Skip to content

Commit 9f869b6

Browse files
committed
Merge branch 'DOCS-1006' of github.com:SumoLogic/sumologic-documentation into DOCS-1006
2 parents d47010c + 85df9bf commit 9f869b6

File tree

245 files changed

+3318
-746
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

245 files changed

+3318
-746
lines changed

.clabot

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -187,7 +187,10 @@
187187
"Apoorvkudesia-sumologic",
188188
"ntanwar-sumo",
189189
"aj-sumo",
190-
"samiura"
190+
"samiura",
191+
"naveenrama",
192+
"fguimond",
193+
"rmeyer-legato"
191194
],
192195
"message": "Thank you for your contribution! As this is an open source project, we require contributors to sign our Contributor License Agreement and do not have yours on file. To proceed with your PR, please [sign your name here](https://forms.gle/YgLddrckeJaCdZYA6) and we will add you to our approved list of contributors.",
193196
"label": "cla-signed",

blog-cse/2025-08-15-content.md

Lines changed: 41 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,41 @@
1+
---
2+
title: August 15, 2025 - Content Release
3+
image: https://help.sumologic.com/img/reuse/rss-image.jpg
4+
keywords:
5+
- log mappers
6+
- parsers
7+
hide_table_of_contents: true
8+
---
9+
10+
This content release includes:
11+
- New product support for Vectra AI.
12+
- Updated parsers and log mappers for Azure Event Hub, Barracuda CloudGen Firewall, Microsoft IIS, and Surepass.
13+
- Updated Surepass to the correct vendor name.
14+
15+
Changes are enumerated below.
16+
17+
### Log Mappers
18+
- [New] Vectra AI Catch All
19+
- [New] Vectra AI User Login
20+
- [Updated] Azure Event Hub - Windows Defender Logs
21+
- Updated field mappings to include new fields.
22+
- [Updated] Barracuda CloudGen Firewall Activity
23+
- Updated `event_id` criteria to handle abridged event types in some logs.
24+
- [Updated] Microsoft IIS Parser - Catch All
25+
- Updated to support `http_url` and downstream enrichment.
26+
- [Updated] Surepass Authentication
27+
- [Updated] Surepass Catch All
28+
- [Updated] Surepass Network Event
29+
30+
### Parsers
31+
- [New] /Parsers/System/Vectra/Vectra AI
32+
- [Updated] /Parsers/System/Barracuda/Barracuda CloudGen
33+
- Updated `event_id` criteria to handle abridged event types in some logs and to support additional log formats.
34+
- [Updated] /Parsers/System/Cylance/Cylance Syslog
35+
- Updated timestamp parsing.
36+
- [Updated] /Parsers/System/DocuSign/DocuSign Monitor
37+
- Updated timestamp parsing.
38+
- [Updated] /Parsers/System/Microsoft/Microsoft Azure JSON
39+
- Updated parser to parse additional nested fields.
40+
- [Updated] /Parsers/System/Microsoft/Microsoft IIS
41+
- Updated to form `http_url` for downstream enrichment.

blog-cse/2025-08-19-application.md

Lines changed: 23 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,23 @@
1+
---
2+
title: August 19, 2025 - Application Update
3+
image: https://help.sumologic.com/img/reuse/rss-image.jpg
4+
keywords:
5+
- taxii
6+
- threat intelligence
7+
hide_table_of_contents: true
8+
---
9+
10+
import useBaseUrl from '@docusaurus/useBaseUrl';
11+
12+
### New TAXII 2 Threat Intelligence Sources
13+
14+
We're excited to announce the following new threat intelligence sources that allow you to collect TAXII feeds with greater ease. These sources are based on the underlying code of our STIX/TAXII 2 Client Source, but are tailored for each of the vendors to facilitate setup:
15+
* CISA TAXII Client
16+
* Dragos TAXII Client
17+
* Nozomi TAXII Client
18+
* Recorded Future TAXII Client
19+
* Unit42 TAXII Client
20+
21+
When you set up a source, search for "taxii" and select the tile for the source you want to install:<br/><img src={useBaseUrl('img/security/taxii-sources.png')} alt="TAXII sources" style={{border: '1px solid gray'}} width="800" />
22+
23+
[Learn more](/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/stix-taxii-2-client-source/#taxii-2-sources).

blog-cse/2025-08-20-content.md

Lines changed: 15 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,15 @@
1+
---
2+
title: August 20, 2025 - Content Release
3+
image: https://help.sumologic.com/img/reuse/rss-image.jpg
4+
keywords:
5+
- log mappers
6+
hide_table_of_contents: true
7+
---
8+
9+
This content release includes new log mappers to cover additional security finding sources collected via AWS Security Hub.
10+
11+
### Log Mappers
12+
- [New] AWS GuardDuty - OCSF Finding Events
13+
- [New] AWS Inspector - OCSF Finding Events
14+
- [New] AWS Security Hub Coverage - OCSF Finding Events
15+
- [New] AWS Security Hub Exposure Detection - OCSF Finding Events

blog-cse/2025-08-27-content.md

Lines changed: 44 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,44 @@
1+
---
2+
title: August 27, 2025 - Content Release
3+
image: https://help.sumologic.com/img/reuse/rss-image.jpg
4+
keywords:
5+
- log mappers
6+
hide_table_of_contents: true
7+
---
8+
9+
This content release includes:
10+
- New mappers and parsing support for additional Cisco ASA events and updates to existing Cisco ASA mappers to support additional fields.
11+
- Updates to AWS Security Hub OCSF Findings mappers to handle username alternate mappings.
12+
- Updates to McAfee Web Gateway CSV parser and mapper to support additional fields.
13+
- Fix to Sysdig Policy Detection JSON mapper to correctly map threat signal name and summary.
14+
15+
Changes are enumerated below.
16+
17+
### Log Mappers
18+
- [New] Cisco ASA 109201|109207|113022
19+
- [New] Cisco ASA 317077|317078
20+
- [New] Cisco ASA 725016|771002
21+
- [Updated] AWS GuardDuty - OCSF Finding Events
22+
- [Updated] AWS Inspector - OCSF Finding Events
23+
- [Updated] AWS Security Hub - OCSF Finding Events
24+
- [Updated] AWS Security Hub Coverage - OCSF Finding Events
25+
- [Updated] AWS Security Hub Exposure Detection - OCSF Finding Events
26+
- [Updated] Cisco ASA 113008 JSON
27+
- [Updated] Cisco ASA 302010 JSON
28+
- [Updated] Cisco ASA 303002 JSON
29+
- [Updated] Cisco ASA 313001 JSON
30+
- [Updated] Cisco ASA 50000(4|3) JSON
31+
- [Updated] Cisco ASA 602303-4|602101
32+
- [Updated] Cisco ASA 710005|716058
33+
- [Updated] Cisco ASA 713nnn JSON
34+
- [Updated] Cisco ASA 722034
35+
- [Updated] Cisco ASA 722051|722022|722023|722028|722032|722033|722036|722037|722041 JSON
36+
- [Updated] Cisco ASA 733100|734001|737005|737017|737036|737029|746014|746015|746016 JSON
37+
- [Updated] Cisco ASA 751023|725001|725002|725003|725006|725007|750001|750003|750006|750007|751022 JSON
38+
- [Updated] Cisco ASA Network events
39+
- [Updated] McAfee WebGateway - Parser
40+
- [Updated] Sysdig Policy Detection JSON
41+
42+
### Parsers
43+
- [Updated] /Parsers/System/Cisco/Cisco ASA
44+
- [Updated] /Parsers/System/McAfee/McAfee Web Gateway CSV
Lines changed: 12 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,12 @@
1+
---
2+
title: AWS IAM Users Source (Collection)
3+
image: https://help.sumologic.com/img/reuse/rss-image.jpg
4+
keywords:
5+
- c2c
6+
- aws-iam-users-source
7+
hide_table_of_contents: true
8+
---
9+
10+
import useBaseUrl from '@docusaurus/useBaseUrl';
11+
12+
We're excited to announce the release of our new cloud-to-cloud source for AWS IAM Users. This source collects the IAM User Inventory logs from the AWS SDK and sends them to Sumo Logic for streamlined analysis. [Learn more](/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/aws-iam-users-source).
Lines changed: 12 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,12 @@
1+
---
2+
title: GitHub Copilot Source (Collection)
3+
image: https://help.sumologic.com/img/sumo-square.png
4+
keywords:
5+
- c2c
6+
- github-copilot-source
7+
hide_table_of_contents: true
8+
---
9+
10+
import useBaseUrl from '@docusaurus/useBaseUrl';
11+
12+
We're excited to announce the release of our new cloud-to-cloud source for GitHub Copilot. This source aims to collect the organization and team metrics logs from the Copilot platform and send them to Sumo Logic for streamlined analysis. [Learn more](/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/github-copilot-source).
Lines changed: 12 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,12 @@
1+
---
2+
title: ExtraHop RevealX 360 (Apps)
3+
image: https://help.sumologic.com/img/reuse/rss-image.jpg
4+
keywords:
5+
- apps
6+
- extrahop-revealx-360
7+
hide_table_of_contents: true
8+
---
9+
10+
import useBaseUrl from '@docusaurus/useBaseUrl';
11+
12+
We're excited to introduce the new ExtraHop RevealX 360 app for Sumo Logic, which enables you to gain real-time visibility into your security hub findings data. This app can help security teams to monitor detection trends, track changes in risk levels, and gain insights into the most frequently observed MITRE techniques, top destination devices, and key targets on the network. [Learn more](/docs/integrations/webhooks/extrahop-revealx-360).

blog-service/2025-08-20-apps.md

Lines changed: 12 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,12 @@
1+
---
2+
title: Vectra (Apps)
3+
image: https://help.sumologic.com/img/reuse/rss-image.jpg
4+
keywords:
5+
- apps
6+
- vectra
7+
hide_table_of_contents: true
8+
---
9+
10+
import useBaseUrl from '@docusaurus/useBaseUrl';
11+
12+
We're excited to introduce the new Vectra app for Sumo Logic. This app leverages the Sumo Logic Cloud-to-Cloud [Vectra source](/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/vectra-source/) to collect the detections from the Vectra platform. It provides security analysts with visibility into security threats detected across networks, cloud environments, and endpoints. [Learn more](/docs/integrations/saas-cloud/vectra/).

blog-service/2025-08-26-apps.md

Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,14 @@
1+
---
2+
title: OpenTelemetry Collector Insights (Apps)
3+
image: https://help.sumologic.com/img/reuse/rss-image.jpg
4+
keywords:
5+
- apps
6+
- sumo-logic
7+
- opentelemetry-collector-insights
8+
hide_table_of_contents: true
9+
---
10+
11+
import useBaseUrl from '@docusaurus/useBaseUrl';
12+
13+
14+
We're excited to introduce the new OpenTelemetry Collector Insights app for Sumo Logic. This app offers robust monitoring and observability for Sumo Logic OpenTelemetry Collector instances (version 0.130.1-sumo-0 and above), enabling you to track performance, data flow, and resource usage through prebuilt dashboards and alerts. [Learn more](/docs/integrations/sumo-apps/opentelemetry-collector-insights/).

0 commit comments

Comments
 (0)