Skip to content

Commit a2dec06

Browse files
Merge branch 'main' into CSOAR-3557
2 parents d0b9b7d + e888ce7 commit a2dec06

File tree

103 files changed

+524
-657
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

103 files changed

+524
-657
lines changed

blog-cse/2025-10-28-content.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -12,7 +12,7 @@ This content release includes:
1212
- Updates to existing mappers for Crowdstrike Falcon, F5, and Okta events to support additional fields and events.
1313
- Updates to F5 Networks and Okta SSO parsers.
1414

15-
Changes are enumerated below.
15+
This new and updated content is effective as of October 22, 2025. Changes are enumerated below.
1616

1717
### Log Mappers
1818
- [New] CrowdStrike Falcon Host API IdpDetectionSummaryEvent

blog-cse/2025-10-29-content.md

Lines changed: 22 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,22 @@
1+
---
2+
title: October 29, 2025 - Content Release
3+
image: https://assets-www.sumologic.com/company-logos/_800x418_crop_center-center_82_none/SumoLogic_Preview_600x600.jpg?mtime=1617040082
4+
keywords:
5+
- log mappers
6+
- parsers
7+
hide_table_of_contents: true
8+
---
9+
10+
This content release includes:
11+
- New log mappers for Crowdstrike Falcon to support eppDetectionSummary events from multiple ingest methods.
12+
- New parsers and log mappers for Databricks Audit logs and Varonis Alerts.
13+
14+
## Log Mappers
15+
- [New] CrowdStrike Falcon - EppDetectionSummaryEvents (CNC)
16+
- [New] DataBricks Audit Catch All
17+
- [New] DataBricks Authentication
18+
- [New] Varonis Alerts Catch All
19+
20+
## Parsers
21+
- [New] /Parsers/System/Databricks/Databricks Audit
22+
- [New] /Parsers/System/Varonis/Varonis Alert JSON

blog-service/2025-04-28-manage.md

Lines changed: 1 addition & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -12,6 +12,4 @@ import useBaseUrl from '@docusaurus/useBaseUrl';
1212

1313
We are happy to announce that authorized users can now control the visibility of installed app content. This update allows content administrators and the installing user to configure the roles and users who should be allowed to view the dashboards and log searches that are installed with an app.
1414

15-
For more information about sharing apps, see [Content Sharing in Sumo Logic](/docs/manage/content-sharing/).
16-
17-
<img src={useBaseUrl('img/content-sharing/grant-app-access-to-org.png')} alt="<your image description>" style={{border: '1px solid gray'}} width="<insert-pixel-number>" />
15+
For more information about sharing apps, see [Content Sharing in Sumo Logic](/docs/manage/content-sharing/).

blog-service/2025-10-31-apps.md

Lines changed: 61 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,61 @@
1+
---
2+
title: Apps, Solutions, and Collection Integrations - October Release
3+
image: https://assets-www.sumologic.com/company-logos/_800x418_crop_center-center_82_none/SumoLogic_Preview_600x600.jpg?mtime=1617040082
4+
keywords:
5+
- apps
6+
- october-release
7+
hide_table_of_contents: true
8+
---
9+
10+
import useBaseUrl from '@docusaurus/useBaseUrl';
11+
12+
### New release
13+
14+
15+
- **Azure OpenAI**. The Azure OpenAI app enables you to track the request volume, token usage, response latency, and error rates, to ensure efficient model utilization and reliable AI-driven application performance. [Learn more](/docs/integrations/microsoft-azure/azure-open-ai/).
16+
17+
### AWS Observability Solution v2.13.0
18+
19+
**New release**:
20+
21+
- Added tag support for AWS resources created with Terraform based AWS Observability (AWSO) Solution. [Learn more](https://github.com/SumoLogic/sumologic-solution-templates/releases/tag/v2.13.0).
22+
23+
**Enhancements**:
24+
25+
- Enhanced the app installation and sharing workflow within the Admin Recommended folder for smoother management and collaboration.
26+
- Integrated updated EC2, Lambda, and RDS apps with AWSO Solution.
27+
- Upgraded the AWS provider to support versions `>= 5.16.2` and `< 7.0.0`.
28+
- Updated the minimum required Terraform version to `1.5.7`.
29+
- Addressed CVEs identified in Python and Go modules.
30+
- Updated the following SAM app versions:
31+
- `sumologic-app-utils` - `2.0.21`.
32+
- `sumologic-s3-logging-auto-enable` - `1.0.18`.
33+
34+
**Deprecation**:
35+
36+
- The Global Intelligence for AWS CloudTrail DevOps app is scheduled for deprecation in the near future and, as a result, has been removed from the AWS Observability Solution.
37+
- Deprecated AWS Observability Solution v2.8.0 and earlier due to their dependence on [Node.js 18](https://docs.aws.amazon.com/lambda/latest/dg/lambda-runtimes.html#runtimes-deprecated), which is deprecated in the AWS Lambda runtime as of September 1, 2025.
38+
- Amazon will deprecate the [AWS Lambda runtime](https://docs.aws.amazon.com/lambda/latest/dg/lambda-runtimes.html) Node.js 20 on April 30, 2026. AWS Observability Solution versions v2.9.0, v2.10.0, and v2.11.0 use Node.js 20 and will therefore be deprecated and no longer supported starting May 1, 2026. Sumo Logic encourages you to upgrade to the [latest version](https://github.com/SumoLogic/sumologic-solution-templates/releases) of the AWS Observability Solution to ensure continued support.
39+
40+
### App enhancements
41+
42+
* Sumo Logic has introduced a new app category (AI/ML) in the Sumo Logic App Catalog.
43+
* Updated the Azure Machine Learning app to monitor nested namespace metrics.
44+
* Updated 9 AWS-related apps, including [AWS API Gateway](/docs/integrations/amazon-aws/api-gateway/), [Application Load Balancer (ALB)](/docs/integrations/amazon-aws/application-load-balancer/), [Classic Load Balancer](/docs/integrations/amazon-aws/classic-load-balancer/), [Network Load Balancer (NLB)](/docs/integrations/amazon-aws/network-load-balancer/), [EC2](/docs/platform-services/automation-service/app-central/integrations/aws-ec2), [ElastiCache](/docs/integrations/amazon-aws/elasticache/), [RDS](/docs/integrations/amazon-aws/rds/), [Lambda](/docs/integrations/amazon-aws/lambda/), and [SNS](/docs/integrations/amazon-aws/sns/), to enhance CloudTrail ARN pattern parsing and improve CloudTrail dashboards for ALB and NLB.
45+
46+
### Integration enhancements
47+
48+
Updated the Sumo Logic Lambda Extension to version 1.3.0. [Learn more](https://github.com/SumoLogic/sumologic-lambda-extensions/releases/tag/v1.3.0).
49+
* Upgraded Golang to version 1.24 with CVE fixes.
50+
* Updated the base container image.
51+
* Enhanced error handling for improved reliability.
52+
* Fixed issues identified by golangci-lint.
53+
* Migrated from `aws-sdk-go` to `aws-sdk-go-v2` for better performance and modularity.
54+
55+
### Bug fixes
56+
57+
- AWS CloudTrail specific FER for AWS Network Load Balancer and AWS Application Load Balancer apps.
58+
59+
### Deprecation
60+
61+
The method of collecting metrics using [Azure Resource Manager (ARM)](/docs/send-data/collect-from-other-data-sources/azure-monitoring/collect-metrics-azure-monitor/) will be deprecated and no longer supported starting January 1, 2026. Refer to the updated approach using [Azure Metric Source](/docs/send-data/hosted-collectors/microsoft-source/azure-metrics-source/), which offers improved functionality and ongoing support.

docs/contributing/style-guide.md

Lines changed: 5 additions & 28 deletions
Original file line numberDiff line numberDiff line change
@@ -894,7 +894,7 @@ Always start with `1.`. Markdown automatically numbers sequentially when buildin
894894
1. Ordered sub-list.
895895
1. And another item.
896896
897-
More content for this entry. And a screenshot:<br/> ![span hover](/img/apm/span-hover-view.png)
897+
More content for this entry. And a screenshot:<br/><img src={useBaseUrl('img/apm/span-hover-view.png')} alt="Span hover" style={{border: '1px solid gray'}} width="400" />
898898
899899
```
900900
</TabItem>
@@ -906,7 +906,7 @@ Always start with `1.`. Markdown automatically numbers sequentially when buildin
906906
1. Actual numbers do not matter, just that it is a number.
907907
1. Ordered sub-list.
908908
1. And another item.
909-
* More content for this entry. And a screenshot:<br/> ![span hover](/img/apm/span-hover-view.png)
909+
* More content for this entry. And a screenshot:<br/><img src={useBaseUrl('img/apm/span-hover-view.png')} alt="Span hover" style={{border: '1px solid gray'}} width="400" />
910910

911911
</TabItem>
912912
</Tabs>
@@ -1271,10 +1271,6 @@ In the UI, avoid periods for single sentences on their own. Whenever there are t
12711271
12721272
Our release notes (also known as changelog) are posted to the both the docs site and corresponding RSS feed. Check out the categories [here](/docs/release-notes). Keep your them concise and add links to documentation. If there are updated UI elements, add an image or gif.
12731273
1274-
### Text only
1275-
1276-
To add a text-only release note:
1277-
12781274
1. In the appropriate blog folder ([blog-collector](https://github.com/SumoLogic/sumologic-documentation/tree/main/blog-collector), [blog-cse](https://github.com/SumoLogic/sumologic-documentation/tree/main/blog-cse), [blog-csoar](https://github.com/SumoLogic/sumologic-documentation/tree/main/blog-csoar), [blog-developer](https://github.com/SumoLogic/sumologic-documentation/tree/main/blog-developer), [blog-service](https://github.com/SumoLogic/sumologic-documentation/tree/main/blog-service)), add a new file that follows the format of the other posts in that folder. For example, for blog-service release notes, the format is `YYYY-MM-DD-<product/feature>`. For Cloud SIEM and SOAR, the format is `YYYY-MM-DD-application-update` or `YYYY-MM-DD-content-update`.<br/><img src={useBaseUrl('img/contributing/release-notes-dropdown-menu.png')} alt="Release notes menu" style={{border: '1px solid gray'}} width="200"/>
12791275
1. Add the following frontmatter, swapping out these example values with your own. Because there's no `image`, we'll use the Sumo Logic logo in its place.
12801276
```markdown
@@ -1294,29 +1290,10 @@ To add a text-only release note:
12941290
* `hide-table-of-contents`. Hide the TOC on the page, keeping the notes clean and wide on the page.
12951291
1. Document the release notes. Add links, bullets, and images as needed.
12961292
1297-
#### Long release notes
1293+
### Long release notes
12981294
12991295
For lengthy release notes, we recommend introducing the notes and adding a truncate line (`<!--truncate-->`), followed by the full set of release notes.
13001296
1301-
### Text and images
1302-
1303-
To add release notes with images:
1304-
1305-
1. In the blog folder, create a new folder with the following name format: `YYYY-MM-DD-product`.
1306-
1. In the new folder, create a markdown file named `index.md`.
1307-
1. Add your release notes with frontmatter:
1308-
```markdown
1309-
---
1310-
title: New XYZ Feature
1311-
hide_table_of_contents: true
1312-
keywords:
1313-
- alerts
1314-
image: https://assets-www.sumologic.com/company-logos/_800x418_crop_center-center_82_none/SumoLogic_Preview_600x600.jpg?mtime=1617040082
1315-
---
1316-
```
1317-
1. Save the image to this folder and add them to the markdown file: `![alt text](image-name.png)`.
1318-
1319-
13201297
## Reusing content
13211298
13221299
For repeatable content - an identical section that appears in one or more docs - you can save a lot of time by creating one instance of that content in the `/docs/reuse` folder and then importing that snippet to other docs.
@@ -1386,7 +1363,7 @@ Tables use plain markdown with one header, default left-aligned columns, and mul
13861363
| Started At | 07/27/2020 09:01:04.533 | When the trace started. |
13871364
| Duration | 12.582 ms | The amount of time the trace spans. |
13881365
| Number of spans | 35 | A trace consists of spans. This number tells you how many spans are in the trace. |
1389-
| Duration Breakdown | ![breakdown](/img/apm/traces/breakdown.png) | Each color indicates a service. The colors assigned to services are always the same on your account. You can change the color in the span summary tab after clicking on the individual span in trace view.<br/>Hover over to view a percentage breakdown of how long each span covers in the trace.<br/>![span hover](/img/apm/traces/span-hover-view.png) |
1366+
| Duration Breakdown | <img src={useBaseUrl('img/apm/traces/breakdown.png')} alt="Breakdown" style={{border: '1px solid gray'}} width="200" /> | Each color indicates a service. The colors assigned to services are always the same on your account. You can change the color in the span summary tab after clicking on the individual span in trace view.<br/>Hover over to view a percentage breakdown of how long each span covers in the trace.<br/><img src={useBaseUrl('img/apm/span-hover-view.png')} alt="Span hover" style={{border: '1px solid gray'}} width="300" /> |
13901367
| Number of errors | 0 | The number of errors in the trace. |
13911368
| Status | 200 | The HTTP status code of the trace. |
13921369
```
@@ -1421,7 +1398,7 @@ Markdown | Less | Pretty
14211398
| Started At | 07/27/2020 09:01:04.533 | When the trace started. |
14221399
| Duration | 12.582 ms | The amount of time the trace spans. |
14231400
| Number of spans | 35 | A trace consists of spans. This number tells you how many spans are in the trace. |
1424-
| Duration Breakdown | ![breakdown](/img/apm/traces/breakdown.png) | Each color indicates a service. The colors assigned to services are always the same on your account. You can change the color in the span summary tab after clicking on the individual span in trace view.<br/>Hover over to view a percentage breakdown of how long each span covers in the trace.<br/>![span hover](/img/apm/span-hover-view.png) |
1401+
| Duration Breakdown | <img src={useBaseUrl('img/apm/traces/breakdown.png')} alt="Breakdown" style={{border: '1px solid gray'}} width="200" /> | Each color indicates a service. The colors assigned to services are always the same on your account. You can change the color in the span summary tab after clicking on the individual span in trace view.<br/>Hover over to view a percentage breakdown of how long each span covers in the trace.<br/><img src={useBaseUrl('img/apm/span-hover-view.png')} alt="Span hover" style={{border: '1px solid gray'}} width="300" /> |
14251402
| Number of errors | 0 | The number of errors in the trace. |
14261403
| Status | 200 | The HTTP status code of the trace. |
14271404

docs/contributing/templates/generic-doc.md

Lines changed: 4 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -9,6 +9,8 @@ description: Example template for creating a document in the Sumo Logic guides.
99
<meta name="robots" content="noindex" />
1010
</head>
1111

12+
import useBaseUrl from '@docusaurus/useBaseUrl';
13+
1214
<!--Copy this markdown file and replace it with your own documentation. To view the full list of markdown components, see our [Style Guide](/docs/contributing/style-guide).
1315
1416
Replace the title above in the [Frontmatter section](/docs/contributing/style-guide#frontmatter) with yours. This will render as an H1 header. All other header sections should be H2, H3, H4, or H5.-->
@@ -20,7 +22,7 @@ To add an image, save the .png file with a simple name to the `/static/img` fold
2022
2123
Example:
2224
23-
![Sumo Logic logo](/img/reuse/sumo-square.png)
25+
<img src={useBaseUrl('img/reuse/sumo-square.png')} alt="Sumo Logic logo" style={{border: '1px solid gray'}} width="50" />
2426
-->
2527

2628
### Instructions
@@ -31,7 +33,7 @@ Always use `1.` to start your instructions. You do not need to actually number t
3133
1. Click **Collections**, then **Sources** tab.
3234
1. Next step, just write it out.
3335
* Bullet list just tab and use `*` or `1.`.
34-
* Next bullet.<br/>![Sumo Logic logo](/img/reuse/sumo-square.png)
36+
* Next bullet.<br/><img src={useBaseUrl('img/reuse/sumo-square.png')} alt="Sumo Logic logo" style={{border: '1px solid gray'}} width="50" />
3537
1. The numbers continue with content indented above!
3638
3739
Here is an example table:

docs/cse/rules/write-aggregation-rule.md

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -7,6 +7,7 @@ description: Learn how to write an aggregation rule.
77

88
import useBaseUrl from '@docusaurus/useBaseUrl';
99
import CseRule from '../../reuse/cse-rule-description-links.md';
10+
import CseDynamicSeverity from '../../reuse/cse-dynamic-severity.md';
1011
import Iframe from 'react-iframe';
1112

1213
This topic has information about Cloud SIEM aggregation rules and how to write them.
@@ -107,6 +108,7 @@ On the right side of the Rules Editor, in the **Then Create a Signal** section,
107108
1. The severity area updates.
108109
1. **severity of**. Use the pulldown to select a default severity value.
109110
1. **for the record field**. Use the down arrows to display a list of fields, and select one. The dynamic severity will be based on the value of (or existence of) that field in the record that matched the rule expression.
111+
<CseDynamicSeverity/>
110112
1. The **Add More Mappings** option appears. <br/><img src={useBaseUrl('img/cse/add-more-mappings.png')} alt="Add More Mappings option" style={{border: '1px solid gray'}} width="450"/>
111113
1. **Click Add More Mappings**. (Optional) You can define additional mappings if desired. If you don’t, the severity value will be the value of the record field you selected above.
112114
1. The **if the value is** option appears.<br/><img src={useBaseUrl('img/cse/if-the-value-is.png')} alt="If the Value Is option" style={{border: '1px solid gray'}} width="450"/>

docs/cse/rules/write-match-rule.md

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -7,6 +7,7 @@ description: Learn how to write a match rule.
77

88
import useBaseUrl from '@docusaurus/useBaseUrl';
99
import CseRule from '../../reuse/cse-rule-description-links.md';
10+
import CseDynamicSeverity from '../../reuse/cse-dynamic-severity.md';
1011
import Iframe from 'react-iframe'; 
1112

1213
This topic has information about match rules and how to create them in the Cloud SIEM UI.
@@ -87,6 +88,7 @@ Watch this micro lesson to learn how to create a match rule.
8788
1. The severity area updates.
8889
1. **severity of**. Use the pulldown to select a default severity value.
8990
1. **for the record field**. Use the down arrows to display a list of fields, and select one. The dynamic severity will be based on the value of (or existence of) that field in the record that matched the rule expression.
91+
<CseDynamicSeverity/>
9092
1. The **Add More Mappings** option appears. <br/><img src={useBaseUrl('img/cse/add-more-mappings.png')} alt="Add More Mappings option" style={{border: '1px solid gray'}} width="300"/>
9193
1. Click **Add More Mappings**. (Optional) You can define additional mappings if desired. If you don’t, the severity value will be the value of the record field you selected above.
9294
1. The **if the value is** option appears.<br/><img src={useBaseUrl('img/cse/if-the-value-is.png')} alt="If the Value is Option.png" style={{border: '1px solid gray'}} width="300"/>

docs/get-started/help.md

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -19,7 +19,7 @@ Docs cover all product features and should be your first resource when you have
1919
If you haven't found the answer to your question in our online help documentation:
2020

2121
1. [**New UI**](/docs/get-started/sumo-logic-ui). In the top menu select **Help > Support**. <br/> [**Classic UI**](/docs/get-started/sumo-logic-ui-classic). In the main Sumo Logic menu select **Help > Support**.
22-
1. You'll be taken to Sumo Logic Support. Click **Submit a Request** to file a ticket.<br/>![Help - Support.png](/img/get-started/Help-Support.png)
22+
1. You'll be taken to Sumo Logic Support. Click **Submit a Request** to file a ticket.<br/><img src={useBaseUrl('img/get-started/Help-Support.png')} alt="Support page" style={{border: '1px solid gray'}} width="800" />
2323

2424
On this site, you can log in with your account to access resources like Sumo Logic announcements, release notes, Knowledge Base articles, and more. You can also access the Sumo Logic Community in order to ask questions of fellow users.
2525

@@ -41,7 +41,7 @@ You can also search for and request features, comment, and vote on issues that a
4141

4242
See the [Sumo Logic Community](https://community.sumologic.com) for more information.
4343

44-
![Help - Community2.png](/img/get-started/Help-Community.png)
44+
<img src={useBaseUrl('img/get-started/Help-Community.png')} alt="Community page" style={{border: '1px solid gray'}} width="800" />
4545

4646

4747
## Privacy Policy
@@ -74,8 +74,8 @@ The Service Status Indicator on the Help menu shows the severity of the outage.
7474
| Icon | Status |
7575
| :-- | :-- |
7676
| NONE | **None.** All systems operational. |
77-
| ![](/img/reuse/outage_critical.png) | **Critical.** Major system outage. |
78-
| ![](/img/reuse/outage_major.png) | **Major.** Partial system outage. |
79-
| ![](/img/reuse/outage_minor.png) | **Minor.** Minor system outage. |
77+
| <img src={useBaseUrl('img/reuse/outage_critical.png')} alt="Critical icon" style={{border: '1px solid gray'}} width="25" />| **Critical.** Major system outage. |
78+
| <img src={useBaseUrl('img/reuse/outage_major.png')} alt="Major icon" style={{border: '1px solid gray'}} width="25" /> | **Major.** Partial system outage. |
79+
| <img src={useBaseUrl('img/reuse/outage_minor.png')} alt="Minor icon" style={{border: '1px solid gray'}} width="25" /> | **Minor.** Minor system outage. |
8080

8181
To determine which pod your account uses, look at the Sumo Logic URL. If you see `us2`, that means you're running on the US2 pod. If you see `eu` or `au`, you're on one of those pods.

0 commit comments

Comments
 (0)