Skip to content

Commit 8cff9c6

Browse files
authored
Merge branch 'main' into AWS-Security-Hub-OCSF-app-docs
2 parents 13d938a + 8a2261a commit 8cff9c6

File tree

15 files changed

+207
-11
lines changed

15 files changed

+207
-11
lines changed

blog-service/2025-07-28-alerts.md

Lines changed: 19 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,19 @@
1+
---
2+
title: Time range limits for subqueries in scheduled searches (Alerts)
3+
image: https://help.sumologic.com/img/reuse/rss-image.jpg
4+
keywords:
5+
- alerts
6+
- scheduled searches
7+
- subqueries
8+
hide_table_of_contents: true
9+
---
10+
11+
We've introduced time range limits for subqueries in scheduled searches. This change helps you prevent long-running, inefficient queries, especially those impacting system stability and that drive up costs. While maintaining flexibility, these optimizations protect system health and reduce operational overhead.
12+
13+
Key benefits of this enhancements include:
14+
15+
- Improved query performance and responsiveness.
16+
- Encourage efficient search practices.
17+
- Support sustainable resource usage.
18+
19+
[Learn more](/docs/alerts/scheduled-searches/schedule-search/#step-3-time-range).

blog-service/2025-07-31-apps.md

Lines changed: 15 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,15 @@
1+
---
2+
title: Apps, Solutions, and Collection Integrations - July Release
3+
image: https://help.sumologic.com/img/reuse/rss-image.jpg
4+
keywords:
5+
- apps
6+
- july-release
7+
hide_table_of_contents: true
8+
---
9+
10+
import useBaseUrl from '@docusaurus/useBaseUrl';
11+
12+
### Enhancements
13+
14+
- **Updated OpenTelemetry apps**. [Oracle - OpenTelemetry](/docs/integrations/databases/opentelemetry/oracle-opentelemetry/), [SQL Server - OpenTelemetry](/docs/integrations/microsoft-azure/opentelemetry/sql-server-opentelemetry/), and [SQL Server for Linux - OpenTelemetry](/docs/integrations/microsoft-azure/opentelemetry/sql-server-linux-opentelemetry/).
15+
- **Updated 1 Webhook app**. [Sentry](/docs/integrations/webhooks/sentry/).
Lines changed: 12 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,12 @@
1+
---
2+
title: OneLogin Source (Collection)
3+
image: https://help.sumologic.com/img/reuse/rss-image.jpg
4+
keywords:
5+
- c2c
6+
- onelogin-source
7+
hide_table_of_contents: true
8+
---
9+
10+
import useBaseUrl from '@docusaurus/useBaseUrl';
11+
12+
We're excited to announce the release of our new cloud-to-cloud source for OneLogin. This source aims to collect the user list logs from the OneLogin API and send it to Sumo Logic for streamlined analysis. [Learn more](/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/onelogin-source).

cid-redirects.json

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -476,6 +476,7 @@
476476
"/05Search/Optimize-Search-Performance": "/docs/search/optimize-search-performance",
477477
"/05Search/Optimize-Search-Performance/Optimizing_Search_with_Partitions": "/docs/search/optimize-search-partitions",
478478
"/docs/manage/queries/optimize-queries": "/docs/search/optimize-search-performance",
479+
"/docs/search/search-across-child-org": "/docs/search/search-across-child-orgs",
479480
"/05Search/Search-Cheat-Sheets": "/docs/search/search-cheat-sheets",
480481
"/05Search/Search-Cheat-Sheets/General-Search-Examples-Cheat-Sheet": "/docs/search/search-cheat-sheets/general-search-examples",
481482
"/05Search/Search-Cheat-Sheets/grep-to-Searching-with-Sumo-Cheat-Sheet": "/docs/search/search-cheat-sheets/grep-searching-with-sumo",
@@ -2911,6 +2912,7 @@
29112912
"/cid/21037": "/docs/integrations/google/cloud-vpn",
29122913
"/cid/21333": "/docs/integrations/microsoft-azure/microsoft-defender-for-endpoint",
29132914
"/cid/21039": "/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/vectra-source",
2915+
"/cid/21059": "/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/onelogin-source",
29142916
"/cid/21041": "/docs/integrations/google/cloud-security-command-center",
29152917
"/cid/21097": "/docs/integrations/saas-cloud/confluent-cloud",
29162918
"/cid/21040": "/docs/manage/manage-subscription/create-and-manage-orgs/create-manage-orgs-service-providers",
@@ -3802,6 +3804,7 @@
38023804
"/03Send-Data/Collect-from-Other-Data-Sources/Collect_Logs_from_AWS_Lambda_using_Lambda_Extension": "/docs/send-data/collect-from-other-data-sources/collect-aws-lambda-logs-extension",
38033805
"/03Send-Data/Collect-from-Other-Data-Sources/Collecting-Logs-from-a-Local-File-System": "/docs/send-data/installed-collectors/sources/local-file-source",
38043806
"/03Send-Data/Hosted-Collectors/GCP_Metrics_Source": "/docs/send-data/hosted-collectors/google-source/gcp-metrics-source",
3807+
"/03Send-Data/Hosted-Collectors/HTTP-Source": "/docs/send-data/hosted-collectors/http-source/logs-metrics",
38053808
"/03Send-Data/Sources/01Sources-for-Installed-Collectors": "/docs/send-data/installed-collectors/sources",
38063809
"/03Send-Data/Sources/01Sources-for-Installed-Collectors/Local_Windows_Event_Log_Source": "/docs/send-data/installed-collectors/sources/local-windows-event-log-source",
38073810
"/03Send-Data/Sources/02Sources-for-Hosted-Collectors/Amazon-Web-Services": "/docs/send-data/hosted-collectors/amazon-aws",
@@ -3887,6 +3890,7 @@
38873890
"/Apps/Preview_Apps/Cylance/01Collect_Logs_for_Cylance": "/docs/integrations/security-threat-detection/cylance",
38883891
"/Apps/Preview_Apps/Azure_Audit_App": "/docs/integrations/microsoft-azure/audit",
38893892
"/Apps/Preview_Apps/Azure_Audit+App": "/docs/integrations/microsoft-azure/audit",
3893+
"/Apps/Preview_Apps/Azure_Web_Apps": "/docs/integrations/microsoft-azure/web-apps",
38903894
"/Apps/Windows_App/Windows_App_Dashboards": "/docs/integrations/microsoft-azure",
38913895
"/Beta": "/docs/beta",
38923896
"/Beta/APIs": "/docs/api",

docs/alerts/scheduled-searches/schedule-search.md

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -44,6 +44,10 @@ The [time range](../../search/get-started-with-search/search-basics/time-range-e
4444
This setting is different than the Time Range option configured for the Saved Search. The first time range is only used when you run the Saved Search from the Library. This Time Range applies to your Scheduled Search.
4545
:::
4646

47+
:::note
48+
The time range limitations below apply to both parent queries and subqueries in your scheduled search.
49+
:::
50+
4751
Alternately, type a time range; for example, -15m to run the search against data generated in the past 15 minutes. A time range outside the maximum allowed range for a given frequency is not allowed and presents the message like this: `Invalid query. Max allowed time range for 15 minutes frequency is 1 day`.
4852

4953
The maximum allowed time range for different Scheduled Search frequencies is as below:

docs/cse/rules/write-first-seen-rule.md

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -50,7 +50,7 @@ Watch this micro lesson to learn more about first seen rules.
5050

5151
A first seen rule is different from other Cloud SIEM rule types in that you don’t define the criteria for firing a signal. Instead, the rule expression in a first seen rule is simply a filter condition that defines what incoming records the rule will apply to. For each first seen rule, Cloud SIEM automatically creates a baseline model of normal behavior for a defined time period (by default for the last 90 days) evidenced by records that match the Rule Expression. The activity found during this period is considered normal behavior and will not be alerted on.
5252

53-
As soon as you save or update a first seen rule, the baseline is built using existing data collected. If data exists in the system to build the baseline, baseline creation typically takes only minutes to complete. If the records gathered for a baseline exceed 50 million, the historical baseline capabilities become inefficient and it’s better to let the baseline gather data over time. You will be notified of this state in the UI, and can either let the baseline gather over the days set in the baseline, or edit the rule to filter more records or reduce the baseline period to keep it under 50 million records.
53+
As soon as you save or update a first seen rule (or disable and re-enable it), the full baseline is built using existing data collected. If data exists in the system to build the baseline, baseline creation typically takes only minutes to complete. If the records gathered for a baseline exceed 50 million, the historical baseline capabilities become inefficient and it’s better to let the baseline gather data over time. You will be notified of this state in the UI, and can either let the baseline gather over the days set in the baseline, or edit the rule to filter more records or reduce the baseline period to keep it under 50 million records.
5454

5555
Once the baseline is created, when an incoming record includes matching activity not seen during the baseline retention period, the rule creates a signal identifying the activity as *first seen*. The signal indicates that the activity is first seen:
5656

@@ -86,9 +86,9 @@ The settings in the **If Triggered** section determine what records the rule wil
8686

8787
1. **When a Record matching the expression**. Enter an expression that matches the records that you want to rule to apply to.
8888
1. Click **Test Rule Expression** to test it against existing records in Cloud SIEM. The **If Triggered** section expands, and Cloud SIEM searches for records that match the rule expression. If there are no matching records, you'll see a **There aren't any matches for the expression** message. If no matches were returned, try changing the time range.
89-
1. Select **Add Tuning Expression** if you want to add a [rule tuning expression](/docs/cse/rules/rule-tuning-expressions) to the rule.
89+
1. Select **Add Tuning Expression** if you want to add a [rule tuning expression](/docs/cse/rules/rule-tuning-expressions) to the rule. (If you use **Test Rule Expression** on a rule that has one or more rule tuning expressions, you can test it without the tuning expressions, or with selected tuning expressions.)
9090
:::note
91-
If you use **Test Rule Expression** on a rule that has one or more rule tuning expressions, you can test it without the tuning expressions, or with selected tuning expressions.
91+
The [baseline for a first seen rule](#baselines-for-first-seen-rules) is recalculated if a rule tuning expression that applies to the selected rule is updated. However, the baseline is not recalculated if the rule tuning expression applies to all rules.
9292
:::
9393
1. **has a new value for the field(s)**. Select the record field that will be used to build the baseline.
9494
1. **after building a [global | per Entity] baseline** The settings in this section define the scope of the baseline that will be built.

docs/cse/rules/write-outlier-rule.md

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -53,7 +53,7 @@ Watch this micro lesson to learn more about outlier rules.
5353

5454
When you create the rule, you can set the amount of time Cloud SIEM analyzes data to create a baseline model of behavior, with the default period being for the last 90 days. You can set the rule to build data hourly or daily, depending on how frequently you believe events of interest will occur, and how much data you want to gather. In the rule, you set the model sensitivity threshold to calculate outlier activity based on the number of standard deviations from the mean (z‑score).
5555

56-
As soon as you save or update an outlier rule, the baseline is built using existing data collected. So if your baseline retention period is for the last 90 days (the default), the system uses data from the last 90 days to build the baseline. If data exists in the system to build the baseline, baseline creation typically takes only minutes to complete. If the records gathered for a baseline exceed 50 million, the historical baseline capabilities become inefficient and it’s better to let the baseline gather data over time. You will be notified of this state in the UI, and can either let the baseline gather over the days set in the baseline, or edit the rule to filter more records or reduce the baseline period to keep it under 50 million records.
56+
As soon as you save or update an outlier rule (or disable and re-enable it), the full baseline is built using existing data collected. So if your baseline retention period is for the last 90 days (the default), the system uses data from the last 90 days to build the baseline. If data exists in the system to build the baseline, baseline creation typically takes only minutes to complete. If the records gathered for a baseline exceed 50 million, the historical baseline capabilities become inefficient and it’s better to let the baseline gather data over time. You will be notified of this state in the UI, and can either let the baseline gather over the days set in the baseline, or edit the rule to filter more records or reduce the baseline period to keep it under 50 million records.
5757

5858
Once the baseline is created, Cloud SIEM tracks aggregates of count, sum, min, max, and averages of record values, and creates a signal when deviations from the mean occurs. For example, for the [spike in failed logins from a user](#use-case-for-a-spike-in-failed-logins-from-a-user) use case, Cloud SIEM builds a baseline model of counts of authentication failures that are associated with a user over time, and creates a signal when outlier behavior is detected:
5959

@@ -91,9 +91,9 @@ The settings in the **If Triggered** section are divided into two subsections, o
9191
**Baseline Configuration**
9292
1. **For the records matching the expression**. Enter an expression that matches the records that you want to rule to apply to.
9393
1. Click **Test Rule Expression** to test it against existing records in Cloud SIEM. The **If Triggered** section expands, and Cloud SIEM searches for records that match the rule expression. If there are no matching records, you'll see a **There aren't any matches for the expression** message. If no matches were returned, try changing the time range.
94-
1. Select **Add Tuning Expression** if you want to add a [rule tuning expression](/docs/cse/rules/rule-tuning-expressions) to the rule.
94+
1. Select **Add Tuning Expression** if you want to add a [rule tuning expression](/docs/cse/rules/rule-tuning-expressions) to the rule. (If you use **Test Rule Expression** on a rule that has one or more rule tuning expressions, you can test it without the tuning expressions, or with selected tuning expressions.)
9595
:::note
96-
If you use **Test Rule Expression** on a rule that has one or more rule tuning expressions, you can test it without the tuning expressions, or with selected tuning expressions.
96+
The [baseline for an outlier rule](#baselines-for-outlier-rules) is recalculated if a rule tuning expression that applies to the selected rule is updated. However, the baseline is not recalculated if the rule tuning expression applies to all rules.
9797
:::
9898
1. **build a daily/hourly baseline**. Select the time window for building the baseline. It can either be a daily or hourly baseline.
9999
1. **for the entity(ies)**. Select one or more record fields for which you want baselines built. Selecting multiple fields will build a distinct baseline for a combination of entities.

docs/integrations/product-list/product-list-m-z.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -60,7 +60,7 @@ For descriptions of the different types of integrations Sumo Logic offers, see [
6060
| <img src={useBaseUrl('img/integrations/security-threat-detection/Observable.png')} alt="Thumbnail icon" width="50"/> | [Observable Networks](https://www.cisco.com/c/en/us/services/acquisitions/observable-networks.html) | App: [Observable Networks](/docs/integrations/security-threat-detection/observable-networks/) |
6161
| <img src={useBaseUrl('img/integrations/misc/oisf-logo.png')} alt="Thumbnail icon" width="75"/> | [OISF](https://oisf.net/) | Cloud SIEM integration: [OISF](https://github.com/SumoLogic/cloud-siem-content-catalog/blob/master/vendors/9c138edd-dc14-43a6-b751-52e41a8bd105.md) |
6262
| <img src={useBaseUrl('img/integrations/saml/okta.png')} alt="Thumbnail icon" width="50"/> | [Okta](https://www.okta.com/) | App: [Okta](/docs/integrations/saml/okta/) <br/>Automation integration: [Okta](/docs/platform-services/automation-service/app-central/integrations/okta/) <br/>Cloud SIEM integration: [Okta](https://github.com/SumoLogic/cloud-siem-content-catalog/blob/master/vendors/d8d14556-180c-4463-90da-d8b8600f7362.md) <br/>Collectors: <br/>- [Okta Source](/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/okta-source/) |
63-
| <img src={useBaseUrl('img/integrations/saml/onelogin.png')} alt="Thumbnail icon" width="50"/> | [OneLogin](https://www.onelogin.com/) | App: [OneLogin](/docs/integrations/saml/onelogin/) <br/>Automation integration: [OneLogin](/docs/platform-services/automation-service/app-central/integrations/onelogin/) <br/>Cloud SIEM integration: [OneLogin](https://github.com/SumoLogic/cloud-siem-content-catalog/blob/master/vendors/e34a3430-613f-47c0-9ddd-a320bc3e5c4d.md) |
63+
| <img src={useBaseUrl('img/integrations/saml/onelogin.png')} alt="Thumbnail icon" width="50"/> | [OneLogin](https://www.onelogin.com/) | App: [OneLogin](/docs/integrations/saml/onelogin/) <br/>Automation integration: [OneLogin](/docs/platform-services/automation-service/app-central/integrations/onelogin/) <br/>Cloud SIEM integration: [OneLogin](https://github.com/SumoLogic/cloud-siem-content-catalog/blob/master/vendors/e34a3430-613f-47c0-9ddd-a320bc3e5c4d.md) <br/>Collector: [OneLogin Source](/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/onelogin-source) |
6464
| <img src={useBaseUrl('img/integrations/1password/1password.png')} alt="Thumbnail icon" width="50"/> | [1Password](https://1password.com/) | App: [1Password](/docs/integrations/saas-cloud/1password/) <br/>Cloud SIEM integration: [1Password](https://github.com/SumoLogic/cloud-siem-content-catalog/blob/master/vendors/d0455ea1-e901-4999-b047-0533d16adfdc.md) <br/>Collector: [1Password Source](/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/1password-source/) |
6565
| <img src={useBaseUrl('img/platform-services/automation-service/app-central/logos/onetrust.png')} alt="Thumbnail icon" width="75"/> | [OneTrust](https://www.onetrust.com/) | Automation integration: [OneTrust](/docs/platform-services/automation-service/app-central/integrations/onetrust/) |
6666
| <img src={useBaseUrl('img/platform-services/automation-service/app-central/logos/openai-chatgpt.png')} alt="Thumbnail icon" width="75"/> | [OpenAI](https://openai.com/) | Automation integration: [OpenAI ChatGPT](/docs/platform-services/automation-service/app-central/integrations/openai-chatgpt/) |

docs/platform-services/automation-service/app-central/integrations/censys-v2.md

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -6,8 +6,8 @@ import useBaseUrl from '@docusaurus/useBaseUrl';
66

77
<img src={useBaseUrl('/img/platform-services/automation-service/app-central/logos/censys.png')} alt="censys" width="100"/>
88

9-
***Version: 2.2
10-
Updated: Jul 07, 2023***
9+
***Version: 2.3
10+
Updated: Jul 31, 2025***
1111

1212
Censys reduces your Internet attack surface by continually discovering unknown assets and helping remediate Internet facing risks.
1313

@@ -49,3 +49,4 @@ For information about Censys V2, see [Censys documentation](https://docs.censys.
4949
* July 7, 2023 (v2.2)
5050
+ Updated the integration with Environmental Variables
5151
+ Integration renamed from Censys 2.0 to Censys V2
52+
* July 31, 2025 (v2.3) - Updated the integration logo.

docs/platform-services/automation-service/app-central/integrations/censys.md

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -6,8 +6,8 @@ import useBaseUrl from '@docusaurus/useBaseUrl';
66

77
<img src={useBaseUrl('/img/platform-services/automation-service/app-central/logos/censys.png')} alt="censys" width="100"/>
88

9-
***Version: 1.1
10-
Updated: Jul 11, 2023***
9+
***Version: 1.2
10+
Updated: Jul 31, 2025***
1111

1212
Search Censys for enrichment data during active investigation.
1313

@@ -49,3 +49,4 @@ For information about Censys, see [Censys documentation](https://docs.censys.com
4949

5050
* January 31, 2020 - First upload
5151
* July 11, 2023 (v1.1) - Updated the integration with Environmental Variables
52+
* July 31, 2025 (v1.2) - Updated the integration logo.

0 commit comments

Comments
 (0)