Skip to content

Commit 3f6fde8

Browse files
committed
Merge branch 'lb-cloudtrail' of https://github.com/SumoLogic/sumologic-documentation into lb-cloudtrail
2 parents f8482ab + e6d6726 commit 3f6fde8

File tree

14 files changed

+186
-8
lines changed

14 files changed

+186
-8
lines changed

.github/CODEOWNERS

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1,14 +1,14 @@
11
# Default owners for everything in the repo.
2-
* @kimsauce @jpipkin1 @JV0812 @mafsumo
2+
* @kimsauce @jpipkin1 @JV0812 @mafsumo @amee-sumo
33

44
# Owners of all files in the `/docs` directory and its subdirectories.
5-
/docs/ @kimsauce @jpipkin1 @JV0812 @mafsumo
5+
/docs/ @kimsauce @jpipkin1 @JV0812 @mafsumo @amee-sumo
66

77
# Owners of all files in the `/docs/send-data/kubernetes` directory.
8-
/docs/send-data/kubernetes/ @SumoLogic/open-source-collection-team @kimsauce @jpipkin1 @JV0812 @mafsumo
8+
/docs/send-data/kubernetes/ @SumoLogic/open-source-collection-team @kimsauce @jpipkin1 @JV0812 @mafsumo @amee-sumo
99

1010
# Owners of all files in the `/docs/send-data/opentelemetry-collector` directory and its subdirectories.
11-
/docs/send-data/opentelemetry-collector/ @SumoLogic/open-source-collection-team @kimsauce @jpipkin1 @mafsumo @JV0812
11+
/docs/send-data/opentelemetry-collector/ @SumoLogic/open-source-collection-team @kimsauce @jpipkin1 @mafsumo @JV0812 @amee-sumo
1212

1313
# GitHub workflow owners
1414
/.github/workflows/ @SumoLogic/open-source-collection-team @kimsauce

blog-csoar/2024-11-20-content.md

Lines changed: 46 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,46 @@
1+
---
2+
title: November 20, 2024 - Content Release
3+
hide_table_of_contents: true
4+
image: https://help.sumologic.com/img/sumo-square.png
5+
keywords:
6+
- automation service
7+
- cloud soar
8+
- soar
9+
---
10+
11+
import useBaseUrl from '@docusaurus/useBaseUrl';
12+
13+
<a href="https://help.sumologic.com/release-notes-csoar/rss.xml"><img src={useBaseUrl('img/release-notes/rss-orange2.png')} alt="icon" width="50"/></a>
14+
15+
This release introduces new integrations, new playbooks, and several updates.
16+
17+
### Integrations
18+
19+
* [New] [Google Chat](/docs/platform-services/automation-service/app-central/integrations/google-chat)
20+
* [New] [Malwarebytes Oneview](/docs/platform-services/automation-service/app-central/integrations/malwarebytes-oneview)
21+
* [New] [Silent Push](/docs/platform-services/automation-service/app-central/integrations/silent-push)
22+
* [New] [Sumo Logic Automation Tools](/docs/platform-services/automation-service/app-central/integrations/sumo-logic-automation-tools)
23+
* [New] [VirusTotal V3](/docs/platform-services/automation-service/app-central/integrations/virustotal-v3)
24+
* [Updated] [APIVoid](/docs/platform-services/automation-service/app-central/integrations/apivoid)
25+
* [Updated] [Atlassian Jira V2](/docs/platform-services/automation-service/app-central/integrations/atlassian-jira-v2)
26+
* [Updated] [Atlassian Opsgenie](/docs/platform-services/automation-service/app-central/integrations/atlassian-opsgenie)
27+
* [Updated] [AWS EC2](/docs/platform-services/automation-service/app-central/integrations/aws-ec2)
28+
* [Updated] [AWS EKS](/docs/platform-services/automation-service/app-central/integrations/aws-eks)
29+
* [Updated] [Azure AD](/docs/platform-services/automation-service/app-central/integrations/azure-ad)
30+
* [Updated] [Cloudflare](/docs/platform-services/automation-service/app-central/integrations/cloudflare)
31+
* [Updated] [ConnectWise Manage](/docs/platform-services/automation-service/app-central/integrations/connectwise-manage)
32+
* [Updated] [Cortex XDR](/docs/platform-services/automation-service/app-central/integrations/cortex-xdr)
33+
* [Updated] [CrowdStrike Falcon](/docs/platform-services/automation-service/app-central/integrations/crowdstrike-falcon)
34+
* [Updated] [Freshservice](/docs/platform-services/automation-service/app-central/integrations/freshservice)
35+
* [Updated] [Gmail](/docs/platform-services/automation-service/app-central/integrations/gmail)
36+
* [Updated] [HTTP Tools](/docs/platform-services/automation-service/app-central/integrations/http-tools)
37+
* [Updated] [IBM X-Force Exchange](/docs/platform-services/automation-service/app-central/integrations/ibm-x-force-exchange)
38+
* [Updated] [Microsoft EWS](/docs/platform-services/automation-service/app-central/integrations/microsoft-ews)
39+
* [Updated] [Microsoft OneDrive](/docs/platform-services/automation-service/app-central/integrations/microsoft-onedrive)
40+
* [Updated] [Microsoft Sentinel](/docs/platform-services/automation-service/app-central/integrations/microsoft-sentinel)
41+
* [Updated] [Netskope V2](/docs/platform-services/automation-service/app-central/integrations/netskope-v2)
42+
* [Updated] [Slack](/docs/platform-services/automation-service/app-central/integrations/slack)
43+
* [Updated] [Sumo Logic Cloud SIEM](/docs/platform-services/automation-service/app-central/integrations/sumo-logic-cloud-siem)
44+
* [Updated] [Sumo Logic Notifications by Gmail](/docs/platform-services/automation-service/app-central/integrations/sumo-logic-notifications-by-gmail)
45+
* [Updated] [URLScan.io](/docs/platform-services/automation-service/app-central/integrations/urlscan.io)
46+
* [Updated] [VirusTotal](/docs/platform-services/automation-service/app-central/integrations/virustotal)

cid-redirects.json

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -2636,6 +2636,7 @@
26362636
"/cid/16323": "/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/druva-source",
26372637
"/cid/13428": "/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/kandji-source",
26382638
"/cid/17343": "/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/automox-source",
2639+
"/cid/17344": "/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/smartsheet-source",
26392640
"/cid/20172": "/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/cisco-vulnerability-management-source",
26402641
"/cid/19880": "/docs/metrics/metrics-operators/predict",
26412642
"/cid/19881": "/docs/metrics/metrics-operators/accum",

docs/integrations/product-list/product-list-m-z.md

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -141,6 +141,7 @@ For descriptions of the different types of integrations Sumo Logic offers, see [
141141
| <img src={useBaseUrl('img/platform-services/automation-service/app-central/logos/shodan.png')} alt="Thumbnail icon" width="100"/> | [Shodan](https://www.shodan.io/) | Automation integration: [Shodan](/docs/platform-services/automation-service/app-central/integrations/shodan/) |
142142
| <img src={useBaseUrl('/img/platform-services/automation-service/app-central/logos/silent-push.png')} alt="Thumbnail icon" width="100"/> | [Silent Push](https://www.silentpush.com/) | Automation integration: [Silent Push](/docs/platform-services/automation-service/app-central/integrations/silent-push) |
143143
| <img src={useBaseUrl('img/integrations/saas-cloud/slack.png')} alt="Thumbnail icon" width="50"/> | [Slack](https://slack.com/) | App: [Slack](/docs/integrations/saas-cloud/slack/) <br/>Automation integration: [Slack](/docs/platform-services/automation-service/app-central/integrations/slack/) <br/>Cloud SIEM integration: [Slack](https://github.com/SumoLogic/cloud-siem-content-catalog/blob/master/vendors/c93d9bf6-0a88-49fc-aebb-ac7b2ea6792c.md) <br/>Collector: [Slack Source](/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/slack-source/) <br/>Webhook: [Webhook Connection for Slack](/docs/alerts/webhook-connections/slack/) |
144+
| <img src={useBaseUrl('img/send-data/smartsheet.png')} alt="Thumbnail icon" width="50"/> | [Smartsheet](https://www.smartsheet.com/) | Collector: [Smartsheet Source](/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/smartsheet-source) |
144145
| <img src={useBaseUrl('img/integrations/misc/snare-logo.png')} alt="Thumbnail icon" width="75"/> | [Snare](https://www.snaresolutions.com/) | Cloud SIEM integration: [Intersect Alliance](https://github.com/SumoLogic/cloud-siem-content-catalog/blob/master/vendors/005c835d-f067-4147-9da9-fe4d2691247e.md) |
145146
| <img src={useBaseUrl('img/integrations/misc/snowflake-logo.png')} alt="Thumbnail icon" width="100"/> | [Snowflake](https://www.snowflake.com/en/) | Cloud SIEM integration: [Snowflake](https://github.com/SumoLogic/cloud-siem-content-catalog/blob/master/vendors/5541f59d-e27d-48e6-a35c-34fb75e9cf13.md) <br/>Collector: [Snowflake SQL API Source](/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/snowflake-sql-api-source) |
146147
| <img src={useBaseUrl('img/platform-services/automation-service/app-central/logos/snyk.png')} alt="Thumbnail icon" width="75"/> | [Snyk](https://snyk.io/) | Automation integration: [Snyk](/docs/platform-services/automation-service/app-central/integrations/snyk/) |

docs/observability/reliability-management-slo/index.md

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -73,9 +73,9 @@ As an example, let's say an eCommerce app considers its checkout service transac
7373

7474
The _SLI_ can be defined as the percentage of successful 5m windows in a _compliance period_ of 30 days (30d) or equal to 99.9% for any month. The number of unsuccessful (bad) transactions we allow as an _error budget_ is 0.1% of these 5m windows in 30d.
7575

76-
The following chart shows our calculations and an example 5m window for the month of January where a number of requests were unsuccessful due to a completions that averaged greater than 600ms:
76+
The following chart shows our calculations and an example 5m window for the month of January where a number of requests were unsuccessful due to completions that were greater than 500ms:
7777

78-
<img src={useBaseUrl('img/observability/slo-checkout-example.png')} alt="Reliability Management SLO SLI" />
78+
<img src={useBaseUrl('img/observability/slo-checkout-example.png')} alt="Reliability Management SLO SLI" style={{border: '1px solid gray'}} width="800" />
7979

8080
With these calculations, we can configure an SLO, add a monitor, and start managing this and other services with ease. This is just one example. You can develop many different SLOs based on evaluation types (windows-based and request-based), ratios and thresholds for calculations, and error budgets for rolling or calendar compliance periods.
8181

@@ -137,7 +137,7 @@ In the SLO screen, you can view, search, and add SLOs. Use folders to collect, p
137137

138138
To locate an SLO, use the search that returns a list of SLOs based on the name and description.
139139

140-
<img src={useBaseUrl('img/observability/slo1.png')} alt="Reliability Management SLO SLI" />
140+
<img src={useBaseUrl('img/observability/slo1.png')} alt="Reliability Management SLO SLI" style={{border: '1px solid gray'}} width="800" />
141141

142142
To open the dashboard, locate and select an SLO. The details pane gives you a preview and an option to **Open SLO Dashboard**. See [SLO Dashboards and Notifications](/docs/observability/reliability-management-slo/dashboards) for more information.
143143

@@ -154,7 +154,7 @@ The **SLO Details** tab provides a quick view of the SLO ID, description, config
154154

155155
The **Monitors** tab provides a list of associated monitors for the SLO. Expand entries to review the status, condition, and configured triggers. Click the open icon (<img src={useBaseUrl('img/observability/open-monitor.png')} alt="Reliability Management SLO SLI" width="20" /> ) to open and edit the monitor.
156156

157-
<img src={useBaseUrl('img/observability/slo-preview.gif')} alt="Reliability Management SLO SLI" />
157+
<img src={useBaseUrl('img/observability/slo-preview.gif')} alt="Reliability Management SLO SLI" style={{border: '1px solid gray'}} width="800" />
158158

159159

160160
### Query Recommendations

docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/index.md

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -451,6 +451,12 @@ In this section, we'll introduce the following concepts:
451451
<p>Learn about the Slack Source, part of Sumo Logic's Cloud-to-Cloud Integration Framework.</p>
452452
</div>
453453
</div>
454+
<div className="box smallbox card">
455+
<div className="container">
456+
<a href="/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/smartsheet-source"><img src={useBaseUrl('img/send-data/smartsheet.png')} alt="Thumbnail icon" width="50"/><h4>Smartsheet</h4></a>
457+
<p>Learn how to collect events from Smartsheet platform.</p>
458+
</div>
459+
</div>
454460
<div className="box smallbox card">
455461
<div className="container">
456462
<a href="/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/sophos-central-source"><img src={useBaseUrl('img/send-data/sophos.jpeg')} alt="icon" width="50"/><h4>Sophos Central</h4></a>
Lines changed: 90 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,90 @@
1+
---
2+
id: smartsheet-source
3+
title: Smartsheet Source
4+
sidebar_label: Smartsheet
5+
keywords:
6+
- smartsheet
7+
- cloud-to-cloud
8+
description: Learn how to collect events from Smartsheet platform.
9+
---
10+
import CodeBlock from '@theme/CodeBlock';
11+
import ExampleJSON from '/files/c2c/smartsheet/example.json';
12+
import MyComponentSource from '!!raw-loader!/files/c2c/smartsheet/example.json';
13+
import TerraformExample from '!!raw-loader!/files/c2c/smartsheet/example.tf';
14+
import useBaseUrl from '@docusaurus/useBaseUrl';
15+
16+
<img src={useBaseUrl('img/send-data/smartsheet.png')} alt="thumbnail icon" width="55"/>
17+
18+
Smartsheet is used to collaborate on project timelines, documents, calendars, tasks, and other works. Smartsheet integrates and connects with many of the systems teams use today. This allows for efficient information sharing, improved collaboration, and decision-making across teams’ tech stack. The Smartsheet source collects and ingests the events that are occurring in your Smartsheet organization account. Examples of events are creation, update, load, and delete of sheets, reports, dashboards, attachments, and users.
19+
20+
## Data collected
21+
22+
| Polling Interval | Data |
23+
| :--- | :--- |
24+
| User entered | [List Events](https://smartsheet.redoc.ly/tag/events/#operation/list-events) |
25+
26+
## Setup
27+
28+
### Vendor configuration
29+
30+
To collect data from Smartsheet, you need a Smartsheet account with admin privileges that would allow the creation of an app via a developer account. See [steps in the Smartsheet documentation](https://smartsheet.redoc.ly/#section/OAuth-Walkthrough/First-Steps) to create a developer account in Smartsheet.
31+
32+
### Source configuration
33+
34+
When you create a Smartsheet source, you add it to a Hosted Collector. Before creating the source, identify the Hosted Collector you want to use or create a new Hosted Collector. For instructions, see [Configure a Hosted Collector and Source](/docs/send-data/hosted-collectors/configure-hosted-collector).
35+
36+
To configure Smartsheet Source:
37+
1. [**Classic UI**](/docs/get-started/sumo-logic-ui-classic). In the main Sumo Logic menu, select **Manage Data > Collection > Collection**. <br/>[**New UI**](/docs/get-started/sumo-logic-ui). In the Sumo Logic top menu select **Configuration**, and then under **Data Collection** select **Collection**. You can also click the **Go To...** menu at the top of the screen and select **Collection**.
38+
1. On the collectors page, click **Add Source** next to a Hosted Collector.
39+
1. Search for and select **Smartsheet** icon.
40+
1. Enter a **Name** to display for the source in the Sumo Logic web application. The description is optional.
41+
1. (Optional) For **Source Category**, enter any string to tag the output collected from the source. Category metadata is stored in a searchable field called `_sourceCategory`.
42+
1. (Optional) **Fields**. Click the **+Add Field** link to define the fields you want to associate. Each field needs a name (key) and value.
43+
* ![green check circle.png](/img/reuse/green-check-circle.png) A green circle with a check mark is shown when the field exists in the Fields table schema.
44+
* ![orange exclamation point.png](/img/reuse/orange-exclamation-point.png) An orange triangle with an exclamation point is shown when the field doesn't exist in the Fields table schema. In this case, an option to automatically add the nonexistent fields to the Fields table schema is provided. If a field is sent to Sumo Logic that does not exist in the Fields schema it is ignored, known as dropped.
45+
1. In **Application (client) ID**, paste in the Client ID from the vendor's setup "Create a Developer Account and Register an App" steps.
46+
1. In **Client Secret**, paste in the Client Secret from the vendor's setup "Create a Developer Account and Register an App" steps.
47+
1. In **Oauth 2.0 Authorization Code**, paste in the Authorization Code from the vendor's setup "Create a Developer Account and Register an App" steps.
48+
1. **Polling Interval**. You have the option to select how often to poll for events in minutes. Default is 10 minutes.
49+
1. When you are finished configuring the source, click **Save**.
50+
51+
## JSON schema
52+
53+
Sources can be configured using UTF-8 encoded JSON files with the Collector Management API. See [Use JSON to Configure Sources](/docs/send-data/use-json-configure-sources) for details. 
54+
55+
| Parameter | Type | Value | Required | Description |
56+
|:--|:--|:--|:--|:--|
57+
| schemaRef | JSON Object | `{"type":"Smartsheet"}` | Yes | Define the specific schema type. |
58+
| sourceType | String | `"Universal"` | Yes | Type of source. |
59+
| config | JSON Object | [Configuration object](#configuration-object) | Yes | Source type specific values. |
60+
61+
### Configuration Object
62+
63+
| Parameter | Type | Required | Default | Description | Example |
64+
|:--|:--|:--|:--|:--|:--|
65+
| name | String | Yes | `null` | Type a desired name of the source. The name must be unique per Collector. This value is assigned to the [metadata](/docs/search/get-started-with-search/search-basics/built-in-metadata) field `_source`. | `"mySource"` |
66+
| description | String | No | `null` | Type a description of the source. | `"Testing source"`\ |
67+
| category | String | No | `null` | Type a category of the source. This value is assigned to the [metadata](/docs/search/get-started-with-search/search-basics/built-in-metadata) field `_sourceCategory`. See [best practices](/docs/send-data/best-practices) for details. | `"mySource/test"` |
68+
| fields | JSON Object | No | `null` | JSON map of key-value fields (metadata) to apply to the Collector or Source. Use the boolean field `_siemForward` to enable forwarding to SIEM.|`{"_siemForward": false, "fieldA": "valueA"}` |
69+
| app_client_id | String | Yes | `null` | The Smartsheet app client ID to collect from Smartsheet platform. | |
70+
| client_secret | String | Yes | `null` | The Smartsheet app client secret to collect from Smartsheet platform. | |
71+
| authorization_code | String | Yes | `null` | The Smartsheet app client OAuth2 authorization code to collect from Smartsheet platform. | |
72+
| polling_interval | Integer | Yes | 10 | How frequently the integration should poll to Smartsheet. | |
73+
74+
### JSON example
75+
76+
<CodeBlock language="json">{MyComponentSource}</CodeBlock>
77+
78+
<a href="/files/c2c/smartsheet/example.json" target="_blank">Download example</a>
79+
80+
### Terraform example
81+
82+
<CodeBlock language="json">{TerraformExample}</CodeBlock>
83+
84+
<a href="/files/c2c/smartsheet/example.tf" target="_blank">Download example</a>
85+
86+
## FAQ
87+
88+
:::info
89+
Click [here](/docs/c2c/info) for more information about Cloud-to-Cloud sources.
90+
:::

sidebars.ts

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -458,6 +458,7 @@ module.exports = {
458458
'send-data/hosted-collectors/cloud-to-cloud-integration-framework/salesforce-source',
459459
'send-data/hosted-collectors/cloud-to-cloud-integration-framework/sentinelone-mgmt-api-source',
460460
'send-data/hosted-collectors/cloud-to-cloud-integration-framework/slack-source',
461+
'send-data/hosted-collectors/cloud-to-cloud-integration-framework/smartsheet-source',
461462
'send-data/hosted-collectors/cloud-to-cloud-integration-framework/snowflake-sql-api-source',
462463
'send-data/hosted-collectors/cloud-to-cloud-integration-framework/sophos-central-source',
463464
//'send-data/hosted-collectors/cloud-to-cloud-integration-framework/sumo-logic-kickstart-data-source',
Lines changed: 16 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,16 @@
1+
{
2+
"api.version": "v1",
3+
"source": {
4+
"schemaRef": {
5+
"type": "Smartsheet"
6+
},
7+
"config": {
8+
"name": "smartsheet",
9+
"app_client_id": "<your client id>",
10+
"client_secret": "***********",
11+
"authorization_code": "***********",
12+
"polling_interval": 10
13+
},
14+
"sourceType": "Universal"
15+
}
16+
}
Lines changed: 17 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,17 @@
1+
resource "sumologic_cloud_to_cloud_source" "lastpass-source" {
2+
collector_id = sumologic_collector.collector.id
3+
schema_ref = {
4+
type = "Smartsheet"
5+
}
6+
config = jsonencode({
7+
"name": "smartsheet",
8+
"app_client_id": "<your client id>",
9+
"client_secret": "***********",
10+
"authorization_code": "***********",
11+
"polling_interval": 10
12+
})
13+
}
14+
resource "sumologic_collector" "collector" {
15+
name = "my-collector"
16+
description = "Just testing this"
17+
}

0 commit comments

Comments
 (0)