Skip to content

Commit 5235953

Browse files
authored
Merge branch 'main' into mssp-dashboard
2 parents 7086d52 + 41267ad commit 5235953

File tree

60 files changed

+899
-60
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

60 files changed

+899
-60
lines changed

blog-cse/2025-08-19-application.md

Lines changed: 23 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,23 @@
1+
---
2+
title: August 19, 2025 - Application Update
3+
image: https://help.sumologic.com/img/reuse/rss-image.jpg
4+
keywords:
5+
- taxii
6+
- threat intelligence
7+
hide_table_of_contents: true
8+
---
9+
10+
import useBaseUrl from '@docusaurus/useBaseUrl';
11+
12+
### New TAXII 2 Threat Intelligence Sources
13+
14+
We're excited to announce the following new threat intelligence sources that allow you to collect TAXII feeds with greater ease. These sources are based on the underlying code of our STIX/TAXII 2 Client Source, but are tailored for each of the vendors to facilitate setup:
15+
* CISA TAXII Client
16+
* Dragos TAXII Client
17+
* Nozomi TAXII Client
18+
* Recorded Future TAXII Client
19+
* Unit42 TAXII Client
20+
21+
When you set up a source, search for "taxii" and select the tile for the source you want to install:<br/><img src={useBaseUrl('img/security/taxii-sources.png')} alt="TAXII sources" style={{border: '1px solid gray'}} width="800" />
22+
23+
[Learn more](/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/stix-taxii-2-client-source/#taxii-2-sources).

blog-cse/2025-08-20-content.md

Lines changed: 15 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,15 @@
1+
---
2+
title: August 20, 2025 - Content Release
3+
image: https://help.sumologic.com/img/reuse/rss-image.jpg
4+
keywords:
5+
- log mappers
6+
hide_table_of_contents: true
7+
---
8+
9+
This content release includes new log mappers to cover additional security finding sources collected via AWS Security Hub.
10+
11+
### Log Mappers
12+
- [New] AWS GuardDuty - OCSF Finding Events
13+
- [New] AWS Inspector - OCSF Finding Events
14+
- [New] AWS Security Hub Coverage - OCSF Finding Events
15+
- [New] AWS Security Hub Exposure Detection - OCSF Finding Events
Lines changed: 12 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,12 @@
1+
---
2+
title: ExtraHop RevealX 360 (Apps)
3+
image: https://help.sumologic.com/img/reuse/rss-image.jpg
4+
keywords:
5+
- apps
6+
- extrahop-revealx-360
7+
hide_table_of_contents: true
8+
---
9+
10+
import useBaseUrl from '@docusaurus/useBaseUrl';
11+
12+
We're excited to introduce the new ExtraHop RevealX 360 app for Sumo Logic, which enables you to gain real-time visibility into your security hub findings data. This app can help security teams to monitor detection trends, track changes in risk levels, and gain insights into the most frequently observed MITRE techniques, top destination devices, and key targets on the network. [Learn more](/docs/integrations/webhooks/extrahop-revealx-360).

blog-service/2025-08-20-apps.md

Lines changed: 12 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,12 @@
1+
---
2+
title: Vectra (Apps)
3+
image: https://help.sumologic.com/img/reuse/rss-image.jpg
4+
keywords:
5+
- apps
6+
- vectra
7+
hide_table_of_contents: true
8+
---
9+
10+
import useBaseUrl from '@docusaurus/useBaseUrl';
11+
12+
We're excited to introduce the new Vectra app for Sumo Logic. This app leverages the Sumo Logic Cloud-to-Cloud [Vectra source](/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/vectra-source/) to collect the detections from the Vectra platform. It provides security analysts with visibility into security threats detected across networks, cloud environments, and endpoints. [Learn more](/docs/integrations/saas-cloud/vectra/).

cid-redirects.json

Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1479,6 +1479,7 @@
14791479
"/Dashboards-and-Alerts/Dashboards/Chart-Panel-Types": "/docs/dashboards/panels",
14801480
"/Dashboards-and-Alerts/Dashboards/Chart-Panel-Types/Area-Charts": "/docs/dashboards/panels/area-charts",
14811481
"/Dashboards_and_Alerts/Dashboards/Chart_Panel_Types/Line_Charts": "/docs/dashboards/panels/line-charts",
1482+
"/Dashboards-and-Alerts/Dashboards/Edit-Dashboards-and-Panels/Change-Gridlines-on-the-Y-Axis": "/docs/dashboards/panels",
14821483
"/Dashboards-and-Alerts/Dashboards/Edit-Dashboards-and-Panels/Change-the-Color-of-a-Chart-by-Value-Range-on-the-Search-Page": "/docs/dashboards",
14831484
"/Dashboards-and-Alerts/Dashboards/Edit-Dashboards-and-Panels/Change-the-Color-of-a-Chart": "/docs/dashboards",
14841485
"/Dashboards-and-Alerts/Dashboards/Get-Started-with-Dashboards-and-Panels/03Share-Dashboards": "/docs/manage/security/create-allowlist-ip-cidr-addresses",
@@ -1636,6 +1637,7 @@
16361637
"/cid/10210": "/docs/integrations/saas-cloud/proofpoint-tap",
16371638
"/cid/10202": "/docs/integrations/saas-cloud/mimecast",
16381639
"/cid/12222": "/docs/integrations/webhooks/snyk",
1640+
"/cid/12223": "/docs/integrations/webhooks/extrahop-revealx-360",
16391641
"/cid/1119": "/docs/integrations/saas-cloud/druva",
16401642
"/cid/10191": "/docs/integrations/saas-cloud/akamai-datastream",
16411643
"/cid/10194": "/docs/integrations/saas-cloud/proofpoint-on-demand",
@@ -1644,6 +1646,7 @@
16441646
"/cid/10211": "/docs/integrations/saas-cloud/microsoft-azure-ad-inventory",
16451647
"/cid/10203": "/docs/integrations/saas-cloud/microsoft-graph-security-v1",
16461648
"/cid/10205": "/docs/integrations/saas-cloud/microsoft-graph-security-v2",
1649+
"/cid/10212": "/docs/integrations/saas-cloud/vectra",
16471650
"/cid/10206": "/docs/integrations",
16481651
"/cid/10204": "/docs/integrations/saas-cloud/cato-networks",
16491652
"/cid/10198": "/docs/integrations/saas-cloud/microsoft-graph-azure-ad-reporting",
@@ -3239,6 +3242,7 @@
32393242
"/Manage/Connections-and-Integrations/Webhook-Connections/Webhook_Connection_for_Datadog": "/docs/alerts/webhook-connections/datadog",
32403243
"/Manage/Connections-and-Integrations/Webhook-Connections/Webhook_Connection_for_HipChat": "/docs/alerts/webhook-connections",
32413244
"/Manage/Connections-and-Integrations/Webhook-Connections/Webhook_Connection_for_Microsoft_Azure_Functions": "/docs/alerts/webhook-connections/microsoft-azure-functions",
3245+
"/Manage/Connections-and-Integrations/Webhook-Connections/Webhook-Connection-for-Microsoft-Azure-Functions": "/docs/alerts/webhook-connections/microsoft-azure-functions",
32423246
"/Manage/Connections-and-Integrations/Webhook-Connections/Webhook_Connection_for_Microsoft_Teams": "/docs/alerts/webhook-connections/microsoft-teams",
32433247
"/Manage/Connections-and-Integrations/Webhook-Connections/Webhook_Connection_for_New_Relic": "/docs/alerts/webhook-connections/new-relic",
32443248
"/Manage/Connections_and_Integrations/Webhook_Connections/Webhook_Connection_for_New_Relic": "/docs/alerts/webhook-connections/new-relic",
@@ -3249,6 +3253,7 @@
32493253
"/Manage/Connections-and-Integrations/Webhook-Connections/Webhook_Connection_for_Slack": "/docs/alerts/webhook-connections/slack",
32503254
"/Manage/Connections-and-Integrations/Webhook-Connections/Webhook_Connections_for_Jira": "/docs/alerts/webhook-connections/jira-server",
32513255
"/Manage/Connections-and-Integrations/Webhook-Connections/Webhook_Connections_for_Jira/Webhook_Connection_for_Jira_Cloud": "/docs/alerts/webhook-connections/jira-cloud",
3256+
"/Manage/Connections-and-Integrations/Webhook-Connections/Webhook_Connections_for_Jira/Webhook_Connection_for_Jira_Server": "/docs/alerts/webhook-connections/jira-server",
32523257
"/Manage/Content_Sharing": "/docs/manage/content-sharing",
32533258
"/Manage/Content_Sharing/Share_Content": "/docs/manage/content-sharing",
32543259
"/Manage/Content_Sharing/Admin_Mode": "/docs/manage/content-sharing/admin-mode",
@@ -3631,6 +3636,8 @@
36313636
"/Send-Data/Sources": "/docs/send-data",
36323637
"/Send-Data/Sources/02Sources-for-Hosted-Collectors/Amazon_Web_Services": "/docs/send-data/hosted-collectors/amazon-aws",
36333638
"/Send-Data/Sources/02Sources-for-Hosted-Collectors/Amazon_Web_Services/AWS_S3_Source": "/docs/send-data/hosted-collectors/amazon-aws/aws-s3-source",
3639+
"/Send-Data/Source-FAQs/How-to-recurse-through-subdirectories-in-Amazon-S3-bucket-path-expressions": "/docs/send-data/hosted-collectors/amazon-aws/aws-s3-source",
3640+
"/Send-Data/Using-the-Collection-Page/Processing-Rules/Create-a-Processing-Rule": "/docs/send-data/collection/processing-rules/create-processing-rule",
36343641
"/Send_Data/Hosted_Collectors": "/docs/send-data/hosted-collectors",
36353642
"/Send_Data/Hosted_Collectors/Configure_a_Hosted_Collector": "/docs/send-data/hosted-collectors/configure-hosted-collector",
36363643
"/Send_Data/Local_Configuration_File_Management": "/docs/send-data/use-json-configure-sources/local-configuration-file-management/new-collectors-and-sources",
@@ -3851,6 +3858,7 @@
38513858
"/07Sumo-Logic-Apps/Messaging/ActiveMQ/ActiveMQ-App-Dashboards": "/docs/integrations/containers-orchestration/activemq",
38523859
"/07Sumo-Logic-Apps/22Security_and_Threat_Detection": "/docs/integrations/security-threat-detection",
38533860
"/07Sumo-Logic-Apps/22Security_and_Threat_Detection/Carbon_Black": "/docs/integrations/security-threat-detection/carbon-black-cloud",
3861+
"/07Sumo_Logic_Apps/22Security_and_Threat_Detection/Zscaler_Web_Security/Collect-Logs-for-Zscaler-Web-Security": "/docs/integrations/security-threat-detection/zscaler-internet-access",
38543862
"/07Sumo-Logic-Apps/24Web_Servers": "/docs/integrations/web-servers",
38553863
"/07Sumo-Logic-Apps/24Web_Servers/Apache/01-Collect-Logs-for-Apache": "/docs/integrations/web-servers/apache",
38563864
"/07Sumo-Logic-Apps/24Web_Servers/Elasticsearch": "/docs/integrations/databases/elasticsearch",
@@ -4023,6 +4031,7 @@
40234031
"/Search/Search_Query_Language/Search_Operators/Geo_Lookup": "/docs/search/search-query-language/search-operators/geo-lookup-map",
40244032
"/Search/Search-Query-Language/Search-Operators/Geo-Lookup-(Map)": "/docs/search/search-query-language/search-operators/geo-lookup-map",
40254033
"/Search/Search_Query_Language/Search_Operators/num": "/docs/search/search-query-language/search-operators/num",
4034+
"/Search/Search-Query-Language/Search-Operators/sessionize": "/docs/search/search-query-language/search-operators/sessionize",
40264035
"/Search/Search_Query_Language/Search_Operators/outlier": "/docs/search/search-query-language/search-operators/outlier",
40274036
"/Search/Search_Query_Language/Search_Operators/where": "/docs/search/search-query-language/search-operators/where",
40284037
"/Search/Search_Query_Language/Transaction_Analytics": "/docs/search/search-query-language/transaction-analytics",
@@ -4084,6 +4093,7 @@
40844093
"/Send_Data/Installed_Collectors/Configure_Limits_for_Collector_Caching": "/docs/send-data/installed-collectors/configuration",
40854094
"/Send_Data/Installed_Collectors/Supporting_Information_for_Collector_Installation/Set_a_Collector_as_Ephemeral": "/docs/send-data/installed-collectors/collector-installation-reference/set-collector-as-ephemeral",
40864095
"/Send_Data/Sources/02Sources_for_Hosted_Collectors/AWS_S3_Source": "/docs/send-data/hosted-collectors/amazon-aws/aws-s3-source",
4096+
"/Send_Data/Sources/02Sources_for_Hosted_Collectors/Amazon_S3_Audit_Source": "/docs/send-data/hosted-collectors/amazon-aws/amazon-s3-audit-source",
40874097
"/Send_Data/Sources/02Sources_for_Hosted_Collectors/AWS_IP_Address_Range": "/docs/send-data/hosted-collectors/amazon-aws",
40884098
"/Send_Data/Sources/02Sources_for_Hosted_Collectors/Grant_Access_to_an_AWS_S3_Bucket": "/docs/send-data/hosted-collectors/amazon-aws/grant-access-aws-product",
40894099
"/Send_Data/Sources/02Sources_for_Hosted_Collectors/HTTP_Source": "/docs/send-data/hosted-collectors/http-source",
@@ -4212,6 +4222,7 @@
42124222
"/Solutions/Kubernetes_Solution/15Save_and_share_dashboards": "/docs/observability/kubernetes",
42134223
"/Solutions/Kubernetes_Solution/01Set_up_collection_for_Kubernetes": "/docs/observability/kubernetes/collection-setup",
42144224
"/Solutions/Kubernetes_Solution/02Set_up_collection_for_Kubernetes": "/docs/observability/kubernetes/collection-setup",
4225+
"/Solutions/Kubernetes_Solution/06Troubleshoot_with_Explore": "/docs/observability/kubernetes/troubleshoot-with-explore",
42154226
"/Solutions/Kubernetes_Solution/08Kubernetes_and_Dashboard_(Beta)!": "/docs/observability/kubernetes/monitoring",
42164227
"/Solutions/Software_Development_Optimization_Solution": "/docs/observability/sdo",
42174228
"/Solutions/Work_from_Home_Solution": "/docs/observability/work-from-home-vpn",

docs/integrations/microsoft-azure/kubernetes.md

Lines changed: 11 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -41,6 +41,16 @@ The AKS - Control Plane app collects logs for the following [Azure Kubernetes Se
4141

4242
For more details on Azure Kubernetes Service logs and metrics, refer to the [Azure documentation](https://learn.microsoft.com/en-us/azure/aks/monitor-aks-reference).
4343

44+
## Setup
45+
46+
Azure service sends monitoring data to Azure Monitor, which can then [stream data to Eventhub](https://learn.microsoft.com/en-us/azure/azure-monitor/essentials/stream-monitoring-data-event-hubs).
47+
48+
You must explicitly enable diagnostic settings for each Kubernetes Service you want to monitor. You can forward logs to the same Event Hub provided they satisfy the limitations and permissions as described [here](https://learn.microsoft.com/en-us/azure/azure-monitor/essentials/diagnostic-settings?tabs=portal#destination-limitations).
49+
50+
Sumo Logic supports metrics collection using [Azure Metrics Source](/docs/send-data/hosted-collectors/microsoft-source/azure-metrics-source).
51+
52+
When you configure the Event Hubs source, plan your source category to ease the querying process. A hierarchical approach allows you to make use of wildcards. For example: `Azure/AKS/ControlPlane/Logs`.
53+
4454
### Sample log messages
4555

4656
```json title="kube-audit"
@@ -214,10 +224,8 @@ import MetricsSourceBeta from '../../reuse/metrics-source-beta.md';
214224
This section walks you through the process of configuring a pipeline to send logs from Azure Monitor to Sumo Logic.
215225

216226
1. To set up the logs collection in Sumo Logic, refer to [Azure Event Hubs Source for Logs](/docs/send-data/collect-from-other-data-sources/azure-monitoring/ms-azure-event-hubs-source/).
217-
218-
When you configure the event hubs source, plan your source category to ease the querying process. A hierarchical approach allows you to make use of wildcards. For example: `Azure/AKS/ControlPlane/Logs`.
219227

220-
Enable the Kubernetes master node logs in Azure Kubernetes Service to send logs to an event hub created in the previous step.
228+
Enable the Kubernetes master node logs in Azure Kubernetes Service to send logs to an Event Hub.
221229

222230
2. Push logs from Azure Monitor to Event Hub.
223231
1. Sign in to [Azure Portal](https://portal.azure.com/).

docs/integrations/product-list/product-list-a-l.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -219,7 +219,7 @@ For descriptions of the different types of integrations Sumo Logic offers, see [
219219
| <img src={useBaseUrl('img/integrations/misc/eset-logo.png')} alt="Thumbnail icon" width="75"/> | [ESET](https://www.eset.com/us/) | Cloud SIEM integration: [ESET](https://github.com/SumoLogic/cloud-siem-content-catalog/blob/master/vendors/ced86de0-64e4-4e7c-ae25-fb5b3dff3cb8.md) |
220220
| <img src={useBaseUrl('img/integrations/misc/exabeam-logo.svg')} alt="Thumbnail icon" width="75"/> | [Exabeam](https://www.exabeam.com/) | Cloud SIEM integration: [Exabeam](https://github.com/SumoLogic/cloud-siem-content-catalog/blob/master/vendors/9d2d799d-2d6c-4894-a46f-0cce00641bcb.md) |
221221
| <img src={useBaseUrl('img/platform-services/automation-service/app-central/logos/exploit-database.png')} alt="Thumbnail icon" width="75"/> | [Exploit Database](https://www.exploit-db.com/) | Automation integration: [Exploit Database](/docs/platform-services/automation-service/app-central/integrations/exploit-database/) |
222-
| <img src={useBaseUrl('img/integrations/misc/extrahop-logo.png')} alt="Thumbnail icon" width="100"/> | [ExtraHop](https://www.extrahop.com/) | Cloud SIEM integration: [Extrahop](https://github.com/SumoLogic/cloud-siem-content-catalog/blob/master/vendors/a8b03e2e-7497-4104-874d-cafd03aeb4c1.md) <br/>Community app: [Sumo Logic for ExtraHop Reveal(x) 360](https://github.com/SumoLogic/sumologic-content/tree/master/ExtraHop%20Reveal(x)%20360) |
222+
| <img src={useBaseUrl('img/integrations/misc/extrahop-logo.png')} alt="Thumbnail icon" width="100"/> | [ExtraHop](https://www.extrahop.com/) | App: [ExtraHop RevealX 360](/docs/integrations/webhooks/extrahop-revealx-360) <br/>- Cloud SIEM integration: [ExtraHop](https://github.com/SumoLogic/cloud-siem-content-catalog/blob/master/vendors/a8b03e2e-7497-4104-874d-cafd03aeb4c1.md) <br/>Community app: [Sumo Logic for ExtraHop Reveal(x) 360](https://github.com/SumoLogic/sumologic-content/tree/master/ExtraHop%20Reveal(x)%20360) |
223223

224224

225225
## F

0 commit comments

Comments
 (0)