Skip to content

Commit 402659a

Browse files
authored
Merge branch 'main' into aws-iam-changes
2 parents 3c18873 + 714d81b commit 402659a

File tree

90 files changed

+1139
-329
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

90 files changed

+1139
-329
lines changed

blog-cse/2025-08-15-content.md

Lines changed: 41 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,41 @@
1+
---
2+
title: August 15, 2025 - Content Release
3+
image: https://help.sumologic.com/img/reuse/rss-image.jpg
4+
keywords:
5+
- log mappers
6+
- parsers
7+
hide_table_of_contents: true
8+
---
9+
10+
This content release includes:
11+
- New product support for Vectra AI.
12+
- Updated parsers and log mappers for Azure Event Hub, Barracuda CloudGen Firewall, Microsoft IIS, and Surepass.
13+
- Updated Surepass to the correct vendor name.
14+
15+
Changes are enumerated below.
16+
17+
### Log Mappers
18+
- [New] Vectra AI Catch All
19+
- [New] Vectra AI User Login
20+
- [Updated] Azure Event Hub - Windows Defender Logs
21+
- Updated field mappings to include new fields.
22+
- [Updated] Barracuda CloudGen Firewall Activity
23+
- Updated `event_id` criteria to handle abridged event types in some logs.
24+
- [Updated] Microsoft IIS Parser - Catch All
25+
- Updated to support `http_url` and downstream enrichment.
26+
- [Updated] Surepass Authentication
27+
- [Updated] Surepass Catch All
28+
- [Updated] Surepass Network Event
29+
30+
### Parsers
31+
- [New] /Parsers/System/Vectra/Vectra AI
32+
- [Updated] /Parsers/System/Barracuda/Barracuda CloudGen
33+
- Updated `event_id` criteria to handle abridged event types in some logs and to support additional log formats.
34+
- [Updated] /Parsers/System/Cylance/Cylance Syslog
35+
- Updated timestamp parsing.
36+
- [Updated] /Parsers/System/DocuSign/DocuSign Monitor
37+
- Updated timestamp parsing.
38+
- [Updated] /Parsers/System/Microsoft/Microsoft Azure JSON
39+
- Updated parser to parse additional nested fields.
40+
- [Updated] /Parsers/System/Microsoft/Microsoft IIS
41+
- Updated to form `http_url` for downstream enrichment.

blog-cse/2025-08-19-application.md

Lines changed: 23 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,23 @@
1+
---
2+
title: August 19, 2025 - Application Update
3+
image: https://help.sumologic.com/img/reuse/rss-image.jpg
4+
keywords:
5+
- taxii
6+
- threat intelligence
7+
hide_table_of_contents: true
8+
---
9+
10+
import useBaseUrl from '@docusaurus/useBaseUrl';
11+
12+
### New TAXII 2 Threat Intelligence Sources
13+
14+
We're excited to announce the following new threat intelligence sources that allow you to collect TAXII feeds with greater ease. These sources are based on the underlying code of our STIX/TAXII 2 Client Source, but are tailored for each of the vendors to facilitate setup:
15+
* CISA TAXII Client
16+
* Dragos TAXII Client
17+
* Nozomi TAXII Client
18+
* Recorded Future TAXII Client
19+
* Unit42 TAXII Client
20+
21+
When you set up a source, search for "taxii" and select the tile for the source you want to install:<br/><img src={useBaseUrl('img/security/taxii-sources.png')} alt="TAXII sources" style={{border: '1px solid gray'}} width="800" />
22+
23+
[Learn more](/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/stix-taxii-2-client-source/#taxii-2-sources).

blog-cse/2025-08-20-content.md

Lines changed: 15 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,15 @@
1+
---
2+
title: August 20, 2025 - Content Release
3+
image: https://help.sumologic.com/img/reuse/rss-image.jpg
4+
keywords:
5+
- log mappers
6+
hide_table_of_contents: true
7+
---
8+
9+
This content release includes new log mappers to cover additional security finding sources collected via AWS Security Hub.
10+
11+
### Log Mappers
12+
- [New] AWS GuardDuty - OCSF Finding Events
13+
- [New] AWS Inspector - OCSF Finding Events
14+
- [New] AWS Security Hub Coverage - OCSF Finding Events
15+
- [New] AWS Security Hub Exposure Detection - OCSF Finding Events
Lines changed: 12 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,12 @@
1+
---
2+
title: ExtraHop RevealX 360 (Apps)
3+
image: https://help.sumologic.com/img/reuse/rss-image.jpg
4+
keywords:
5+
- apps
6+
- extrahop-revealx-360
7+
hide_table_of_contents: true
8+
---
9+
10+
import useBaseUrl from '@docusaurus/useBaseUrl';
11+
12+
We're excited to introduce the new ExtraHop RevealX 360 app for Sumo Logic, which enables you to gain real-time visibility into your security hub findings data. This app can help security teams to monitor detection trends, track changes in risk levels, and gain insights into the most frequently observed MITRE techniques, top destination devices, and key targets on the network. [Learn more](/docs/integrations/webhooks/extrahop-revealx-360).

blog-service/2025-08-20-apps.md

Lines changed: 12 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,12 @@
1+
---
2+
title: Vectra (Apps)
3+
image: https://help.sumologic.com/img/reuse/rss-image.jpg
4+
keywords:
5+
- apps
6+
- vectra
7+
hide_table_of_contents: true
8+
---
9+
10+
import useBaseUrl from '@docusaurus/useBaseUrl';
11+
12+
We're excited to introduce the new Vectra app for Sumo Logic. This app leverages the Sumo Logic Cloud-to-Cloud [Vectra source](/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/vectra-source/) to collect the detections from the Vectra platform. It provides security analysts with visibility into security threats detected across networks, cloud environments, and endpoints. [Learn more](/docs/integrations/saas-cloud/vectra/).

cid-redirects.json

Lines changed: 15 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1479,6 +1479,7 @@
14791479
"/Dashboards-and-Alerts/Dashboards/Chart-Panel-Types": "/docs/dashboards/panels",
14801480
"/Dashboards-and-Alerts/Dashboards/Chart-Panel-Types/Area-Charts": "/docs/dashboards/panels/area-charts",
14811481
"/Dashboards_and_Alerts/Dashboards/Chart_Panel_Types/Line_Charts": "/docs/dashboards/panels/line-charts",
1482+
"/Dashboards-and-Alerts/Dashboards/Edit-Dashboards-and-Panels/Change-Gridlines-on-the-Y-Axis": "/docs/dashboards/panels",
14821483
"/Dashboards-and-Alerts/Dashboards/Edit-Dashboards-and-Panels/Change-the-Color-of-a-Chart-by-Value-Range-on-the-Search-Page": "/docs/dashboards",
14831484
"/Dashboards-and-Alerts/Dashboards/Edit-Dashboards-and-Panels/Change-the-Color-of-a-Chart": "/docs/dashboards",
14841485
"/Dashboards-and-Alerts/Dashboards/Get-Started-with-Dashboards-and-Panels/03Share-Dashboards": "/docs/manage/security/create-allowlist-ip-cidr-addresses",
@@ -1636,6 +1637,7 @@
16361637
"/cid/10210": "/docs/integrations/saas-cloud/proofpoint-tap",
16371638
"/cid/10202": "/docs/integrations/saas-cloud/mimecast",
16381639
"/cid/12222": "/docs/integrations/webhooks/snyk",
1640+
"/cid/12223": "/docs/integrations/webhooks/extrahop-revealx-360",
16391641
"/cid/1119": "/docs/integrations/saas-cloud/druva",
16401642
"/cid/10191": "/docs/integrations/saas-cloud/akamai-datastream",
16411643
"/cid/10194": "/docs/integrations/saas-cloud/proofpoint-on-demand",
@@ -1644,6 +1646,7 @@
16441646
"/cid/10211": "/docs/integrations/saas-cloud/microsoft-azure-ad-inventory",
16451647
"/cid/10203": "/docs/integrations/saas-cloud/microsoft-graph-security-v1",
16461648
"/cid/10205": "/docs/integrations/saas-cloud/microsoft-graph-security-v2",
1649+
"/cid/10212": "/docs/integrations/saas-cloud/vectra",
16471650
"/cid/10206": "/docs/integrations",
16481651
"/cid/10204": "/docs/integrations/saas-cloud/cato-networks",
16491652
"/cid/10198": "/docs/integrations/saas-cloud/microsoft-graph-azure-ad-reporting",
@@ -2832,7 +2835,7 @@
28322835
"/cid/15633": "/docs/c2c/info/",
28332836
"/cid/14323": "/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/docusign-source",
28342837
"/cid/14324": "/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/zendesk-source",
2835-
"/cid/14326": "/docs/integrations/global-intelligence/kubernetes-devops",
2838+
"/cid/14326": "/docs/integrations/global-intelligence",
28362839
"/cid/30001": "/docs/integrations/microsoft-azure/azure-batch",
28372840
"/cid/30002": "/docs/integrations/microsoft-azure/azure-application-gateway",
28382841
"/cid/30003": "/docs/integrations/microsoft-azure/azure-data-explorer",
@@ -3239,6 +3242,7 @@
32393242
"/Manage/Connections-and-Integrations/Webhook-Connections/Webhook_Connection_for_Datadog": "/docs/alerts/webhook-connections/datadog",
32403243
"/Manage/Connections-and-Integrations/Webhook-Connections/Webhook_Connection_for_HipChat": "/docs/alerts/webhook-connections",
32413244
"/Manage/Connections-and-Integrations/Webhook-Connections/Webhook_Connection_for_Microsoft_Azure_Functions": "/docs/alerts/webhook-connections/microsoft-azure-functions",
3245+
"/Manage/Connections-and-Integrations/Webhook-Connections/Webhook-Connection-for-Microsoft-Azure-Functions": "/docs/alerts/webhook-connections/microsoft-azure-functions",
32423246
"/Manage/Connections-and-Integrations/Webhook-Connections/Webhook_Connection_for_Microsoft_Teams": "/docs/alerts/webhook-connections/microsoft-teams",
32433247
"/Manage/Connections-and-Integrations/Webhook-Connections/Webhook_Connection_for_New_Relic": "/docs/alerts/webhook-connections/new-relic",
32443248
"/Manage/Connections_and_Integrations/Webhook_Connections/Webhook_Connection_for_New_Relic": "/docs/alerts/webhook-connections/new-relic",
@@ -3249,6 +3253,7 @@
32493253
"/Manage/Connections-and-Integrations/Webhook-Connections/Webhook_Connection_for_Slack": "/docs/alerts/webhook-connections/slack",
32503254
"/Manage/Connections-and-Integrations/Webhook-Connections/Webhook_Connections_for_Jira": "/docs/alerts/webhook-connections/jira-server",
32513255
"/Manage/Connections-and-Integrations/Webhook-Connections/Webhook_Connections_for_Jira/Webhook_Connection_for_Jira_Cloud": "/docs/alerts/webhook-connections/jira-cloud",
3256+
"/Manage/Connections-and-Integrations/Webhook-Connections/Webhook_Connections_for_Jira/Webhook_Connection_for_Jira_Server": "/docs/alerts/webhook-connections/jira-server",
32523257
"/Manage/Content_Sharing": "/docs/manage/content-sharing",
32533258
"/Manage/Content_Sharing/Share_Content": "/docs/manage/content-sharing",
32543259
"/Manage/Content_Sharing/Admin_Mode": "/docs/manage/content-sharing/admin-mode",
@@ -3558,7 +3563,7 @@
35583563
"/Observability_Solution/Kubernetes_Solution/04View_Sumo_Logic_Kubernetes_App_Dashboards": "/docs/observability/kubernetes/monitoring",
35593564
"/Observability_Solution/Kubernetes_Solution/05Kubernetes_Apps": "/docs/observability/kubernetes/apps",
35603565
"/Observability_Solution/Kubernetes_Solution/06Troubleshoot_with_Explore": "/docs/observability/kubernetes/troubleshoot-with-explore",
3561-
"/Observability_Solution/Kubernetes_Solution/07Global_Intelligence_for_Kubernetes_DevOps_App": "/docs/integrations/global-intelligence/kubernetes-devops",
3566+
"/Observability_Solution/Kubernetes_Solution/07Global_Intelligence_for_Kubernetes_DevOps_App": "/docs/integrations/global-intelligence",
35623567
"/Observability_Solution/Kubernetes_Solution/06Kubernetes_Alerts": "/docs/observability/kubernetes/alerts",
35633568
"/Observability_Solution/Kubernetes_Solution/08Next_Steps": "/docs/observability/kubernetes",
35643569
"/Observability_Solution/Kubernetes_Solution/09Create_a_New_Dashboard_(New)": "/docs/observability/kubernetes",
@@ -3631,6 +3636,8 @@
36313636
"/Send-Data/Sources": "/docs/send-data",
36323637
"/Send-Data/Sources/02Sources-for-Hosted-Collectors/Amazon_Web_Services": "/docs/send-data/hosted-collectors/amazon-aws",
36333638
"/Send-Data/Sources/02Sources-for-Hosted-Collectors/Amazon_Web_Services/AWS_S3_Source": "/docs/send-data/hosted-collectors/amazon-aws/aws-s3-source",
3639+
"/Send-Data/Source-FAQs/How-to-recurse-through-subdirectories-in-Amazon-S3-bucket-path-expressions": "/docs/send-data/hosted-collectors/amazon-aws/aws-s3-source",
3640+
"/Send-Data/Using-the-Collection-Page/Processing-Rules/Create-a-Processing-Rule": "/docs/send-data/collection/processing-rules/create-processing-rule",
36343641
"/Send_Data/Hosted_Collectors": "/docs/send-data/hosted-collectors",
36353642
"/Send_Data/Hosted_Collectors/Configure_a_Hosted_Collector": "/docs/send-data/hosted-collectors/configure-hosted-collector",
36363643
"/Send_Data/Local_Configuration_File_Management": "/docs/send-data/use-json-configure-sources/local-configuration-file-management/new-collectors-and-sources",
@@ -3851,6 +3858,7 @@
38513858
"/07Sumo-Logic-Apps/Messaging/ActiveMQ/ActiveMQ-App-Dashboards": "/docs/integrations/containers-orchestration/activemq",
38523859
"/07Sumo-Logic-Apps/22Security_and_Threat_Detection": "/docs/integrations/security-threat-detection",
38533860
"/07Sumo-Logic-Apps/22Security_and_Threat_Detection/Carbon_Black": "/docs/integrations/security-threat-detection/carbon-black-cloud",
3861+
"/07Sumo_Logic_Apps/22Security_and_Threat_Detection/Zscaler_Web_Security/Collect-Logs-for-Zscaler-Web-Security": "/docs/integrations/security-threat-detection/zscaler-internet-access",
38543862
"/07Sumo-Logic-Apps/24Web_Servers": "/docs/integrations/web-servers",
38553863
"/07Sumo-Logic-Apps/24Web_Servers/Apache/01-Collect-Logs-for-Apache": "/docs/integrations/web-servers/apache",
38563864
"/07Sumo-Logic-Apps/24Web_Servers/Elasticsearch": "/docs/integrations/databases/elasticsearch",
@@ -3978,7 +3986,8 @@
39783986
"/Observability_Solution/AWS_Observability_Solution/01_Deploy_and_Use_AWS_Observability/Root_Cause_Explorer": "/docs/observability/root-cause-explorer-deprecation",
39793987
"/docs/observability/root-cause-explorer": "/docs/observability/root-cause-explorer-deprecation",
39803988
"/Observability_Solution/Kubernetes_Solution/01Set_up_collection_for_Kubernetes": "/docs/observability/kubernetes/collection-setup",
3981-
"/Observability_Solution/Kubernetes_Solution/Global_Intelligence_for_Kubernetes_DevOps_App": "/docs/integrations/global-intelligence/kubernetes-devops",
3989+
"/Observability_Solution/Kubernetes_Solution/Global_Intelligence_for_Kubernetes_DevOps_App": "/docs/integrations/global-intelligence",
3990+
"/docs/integrations/global-intelligence/kubernetes-devops": "/docs/integrations/global-intelligence",
39823991
"/Observability_Solution/Kubernetes_Solution/Navigate_your_Kubernetes_environment": "/docs/observability/kubernetes",
39833992
"/Search/Get-Started-with-Search/How-to-Build-a-Search/Best-Practices:-7-Search-Rules-to-Live-By": "/docs/search/get-started-with-search/build-search/best-practices-search",
39843993
"/Search/Get-Started-with-Search/How-to-Build-a-Search/Search_Templates": "/docs/search/get-started-with-search/build-search/search-templates",
@@ -4022,6 +4031,7 @@
40224031
"/Search/Search_Query_Language/Search_Operators/Geo_Lookup": "/docs/search/search-query-language/search-operators/geo-lookup-map",
40234032
"/Search/Search-Query-Language/Search-Operators/Geo-Lookup-(Map)": "/docs/search/search-query-language/search-operators/geo-lookup-map",
40244033
"/Search/Search_Query_Language/Search_Operators/num": "/docs/search/search-query-language/search-operators/num",
4034+
"/Search/Search-Query-Language/Search-Operators/sessionize": "/docs/search/search-query-language/search-operators/sessionize",
40254035
"/Search/Search_Query_Language/Search_Operators/outlier": "/docs/search/search-query-language/search-operators/outlier",
40264036
"/Search/Search_Query_Language/Search_Operators/where": "/docs/search/search-query-language/search-operators/where",
40274037
"/Search/Search_Query_Language/Transaction_Analytics": "/docs/search/search-query-language/transaction-analytics",
@@ -4083,6 +4093,7 @@
40834093
"/Send_Data/Installed_Collectors/Configure_Limits_for_Collector_Caching": "/docs/send-data/installed-collectors/configuration",
40844094
"/Send_Data/Installed_Collectors/Supporting_Information_for_Collector_Installation/Set_a_Collector_as_Ephemeral": "/docs/send-data/installed-collectors/collector-installation-reference/set-collector-as-ephemeral",
40854095
"/Send_Data/Sources/02Sources_for_Hosted_Collectors/AWS_S3_Source": "/docs/send-data/hosted-collectors/amazon-aws/aws-s3-source",
4096+
"/Send_Data/Sources/02Sources_for_Hosted_Collectors/Amazon_S3_Audit_Source": "/docs/send-data/hosted-collectors/amazon-aws/amazon-s3-audit-source",
40864097
"/Send_Data/Sources/02Sources_for_Hosted_Collectors/AWS_IP_Address_Range": "/docs/send-data/hosted-collectors/amazon-aws",
40874098
"/Send_Data/Sources/02Sources_for_Hosted_Collectors/Grant_Access_to_an_AWS_S3_Bucket": "/docs/send-data/hosted-collectors/amazon-aws/grant-access-aws-product",
40884099
"/Send_Data/Sources/02Sources_for_Hosted_Collectors/HTTP_Source": "/docs/send-data/hosted-collectors/http-source",
@@ -4211,6 +4222,7 @@
42114222
"/Solutions/Kubernetes_Solution/15Save_and_share_dashboards": "/docs/observability/kubernetes",
42124223
"/Solutions/Kubernetes_Solution/01Set_up_collection_for_Kubernetes": "/docs/observability/kubernetes/collection-setup",
42134224
"/Solutions/Kubernetes_Solution/02Set_up_collection_for_Kubernetes": "/docs/observability/kubernetes/collection-setup",
4225+
"/Solutions/Kubernetes_Solution/06Troubleshoot_with_Explore": "/docs/observability/kubernetes/troubleshoot-with-explore",
42144226
"/Solutions/Kubernetes_Solution/08Kubernetes_and_Dashboard_(Beta)!": "/docs/observability/kubernetes/monitoring",
42154227
"/Solutions/Software_Development_Optimization_Solution": "/docs/observability/sdo",
42164228
"/Solutions/Work_from_Home_Solution": "/docs/observability/work-from-home-vpn",

docs/api/about-apis/getting-started.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -15,9 +15,9 @@ Sumo Logic APIs follow Representational State Transfer (REST) patterns and are o
1515

1616
## Documentation
1717

18-
To view our main docs, click the link below corresponding to your deployment. If you're not sure, see [How to determine your endpoint](#which-endpoint-should-i-should-use).
18+
To access our API documentation, navigate to the appropriate link based on your Sumo Logic deployment. If you're not sure, see [Which endpoint should I use?](#which-endpoint-should-i-should-use)
1919

20-
| Deployment | API Docs URL |
20+
| Deployment | API documentation URL |
2121
|:-----------|:----------------------------------|
2222
| AU | https://api.au.sumologic.com/docs/ |
2323
| CA | https://api.ca.sumologic.com/docs/ |

0 commit comments

Comments
 (0)