Skip to content

Commit 404865f

Browse files
authored
Merge branch 'main' into docs-815-threatlookup-operator
2 parents 08d8024 + e745718 commit 404865f

File tree

256 files changed

+7462
-7829
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

256 files changed

+7462
-7829
lines changed
File renamed without changes.

blog-collector/2025-05-14.md

Lines changed: 17 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,17 @@
1+
---
2+
title: Version 19.525-42
3+
hide_table_of_contents: true
4+
image: https://help.sumologic.com/img/sumo-square.png
5+
---
6+
7+
import useBaseUrl from '@docusaurus/useBaseUrl';
8+
9+
In this release, we've enhanced the security and stability of the Collector with added support for security patches and a bug fix.
10+
11+
## Security Fix
12+
13+
- Upgraded `com.google.crypto.tink` to version 1.16.0 to address protobuf-java DOS vulnerability (CVE-2024-7254).
14+
15+
## Bug Fix
16+
17+
- Fixed the improper filtering of `AD` objects when `Exclude Distinguished Name Suffixes` filter is configured.

blog-cse/2025-05-09-content.md

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -21,7 +21,6 @@ This release includes:
2121

2222
Changes are enumerated below.
2323

24-
2524
### Rules
2625
- [New] OUTLIER-S00033 AWS DynamoDB Outlier in PutItem Events from User
2726
- [Disabled by Default] This rule detects an unusual amount of PutItem events to a DynamoDB resource within an hour time period (DynamoDB data events are required). Verify the user is authorized to modify the DynamoDB tables and instances. This rule is disabled by default due to potential volume of signals, before enabling consider excluding authorized users via match lists, and adjust floor value and model sensitivity as needed.

blog-cse/2025-05-23-content.md

Lines changed: 51 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,51 @@
1+
---
2+
title: May 23, 2025 - Content Release
3+
image: https://help.sumologic.com/img/sumo-square.png
4+
keywords:
5+
- log mappers
6+
- parsers
7+
- rules
8+
hide_table_of_contents: true
9+
---
10+
11+
import useBaseUrl from '@docusaurus/useBaseUrl';
12+
13+
This content release includes:
14+
- Rule update
15+
- New support for CommScope Ruckus SmartZone
16+
- Additional mappers for CrowdStrike FDR, Google G Suite (Workspace), and Windows PowerShell
17+
- Updates for existing mappers for CrowdStrike FDR, Google G Suite (Workspace), and Windows PowerShell
18+
- Added normalizedAction and action fields to Windows PowerShell mappers
19+
- Changes to Windows PowerShell JSON parsing to support additional log formats
20+
21+
Changes are enumerated below.
22+
23+
24+
### Rules
25+
- [Updated] MATCH-S00068 O365 - Users Password Changed
26+
- Updated to use targetUser_username
27+
28+
### Log mappers
29+
- [New] CommScope Ruckus SmartZone Default
30+
- [New] CrowdStrike FDR - DNSRequest
31+
- [New] Google G Suite - login - risky_sensitive_action_allowed
32+
- [New] Google G Suite - login challange
33+
- [New] Windows - Windows PowerShell
34+
- [Updated] CrowdStrike Falcon Host API DetectionSummaryEvent (CNC)
35+
- Added alternate field for threat_name
36+
- [Updated] CrowdStrike Falcon Host API IdpDetectionSummaryEvent (CNC)
37+
- Added alternate field for threat_name
38+
- [Updated] Google G Suite - login - password_change/recovery_info_change
39+
- Added additional mapped fields
40+
- [Updated] Google G Suite - login.login
41+
- Added additional mapped fields
42+
- [Updated] Google G Suite - logout
43+
- Added additional mapped fields
44+
- [Updated] Windows - Microsoft-Windows-PowerShell/Operational - 4103
45+
- [Updated] Windows - Microsoft-Windows-PowerShell/Operational - 4104
46+
- [Updated] Windows - Microsoft-Windows-PowerShell/Operational - 4105
47+
- [Updated] Windows - Microsoft-Windows-PowerShell/Operational - 4106
48+
49+
### Parsers
50+
- [New] /Parsers/System/CommScope/CommScope Ruckus SmartZone
51+
- [Updated] /Parsers/System/Microsoft/Windows PowerShell-JSON

blog-service/2025-02-25-apps.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -17,4 +17,4 @@ We've updated the onboarding experience to give you the option to bypass data co
1717

1818
A new **Go to App Catalog** option now appears in the left-hand menu on the data setup page, allowing you to browse integrations and pre-built dashboards before configuring data ingestion. This change makes it easier to explore Sumo Logic’s capabilities without committing to a full setup.
1919

20-
To learn more, check out our [quickstart](/docs/get-started/quickstart) and [signup](/docs/get-started/sign-up/#set-up-data-collection) guides.
20+
To learn more, check out our [quickstart](/docs/get-started/quickstart) and [signup](/docs/get-started/sign-up) guides.

blog-service/2025-05-13-apps.md

Lines changed: 12 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,12 @@
1+
---
2+
title: Bitwarden (Apps)
3+
image: https://help.sumologic.com/img/sumo-square.png
4+
keywords:
5+
- apps
6+
- bitwarden
7+
hide_table_of_contents: true
8+
---
9+
10+
import useBaseUrl from '@docusaurus/useBaseUrl';
11+
12+
We're excited to introduce the new Bitwarden app for Sumo Logic. This app enables threat detection and identification of high-risk events such as vault exports or SSO deactivation, supporting continuous monitoring and accelerating incident response for credential and secret management workflows. [Learn more](/docs/integrations/saas-cloud/bitwarden).
Lines changed: 19 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,19 @@
1+
---
2+
title: New Sumo Logic Onboarding Experience (Get Started)
3+
image: https://help.sumologic.com/img/sumo-square.png
4+
keywords:
5+
- onboarding
6+
- trial
7+
hide_table_of_contents: true
8+
---
9+
10+
We’ve launched a new **Get Started** onboarding page to help you hit the ground running in Sumo Logic. This personalized hub replaces the previous checklist and guides you through key actions such as:
11+
12+
* Ingesting cloud, SaaS, or on-prem log data with just a few clicks.
13+
* Exploring Kickstart Data dashboards with simulated real-world insights—no setup needed.
14+
* Installing curated apps from the App Catalog.
15+
* Using LiveTail to view real-time logs.
16+
* Inviting teammates to collaborate.
17+
* Navigating to the in-app pricing page to upgrade your plan.
18+
19+
This redesigned experience simplifies setup, accelerates time to value, and provides clear next steps to help you make the most of your trial. [Learn more](/docs/get-started/quickstart).
Lines changed: 12 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,12 @@
1+
---
2+
title: Akamai CPC Source (Collection)
3+
image: https://help.sumologic.com/img/sumo-square.png
4+
keywords:
5+
- c2c
6+
- akamai-cpc-source
7+
hide_table_of_contents: true
8+
---
9+
10+
import useBaseUrl from '@docusaurus/useBaseUrl';
11+
12+
We're excited to announce the release of our new cloud-to-cloud source for Akamai CPC. This source aims to collect CPC-Configs, CPC-Alerts, and CPC-Alert Details data from the Akamai platform and send them to Sumo Logic for streamlined analysis. [Learn more](/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/akamai-cpc-source).

blog-service/2025-05-21-apps.md

Lines changed: 12 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,12 @@
1+
---
2+
title: Kaltura (Apps)
3+
image: https://help.sumologic.com/img/sumo-square.png
4+
keywords:
5+
- apps
6+
- kaltura
7+
hide_table_of_contents: true
8+
---
9+
10+
import useBaseUrl from '@docusaurus/useBaseUrl';
11+
12+
We're excited to introduce the new Kaltura app for Sumo Logic. This app enables you to gain valuable insights into the critical aspects of your platform operations, such as total entries, user activity trends, and event distributions, helping you monitor, secure, and optimize your content management strategies effectively. [Learn more](/docs/integrations/saas-cloud/kaltura).
Lines changed: 12 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,12 @@
1+
---
2+
title: Snowflake Logs Source (Collection)
3+
image: https://help.sumologic.com/img/sumo-square.png
4+
keywords:
5+
- c2c
6+
- snowflake-logs-source
7+
hide_table_of_contents: true
8+
---
9+
10+
import useBaseUrl from '@docusaurus/useBaseUrl';
11+
12+
We're excited to announce the release of our new cloud-to-cloud source for Snowflake Logs. This source aims to collect the row data from the supported global tables (`QUERY_HISTORY`, `LOGIN_HISTORY`, `SESSIONS`, `GRANTS_TO_USERS`, `DATA_TRANSFER_HISTORY`, `STAGES`, and Custom Events) from the Snowflake platform and send them to Sumo Logic for streamlined analysis. [Learn more](/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/snowflake-logs-source).

0 commit comments

Comments
 (0)