Skip to content

Commit 8104cd7

Browse files
authored
Merge branch 'main' into berry
2 parents 2dc71f8 + 54e9bc6 commit 8104cd7

File tree

86 files changed

+1574
-693
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

86 files changed

+1574
-693
lines changed

.clabot

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -173,7 +173,8 @@
173173
"Misterjohnson87",
174174
"lol3909",
175175
"Hellfire4959",
176-
"antonymartinsumo"
176+
"antonymartinsumo",
177+
"amee-sumo"
177178
],
178179
"message": "Thank you for your contribution! As this is an open source project, we require contributors to sign our Contributor License Agreement and do not have yours on file. To proceed with your PR, please [sign your name here](https://forms.gle/YgLddrckeJaCdZYA6) and we'll add you to our approved list of contributors.",
179180
"label": "cla-signed",

blog-cse/2023/12-31.md

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -247,8 +247,6 @@ The new index is automatically generated and retained for a period of 2 years at
247247

248248
As a result, the optional legacy Signal Forwarding feature in Cloud SIEM will be deprecated on **November 15, 2023**. Existing data will not be deleted, but new Signals generated after that date will no longer be forwarded using that feature and the option will no longer be available. (Signals will continue to be forwarded automatically to `sec_signal`.) Customers leveraging data forwarded using the legacy feature to generate dashboards (or for other use cases) will need to modify those applications to use the new `sec_signal` index before then. Note that the content of the `sec_signal` index is not identical to the content in data forwarded using the legacy option.
249249

250-
For more information about this change, and the differences between the two data sets, refer to our [2023 Cloud SIEM Signal Index Migration FAQ](/docs/cse/records-signals-entities-insights/signal-index-migration-faq/).
251-
252250

253251

254252
---
Lines changed: 39 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,39 @@
1+
---
2+
title: November 15, 2024 - Application Update
3+
keywords:
4+
- sumo logic
5+
- cloud soar
6+
- automation service
7+
image: https://help.sumologic.com/img/sumo-square.png
8+
hide_table_of_contents: true
9+
---
10+
11+
import useBaseUrl from '@docusaurus/useBaseUrl';
12+
13+
<a href="https://help.sumologic.com/release-notes-csoar/rss.xml"><img src={useBaseUrl('img/release-notes/rss-orange2.png')} alt="icon" width="50"/></a>
14+
15+
### Changes and Enhancements
16+
17+
#### Platform
18+
19+
* Playbooks
20+
* Improvement - Disabled Cartesian Product flag on all new nodes by default.
21+
22+
#### Automation Bridge
23+
24+
We are happy to announce a beta version of the [Automation Bridge](/docs/platform-services/automation-service/automation-service-bridge/) that includes the following:
25+
* Support for new CentOS version
26+
* The CentOS docker image version has been upgraded from CentOS 7 to CentOS 8.
27+
* Security fixes
28+
29+
### Bug Fixes
30+
31+
* Playbooks
32+
* Fixed Playbook nodes rendering issue on Safari browser.
33+
* Fixed issue related to use of underscore within playbooks input fields.
34+
* Fixed issue with using authorizer value from playbook input variables in user choice node.
35+
* Integrations
36+
* Resolved an issue where the 'Close Insight' trigger action was not functioning as expected.
37+
* Incidents
38+
* Improved Incident templates page load time.
39+
* Fixed issues while trying to update Incident templates.

blog-csoar/2024-11-20-content.md

Lines changed: 46 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,46 @@
1+
---
2+
title: November 20, 2024 - Content Release
3+
hide_table_of_contents: true
4+
image: https://help.sumologic.com/img/sumo-square.png
5+
keywords:
6+
- automation service
7+
- cloud soar
8+
- soar
9+
---
10+
11+
import useBaseUrl from '@docusaurus/useBaseUrl';
12+
13+
<a href="https://help.sumologic.com/release-notes-csoar/rss.xml"><img src={useBaseUrl('img/release-notes/rss-orange2.png')} alt="icon" width="50"/></a>
14+
15+
This release introduces new integrations, new playbooks, and several updates.
16+
17+
### Integrations
18+
19+
* [New] [Google Chat](/docs/platform-services/automation-service/app-central/integrations/google-chat)
20+
* [New] [Malwarebytes Oneview](/docs/platform-services/automation-service/app-central/integrations/malwarebytes-oneview)
21+
* [New] [Silent Push](/docs/platform-services/automation-service/app-central/integrations/silent-push)
22+
* [New] [Sumo Logic Automation Tools](/docs/platform-services/automation-service/app-central/integrations/sumo-logic-automation-tools)
23+
* [New] [VirusTotal V3](/docs/platform-services/automation-service/app-central/integrations/virustotal-v3)
24+
* [Updated] [APIVoid](/docs/platform-services/automation-service/app-central/integrations/apivoid)
25+
* [Updated] [Atlassian Jira V2](/docs/platform-services/automation-service/app-central/integrations/atlassian-jira-v2)
26+
* [Updated] [Atlassian Opsgenie](/docs/platform-services/automation-service/app-central/integrations/atlassian-opsgenie)
27+
* [Updated] [AWS EC2](/docs/platform-services/automation-service/app-central/integrations/aws-ec2)
28+
* [Updated] [AWS EKS](/docs/platform-services/automation-service/app-central/integrations/aws-eks)
29+
* [Updated] [Azure AD](/docs/platform-services/automation-service/app-central/integrations/azure-ad)
30+
* [Updated] [Cloudflare](/docs/platform-services/automation-service/app-central/integrations/cloudflare)
31+
* [Updated] [ConnectWise Manage](/docs/platform-services/automation-service/app-central/integrations/connectwise-manage)
32+
* [Updated] [Cortex XDR](/docs/platform-services/automation-service/app-central/integrations/cortex-xdr)
33+
* [Updated] [CrowdStrike Falcon](/docs/platform-services/automation-service/app-central/integrations/crowdstrike-falcon)
34+
* [Updated] [Freshservice](/docs/platform-services/automation-service/app-central/integrations/freshservice)
35+
* [Updated] [Gmail](/docs/platform-services/automation-service/app-central/integrations/gmail)
36+
* [Updated] [HTTP Tools](/docs/platform-services/automation-service/app-central/integrations/http-tools)
37+
* [Updated] [IBM X-Force Exchange](/docs/platform-services/automation-service/app-central/integrations/ibm-x-force-exchange)
38+
* [Updated] [Microsoft EWS](/docs/platform-services/automation-service/app-central/integrations/microsoft-ews)
39+
* [Updated] [Microsoft OneDrive](/docs/platform-services/automation-service/app-central/integrations/microsoft-onedrive)
40+
* [Updated] [Microsoft Sentinel](/docs/platform-services/automation-service/app-central/integrations/microsoft-sentinel)
41+
* [Updated] [Netskope V2](/docs/platform-services/automation-service/app-central/integrations/netskope-v2)
42+
* [Updated] [Slack](/docs/platform-services/automation-service/app-central/integrations/slack)
43+
* [Updated] [Sumo Logic Cloud SIEM](/docs/platform-services/automation-service/app-central/integrations/sumo-logic-cloud-siem)
44+
* [Updated] [Sumo Logic Notifications by Gmail](/docs/platform-services/automation-service/app-central/integrations/sumo-logic-notifications-by-gmail)
45+
* [Updated] [URLScan.io](/docs/platform-services/automation-service/app-central/integrations/urlscan.io)
46+
* [Updated] [VirusTotal](/docs/platform-services/automation-service/app-central/integrations/virustotal)

blog-service/2024-11-12-search.md

Lines changed: 15 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,15 @@
1+
---
2+
title: scanned_partition_count Field Computation Change (Search)
3+
image: https://help.sumologic.com/img/sumo-square.png
4+
keywords:
5+
- count
6+
- search-operator
7+
- log-search
8+
hide_table_of_contents: true
9+
---
10+
11+
import useBaseUrl from '@docusaurus/useBaseUrl';
12+
13+
<a href="https://help.sumologic.com/release-notes-service/rss.xml"><img src={useBaseUrl('img/release-notes/rss-orange2.png')} alt="icon" width="50"/></a>
14+
15+
We're happy to announce a change in the computation for the `scanned_partition_count` Search Audit Index field. Previously, we were using incorrect computation to calculate the value for the `scanned_partition_count` field. With this change, the incorrect computation is fixed and now you will obtain the correct number of partitions scanned for the respective search.

blog-service/2024-11-13-manage.md

Lines changed: 20 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,20 @@
1+
---
2+
title: Kickstart Data Onboarding
3+
image: https://help.sumologic.com/img/sumo-square.png
4+
hide_table_of_contents: true
5+
---
6+
7+
import useBaseUrl from '@docusaurus/useBaseUrl';
8+
9+
<a href="https://help.sumologic.com/release-notes-service/rss.xml"><img src={useBaseUrl('img/release-notes/rss-orange2.png')} alt="icon" width="50"/></a>
10+
11+
We know that getting started with new tools can be challenging. To simplify your onboarding, we’ve introduced Kickstart Data with preloaded sample data and prebuilt dashboards designed to streamline your trial experience with Sumo Logic. With this sample data, you can jump right in, explore dashboards, and understand Sumo Logic's value without needing to set up your own data first.
12+
13+
### Key benefits
14+
15+
* **Immediate insights**. Begin with sample data and dashboards to experience Sumo Logic’s capabilities instantly.
16+
* **Quick setup**. No need to configure firewall settings or security permissions—get started right away.
17+
* **Guided trial**. Pre-built dashboards and reports demonstrate real-world scenarios, allowig secure and insightful exploration.
18+
* **Easy transition**. Start ingesting your own data anytime. Kickstart deactivated at the trial’s end.
19+
20+
See how Kickstart Data can simplify your onboarding, helping you focus on monitoring and troubleshooting. For more details, visit our [Quickstart Guide](/docs/get-started/quickstart/#getting-started-with-kickstart-data-in-your-trial).

cid-redirects.json

Lines changed: 9 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -90,6 +90,7 @@
9090
"/docs/contributing/edit-doc": "/docs/contributing/create-edit-doc",
9191
"/docs/contributing/markdown-cheat-sheet": "/docs/contributing/style-guide",
9292
"/docs/contributing/templates": "/docs/contributing/templates/generic-doc",
93+
"/docs/contributing/templates/template-doc": "/docs/contributing/templates/generic-doc",
9394
"/docs/c2c": "/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework",
9495
"/Send-Data": "/docs/send-data",
9596
"/03Send-Data": "/docs/send-data",
@@ -225,6 +226,7 @@
225226
"/03Send-Data/Setup-Wizard/Collect-from-Custom-Apps": "/docs/send-data/setup-wizard",
226227
"/03Send-Data/Setup-Wizard/Collect-from-Custom-Apps/Collect_Streaming_Data_from_HTTP": "/docs/send-data/setup-wizard",
227228
"/03Send-Data/Setup-Wizard/Collect-from-Custom-Apps/Collect-Streaming-Data-from-a-Local-File": "/docs/send-data/setup-wizard",
229+
"/03Send-Data/Setup-Wizard/Collect-Streaming-Data-for-Metrics/Collect-Streaming-Data-for-CollectD-Metrics": "/docs/send-data/setup-wizard",
228230
"/03Send-Data/Setup-Wizard/Collect-Streaming-Data-from-Other-Data-Types": "/docs/send-data/setup-wizard",
229231
"/Send-Data/Setup-Wizard/Collect-Streaming-Data-for-Metrics/01Collect-Streaming-Data-for-Host-Metrics": "/docs/send-data/setup-wizard",
230232
"/Send-Data/Setup-Wizard/Collect-Streaming-Data-for-Metrics/Collect-Streaming-Data-for-Graphite-Formatted-Metrics": "/docs/metrics/introduction/metric-formats",
@@ -2400,7 +2402,7 @@
24002402
"/cid/5421": "/docs/search/search-query-language/search-operators/fillmissing",
24012403
"/cid/5422": "/docs/search/time-compare",
24022404
"/cid/12356": "/docs/integrations/sumo-apps/log-analysis-quickstart",
2403-
"/cid/12357": "/docs/integrations/sumo-apps/kickstart-data-astronomy",
2405+
"/cid/12357": "/docs/integrations/sumo-apps/kickstart-data",
24042406
"/cid/5423": "/docs/send-data/installed-collectors/collector-installation-reference/force-collectors-name-clobber",
24052407
"/cid/5424": "/docs/dashboards/about",
24062408
"/cid/5426": "/docs/send-data/collection/processing-rules/hash-rules",
@@ -2634,6 +2636,7 @@
26342636
"/cid/16323": "/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/druva-source",
26352637
"/cid/13428": "/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/kandji-source",
26362638
"/cid/17343": "/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/automox-source",
2639+
"/cid/17344": "/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/smartsheet-source",
26372640
"/cid/20172": "/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/cisco-vulnerability-management-source",
26382641
"/cid/19880": "/docs/metrics/metrics-operators/predict",
26392642
"/cid/19881": "/docs/metrics/metrics-operators/accum",
@@ -3265,6 +3268,7 @@
32653268
"/Metrics/Metric-Queries-and-Alerts/07Metrics_Operators/where": "/docs/metrics/metrics-operators/where",
32663269
"/Metrics/Metric-Queries-and-Alerts/09Metric_Query_Error_Messages": "/docs/metrics/metrics-queries/metric-query-error-messages",
32673270
"/Metrics/Metric-Queries-and-Alerts/Metric_Aggregation_Tips": "/docs/metrics/metrics-queries/aggregation-tips",
3271+
"/Metrics/Metric-Queries-and-Alerts/Filter_Time_Series": "/docs/dashboards/panels",
32683272
"/Monitor_and_Alert/Alerts": "/docs/alerts",
32693273
"/Monitor_and_Alert/Dashboards/About_Dashboards": "/docs/dashboards/about",
32703274
"/Monitor_and_Alert/Alerts/Why_Would_a_Scheduled_Search_Fail": "/docs/alerts/scheduled-searches/faq",
@@ -3764,6 +3768,7 @@
37643768
"/Search/Search-Query-Language/01-Parse-Operators/07-Parse-XML-Formatted-Logs": "/docs/search/search-query-language/parse-operators/parse-xml-formatted-logs",
37653769
"/Search/Search-Query-Language/aaGroup/count,-count-distinct,-and-count-frequent": "/docs/search/search-query-language/group-aggregate-operators/count-count-distinct-and-count-frequent",
37663770
"/Search/Search-Query-Language/aaGroup/fillmissing": "/docs/search/search-query-language/search-operators/fillmissing",
3771+
"/Search/Search-Query-Language/aaGroup/sum": "/docs/search/search-query-language/group-aggregate-operators/sum",
37673772
"/Search/Search-Query-Language/Search-Operators": "/docs/search/search-query-language/search-operators",
37683773
"/Search/Search-Query-Language/Search-Operators/lookup": "/docs/search/search-query-language/search-operators/lookup",
37693774
"/docs/search/search-query-language/search-operators/parse": "/docs/search/search-query-language/parse-operators",
@@ -3853,6 +3858,7 @@
38533858
"/Send-Data/Applications-and-Other-Data-Sources/Palo_Alto_Networks_8/Collect_Logs_for_Palo_Alto_Networks_8": "/docs/integrations/security-threat-detection/palo-alto-networks-9",
38543859
"/Send-Data/Applications-and-Other-Data-Sources/Threat-Intel-Quick-Analysis": "/docs/integrations/security-threat-detection/threat-intel-quick-analysis",
38553860
"/Send-Data/Applications-and-Other-Data-Sources/Threat-Intel-Quick-Analysis/Threat-Intel-FAQ": "/docs/integrations/security-threat-detection/threat-intel-quick-analysis",
3861+
"/Send-Data/Applications-and-Other-Data-Types/Okta": "/docs/integrations/saml/okta",
38563862
"/Send-Data/Applications-and-Other-Data-Types/PCI-Compliance-for-Windows/Collecting-Logs-for-PCI-Compliance-for-Windows-App": "/docs/integrations/microsoft-azure/windows-json-pci-compliance",
38573863
"/Send-Data/Collect-from-Other-Data-Sources/Azure_Blob_Storage": "/docs/send-data/collect-from-other-data-sources/azure-blob-storage/block-blob/collect-logs",
38583864
"/Send-Data/Collect-from-Other-Data-Sources/Azure_Blob_Storage/Collect_Logs_from_Azure_Blob_Storage": "/docs/send-data/collect-from-other-data-sources/azure-blob-storage/block-blob/collect-logs",
@@ -3887,6 +3893,7 @@
38873893
"/Send-Data/Sources/01Sources-for-Installed-Collectors/Remote-File-Source": "/docs/send-data/installed-collectors/sources/remote-file-source",
38883894
"/Send-Data/Sources/01Sources-for-Installed-Collectors/Script-Action": "/docs/send-data/installed-collectors/sources/script-action",
38893895
"/Send-Data/Sources/01Sources-for-Installed-Collectors/Script-Source": "/docs/send-data/installed-collectors/sources/script-source",
3896+
"/Send-Data/Sources/01Sources-for-Installed-Collectors/Remote-Windows-Event-Log-Source/Prerequisites_for_Windows_Log_Collection": "/docs/send-data/installed-collectors/sources/remote-windows-event-log-source",
38903897
"/Send-Data/Sources/01Sources-for-Installed-Collectors/Syslog-Source": "/docs/send-data/installed-collectors/sources/syslog-source",
38913898
"/Send-Data/Sources/01Sources-for-Installed-Collectors/Local_Windows_Event_Log_Source/Local_Windows_Event_Source_Custom_Channels": "/docs/send-data/installed-collectors/sources/local-windows-event-log-source",
38923899
"/Send-Data/Sources/02Sources-for-Hosted-Collectors/AWS-S3-Source": "/docs/send-data/hosted-collectors/amazon-aws/aws-s3-source",
@@ -3897,6 +3904,7 @@
38973904
"/Send-Data/Sources/02Sources-for-Hosted-Collectors/HTTP-Source/Upload-Data-to-an-HTTP-Source": "/docs/send-data/hosted-collectors/http-source",
38983905
"/Send-Data/Sources/02Sources-for-Hosted-Collectors/HTTP-Source/zGenerate-a-new-URL-for-an-HTTP-Source": "/docs/send-data/hosted-collectors/http-source",
38993906
"/Send-Data/Sources/02Sources-for-Hosted-Collectors/Microsoft-Office-365-Audit-Source": "/docs/send-data/hosted-collectors/microsoft-source/ms-office-audit-source",
3907+
"/docs/send-data/hosted-collectors/microsoft-source": "/docs/send-data/hosted-collectors/microsoft-source/ms-office-audit-source",
39003908
"/docs/send-data/hosted-collectors/ms-office-audit-source": "/docs/send-data/hosted-collectors/microsoft-source/ms-office-audit-source",
39013909
"/docs/send-data/hosted-collectors/webhook-sources": "/docs/send-data/hosted-collectors/webhook-sources/zoom",
39023910
"/Send-Data/Sources/04Reference-Information-for-Sources/Timestamps,-Time-Zones,-Time-Ranges,-and-Date-Formats": "/docs/send-data/reference-information/time-reference",

docs/apm/real-user-monitoring/dashboards.md

Lines changed: 18 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -8,20 +8,28 @@ description: Learn how to use the Sumo Logic Real User Monitoring (RUM) Dashboar
88
import useBaseUrl from '@docusaurus/useBaseUrl';
99

1010

11-
## RUM App
11+
## Installing the RUM App (Optional)
1212

13-
Once Sumo Logic detects data coming from user browsers, the RUM app will be installed automatically for all users of your organization. **No action is required**.
13+
Once Sumo Logic detects data coming from user browsers, the RUM app will be installed automatically for all users of your organization. **No action is required**.
1414

15-
The data will populate in your organization's **Sumo Logic RUM - default** dashboards, located inside of your **Admin Recommended** folder. Do not modify or delete content in this folder, as it's maintained and updated automatically.
15+
The data will populate in your organization's **Sumo Logic RUM - default** dashboards, located inside of your **Installed Apps** folder. Do not modify or delete content in this folder, as it is maintained by Sumo Logic.
1616

17-
If your RUM app is removed accidentally, you'll need to install it manually:
17+
If your RUM app is removed accidentally, you'll need to install it manually
18+
19+
import AppInstall from '../../reuse/apps/app-install-v2.md';
20+
21+
## Upgrade/Downgrade the RUM App (Optional)
22+
23+
import AppUpdate from '../../reuse/apps/app-update.md';
24+
25+
<AppUpdate/>
26+
27+
## Uninstalling the RUM App (Optional)
28+
29+
import AppUninstall from '../../reuse/apps/app-uninstall.md';
30+
31+
<AppUninstall/>
1832

19-
1. Go to the **App Catalog**, then search for and select the **Real User Monitoring** app. 
20-
1. Click **Add to Library**.
21-
1. Provide an **App Name**. You can retain the existing name or enter a name of your choice for the app.
22-
1. **Advanced**. Select the Location in Library (the default is the Personal folder in the library), or click New Folder to add a new folder.
23-
1. Click **Add to Library**.
24-
1. Once the app is installed, it will appear in your **Personal** folder or the folder you specified. From here, you can share it with your organization.
2533

2634
## Using Real User Monitoring view
2735

0 commit comments

Comments
 (0)