File tree Expand file tree Collapse file tree 1 file changed +37
-0
lines changed Expand file tree Collapse file tree 1 file changed +37
-0
lines changed Original file line number Diff line number Diff line change 1+ ---
2+ title : November 6, 2025 - Content Release
3+ image : https://assets-www.sumologic.com/company-logos/_800x418_crop_center-center_82_none/SumoLogic_Preview_600x600.jpg?mtime=1617040082
4+ keywords :
5+ - log mappers
6+ - parsers
7+ - rules
8+ hide_table_of_contents : true
9+ ---
10+
11+ This content release includes:
12+ - An updated parser and new log mappers for Netskope Cloud Security for improved handling of Netskope DLP logs.
13+ - An updated mapper for Azure Audit Logs which repurposes the ` changeTarget ` field mapping for changed items such as groups.
14+ - Updated Azure rules to accommodate the repurposed ` changeTarget ` field
15+ - Updated Keeper Authentication mapper to include the ` Success ` field.
16+
17+ ::: note
18+ If you are ingesting Netskope Cloud Security Logs or Azure Audit Logs ensure that the log source is set to use the appropriate system parser:
19+ - Netskope Cloud Security: /Parsers/System/Netskope/Netskope Security Cloud JSON
20+ - Azure Audit Logs: /Parsers/System/Microsoft/Microsoft Azure JSON
21+ :::
22+
23+ ### Rules
24+ - [ Updated] MATCH-S00226 Azure - Add Member to Group
25+ - [ Updated] MATCH-S00220 Azure - Add Member to Role Outside of PIM
26+ - [ Updated] MATCH-S00231 Azure - Member Added to Global Administrator Role
27+ - [ Updated] MATCH-S00233 Azure - Member Added to Global Administrator Role Non-PIM
28+ - [ Updated] MATCH-S00229 Azure - Member Added to Non-Global Administrator Role
29+
30+ ### Log Mappers
31+ - [ New] Netskope - DLP Alerts
32+ - [ New] Netskope - Incidents
33+ - [ Updated] AzureActivityLog AuditLogs
34+ - [ Updated] Keeper Authentication
35+
36+ ### Parsers
37+ - [ Updated] /Parsers/System/Netskope/Netskope Security Cloud JSON
You can’t perform that action at this time.
0 commit comments