Skip to content

Commit 662a0cf

Browse files
authored
Merge branch 'main' into docs-233-soc-analyst-agent-beta
2 parents a340168 + abd7139 commit 662a0cf

File tree

468 files changed

+3613
-1899
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

468 files changed

+3613
-1899
lines changed

.clabot

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -193,7 +193,9 @@
193193
"rmeyer-legato",
194194
"jagan2221",
195195
"pankaj101A",
196-
"prajalb"
196+
"prajalb",
197+
"dk-logic",
198+
"keshavm021"
197199
],
198200
"message": "Thank you for your contribution! As this is an open source project, we require contributors to sign our Contributor License Agreement and do not have yours on file. To proceed with your PR, please [sign your name here](https://forms.gle/YgLddrckeJaCdZYA6) and we will add you to our approved list of contributors.",
199201
"label": "cla-signed",

.github/CODEOWNERS

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -13,4 +13,4 @@
1313
/docs/send-data/opentelemetry-collector/ @SumoLogic/open-source-collection-team @kimsauce @jpipkin1 @mafsumo @JV0812 @amee-sumo
1414

1515
# GitHub workflow owners
16-
/.github/workflows/ @SumoLogic/open-source-collection-team @kimsauce
16+
/.github/workflows/ @kimsauce

.github/workflows/build_and_deploy.yml

Lines changed: 0 additions & 85 deletions
This file was deleted.

.github/workflows/delete-review.yml

Lines changed: 0 additions & 40 deletions
This file was deleted.

.github/workflows/job_build-site.yml

Lines changed: 2 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -27,13 +27,10 @@ jobs:
2727
with:
2828
node-version: '20.x'
2929
cache: 'yarn'
30-
- name: Docusaurus Webpack cache
31-
uses: actions/cache@v3
32-
with:
33-
path: node_modules/.cache
34-
key: ${{ runner.os }}-webpack-cache-${{ hashFiles('yarn.lock') }}
3530
- name: Install dependencies
3631
run: yarn install --frozen-lockfile
32+
- name: Clean Docusaurus cache
33+
run: rm -rf .docusaurus build
3734
- name: Build the Docusaurus site
3835
run: |
3936
yarn build

.github/workflows/production.yml

Lines changed: 0 additions & 21 deletions
This file was deleted.

blog-cse/2025-10-28-content.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -12,7 +12,7 @@ This content release includes:
1212
- Updates to existing mappers for Crowdstrike Falcon, F5, and Okta events to support additional fields and events.
1313
- Updates to F5 Networks and Okta SSO parsers.
1414

15-
Changes are enumerated below.
15+
This new and updated content is effective as of October 22, 2025. Changes are enumerated below.
1616

1717
### Log Mappers
1818
- [New] CrowdStrike Falcon Host API IdpDetectionSummaryEvent

blog-cse/2025-10-29-content.md

Lines changed: 22 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,22 @@
1+
---
2+
title: October 29, 2025 - Content Release
3+
image: https://assets-www.sumologic.com/company-logos/_800x418_crop_center-center_82_none/SumoLogic_Preview_600x600.jpg?mtime=1617040082
4+
keywords:
5+
- log mappers
6+
- parsers
7+
hide_table_of_contents: true
8+
---
9+
10+
This content release includes:
11+
- New log mappers for Crowdstrike Falcon to support eppDetectionSummary events from multiple ingest methods.
12+
- New parsers and log mappers for Databricks Audit logs and Varonis Alerts.
13+
14+
## Log Mappers
15+
- [New] CrowdStrike Falcon - EppDetectionSummaryEvents (CNC)
16+
- [New] DataBricks Audit Catch All
17+
- [New] DataBricks Authentication
18+
- [New] Varonis Alerts Catch All
19+
20+
## Parsers
21+
- [New] /Parsers/System/Databricks/Databricks Audit
22+
- [New] /Parsers/System/Varonis/Varonis Alert JSON

blog-cse/2025-11-06-content.md

Lines changed: 37 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,37 @@
1+
---
2+
title: November 6, 2025 - Content Release
3+
image: https://assets-www.sumologic.com/company-logos/_800x418_crop_center-center_82_none/SumoLogic_Preview_600x600.jpg?mtime=1617040082
4+
keywords:
5+
- log mappers
6+
- parsers
7+
- rules
8+
hide_table_of_contents: true
9+
---
10+
11+
This content release includes:
12+
- An updated parser and new log mappers for Netskope Cloud Security for improved handling of Netskope DLP logs.
13+
- An updated mapper for Azure Audit Logs which repurposes the `changeTarget` field mapping for changed items such as groups.
14+
- Updated Azure rules to accommodate the repurposed `changeTarget` field
15+
- Updated Keeper Authentication mapper to include the `Success` field.
16+
17+
:::note
18+
If you are ingesting Netskope Cloud Security Logs or Azure Audit Logs ensure that the log source is set to use the appropriate system parser:
19+
- Netskope Cloud Security: /Parsers/System/Netskope/Netskope Security Cloud JSON
20+
- Azure Audit Logs: /Parsers/System/Microsoft/Microsoft Azure JSON
21+
:::
22+
23+
### Rules
24+
- [Updated] MATCH-S00226 Azure - Add Member to Group
25+
- [Updated] MATCH-S00220 Azure - Add Member to Role Outside of PIM
26+
- [Updated] MATCH-S00231 Azure - Member Added to Global Administrator Role
27+
- [Updated] MATCH-S00233 Azure - Member Added to Global Administrator Role Non-PIM
28+
- [Updated] MATCH-S00229 Azure - Member Added to Non-Global Administrator Role
29+
30+
### Log Mappers
31+
- [New] Netskope - DLP Alerts
32+
- [New] Netskope - Incidents
33+
- [Updated] AzureActivityLog AuditLogs
34+
- [Updated] Keeper Authentication
35+
36+
### Parsers
37+
- [Updated] /Parsers/System/Netskope/Netskope Security Cloud JSON

blog-cse/2025-11-14-content.md

Lines changed: 44 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,44 @@
1+
---
2+
title: November 14, 2025 - Content Release
3+
image: https://assets-www.sumologic.com/company-logos/_800x418_crop_center-center_82_none/SumoLogic_Preview_600x600.jpg?mtime=1617040082
4+
keywords:
5+
- log mappers
6+
- parsers
7+
- rules
8+
hide_table_of_contents: true
9+
---
10+
11+
This content release includes:
12+
- Updates to Microsoft Azure rules so rule summaries contain richer information around groups and roles that have been modified.
13+
- New and updated mappers for various products, including new support for PingIdentity MFA logs, better handling of severity scores for Netskope DLP alerts, and improved entity handling for Okta logs.
14+
- New and updated parsers, including new support for PingIdentity MFA logs and improved parsing for Netskope DLP events.
15+
16+
Changes are enumerated below.
17+
18+
### Rules
19+
- [Updated] MATCH-S00226 Azure - Add Member to Group
20+
- [Updated] MATCH-S00220 Azure - Add Member to Role Outside of PIM
21+
- [Updated] MATCH-S00231 Azure - Member Added to Global Administrator Role
22+
- [Updated] MATCH-S00233 Azure - Member Added to Global Administrator Role Non-PIM
23+
- [Updated] MATCH-S00229 Azure - Member Added to Non-Global Administrator Role
24+
25+
### Log Mappers
26+
- [New] Netskope - DLP Alerts
27+
- [New] Netskope - Incidents
28+
- [New] PingIdentity MFA - Authentication Event
29+
- [New] PingIdentity MFA - Catch All
30+
- [Updated] AzureActivityLog AuditLogs
31+
- [Updated] Keeper Authentication
32+
- [Updated] Netskope - Alerts
33+
- [Updated] Netskope - Catch All
34+
- [Updated] Okta Authentication - auth_via_AD_agent
35+
- [Updated] Okta Authentication - auth_via_mfa
36+
- [Updated] Okta Authentication - auth_via_radius
37+
- [Updated] Okta Authentication - sso
38+
- [Updated] Okta Authentication Events
39+
- [Updated] Okta Catch All
40+
- [Updated] Okta Security Threat Events
41+
42+
### Parsers
43+
- [New] /Parsers/System/PingIdentity/PingIdentity MFA
44+
- [Updated] /Parsers/System/Netskope/Netskope Security Cloud JSON

0 commit comments

Comments
 (0)