-soar/overview.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -84,9 +84,9 @@ import Theme from '../reuse/dark-light-theme.md';
8484

8585
Sumo Logic Cloud SOAR facilitates timely management of incident response with a rich library of customizable playbooks for different threats.
8686

87-
This solution additionally provides capabilities to support incident responders during the process of assessment, investigation, and data collection to help uncover additional information and metrics analytics to see repetitive patterns when doing analysis. It facilitates documentation and knowledge transfer of information across the critical teams working on incident response and SOC operations team members.
87+
This solution additionally provides capabilities to support incident responders during the process of assessment, investigation, and data collection to help uncover additional information and metrics analytics. It facilitates documentation and knowledge transfer of information across the critical teams working on incident response and SOC operations team members.
8888

89-
Cloud SOAR Automation and Orchestration features help organizations from all sectors of the industry to manage measure and orchestrate security operations tasks including incident qualification, triage and escalation, threat hunting, analysis, threat containment and
89+
Cloud SOAR automation and orchestration features help organizations from all sectors of the industry to manage measure and orchestrate security operations tasks including incident qualification, triage and escalation, threat hunting, analysis, threat containment and
9090
remediation. The gathering of information from different data sources and correlating this information expedites the capabilities and augments human analyst available resources.
9191

9292
The Cloud SOAR tool offers standard management of Incident response events across different teams in the organization with the help of the R3 Rapid response playbook engine. R3 Playbooks are created using a Visual editor supporting granular, stateful and conditional workflows to orchestrate, automate and standardize best practices on a case by case incident response events activities like incident triage, stakeholder notification, data and context enrichment, remediation and threat containment.

docs/get-started/sumo-logic-ui-classic.md

Lines changed: 4 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -7,12 +7,14 @@ description: Get to know the Sumo Logic platform user interface.
77

88
import useBaseUrl from '@docusaurus/useBaseUrl';
99

10+
:::note
11+
This page describes the Classic UI. For the most streamlined navigation and the newest user experience, switch to the [New UI](/docs/get-started/sumo-logic-ui).
12+
:::
13+
1014
This page provides an overview of the Sumo Logic Classic UI, designed to help you navigate and utilize its features effectively.
1115

1216
<img src={useBaseUrl('img/get-started/overview-classic-ui.png')} alt="Overview screenshot of the Classic UI" style={{border: '1px solid gray'}} width="800" />
1317

14-
The Classic UI will be retired in 2025 and will no longer receive updates. The exact date will be communicated closer to the transition. For the latest features, performance improvements, and future innovations, switch to the [New UI](/docs/get-started/sumo-logic-ui) as soon as possible.
15-
1618
## Switching between the Classic and New UI
1719

1820
If you're using the New UI and need to navigate back to the Classic UI, click the **Return to classic UI** option in the left navigation menu. And to switch back to the New UI, follow the same steps, selecting **Switch to New UI** instead.

0 commit comments

Comments
 (0)