Skip to content

Commit a9fbe7c

Browse files
committed
Merge branch 'main' into DOCS-712-Remove-RSS-image-in-all-Release-Notes
2 parents a86f66f + d02e35f commit a9fbe7c

File tree

270 files changed

+3793
-2072
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

270 files changed

+3793
-2072
lines changed

.clabot

Lines changed: 6 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -5,6 +5,8 @@
55
"JV0812",
66
"jpipkin1",
77
"JainM6",
8+
"@dependabot[bot]",
9+
"dependabot[bot]",
810
"docsSeema",
911
"angadrandhawa1",
1012
"kkujawa-sumo",
@@ -176,7 +178,10 @@
176178
"chvik",
177179
"Apoorvkudesia-sumologic",
178180
"akesle",
179-
"ankitgoelcmu"
181+
"ankitgoelcmu",
182+
"Deklin",
183+
"justrelax19",
184+
"dlindelof-sumologic"
180185
],
181186
"message": "Thank you for your contribution! As this is an open source project, we require contributors to sign our Contributor License Agreement and do not have yours on file. To proceed with your PR, please [sign your name here](https://forms.gle/YgLddrckeJaCdZYA6) and we will add you to our approved list of contributors.",
182187
"label": "cla-signed",

blog-cse/2025-02-27-content.md

Lines changed: 28 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,28 @@
1+
---
2+
title: February 27, 2025 - Content Release
3+
image: https://help.sumologic.com/img/sumo-square.png
4+
keywords:
5+
- log mappers
6+
- parsers
7+
hide_table_of_contents: true
8+
---
9+
10+
import useBaseUrl from '@docusaurus/useBaseUrl';
11+
12+
<a href="https://help.sumologic.com/release-notes-cse/rss.xml"><img src={useBaseUrl('img/release-notes/rss-orange2.png')} alt="icon" width="50"/></a>
13+
14+
This content release includes updates to mapping and parsing to support additional AWS CloudTrail, F5 Firewall, and modify behavior in Microsoft Office 365 login events.
15+
16+
Changes are enumerated below.
17+
18+
## Log Mappers
19+
- [New] CloudTrail Batch get Partition
20+
- [New] F5 Tmm Audit and APMD Audit - Custom Parser
21+
- [New] F5 Session and adfs proxy - Custom Parser
22+
- [Updated] F5 SSHD and Apmd - Custom Parser
23+
- Expands scope of existing mapper to include Apmd events.
24+
- [Updated] Microsoft Office 365 Active Directory Authentication Events
25+
- Adds exclusion for invalid user ID `00000000-0000-0000-0000-000000000000`.
26+
27+
## Parsers
28+
- [Updated] /Parsers/System/F5/F5 Syslog

blog-cse/2025-03-03-application.md

Lines changed: 18 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,18 @@
1+
---
2+
title: March 3, 2025 - Application Update
3+
image: https://help.sumologic.com/img/sumo-square.png
4+
keywords:
5+
- threat intel
6+
- security
7+
hide_table_of_contents: true
8+
---
9+
10+
import useBaseUrl from '@docusaurus/useBaseUrl';
11+
12+
<a href="https://help.sumologic.com/release-notes-cse/rss.xml"><img src={useBaseUrl('img/release-notes/rss-orange2.png')} alt="icon" width="50"/></a>
13+
14+
### Threat Intelligence
15+
16+
We’re excited to introduce Sumo Logic Threat Intelligence, a powerful feature set that enables Cloud SIEM administrators to seamlessly import indicators of Compromise (IoC) files and feeds directly into Sumo Logic to aid in security analysis.
17+
18+
For more information, [see our release note](/release-notes-service/2025/03/03/security/) in the *Service* release notes section.

blog-cse/2025-03-10-application.md

Lines changed: 20 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,20 @@
1+
---
2+
title: March 10, 2025 - Application Update
3+
image: https://help.sumologic.com/img/sumo-square.png
4+
keywords:
5+
- custom insights
6+
- insights
7+
hide_table_of_contents: true
8+
---
9+
10+
import useBaseUrl from '@docusaurus/useBaseUrl';
11+
12+
<a href="https://help.sumologic.com/release-notes-cse/rss.xml"><img src={useBaseUrl('img/release-notes/rss-orange2.png')} alt="icon" width="50"/></a>
13+
14+
### Strict signal configuration
15+
16+
We're happy to announce that now when you create custom insights, you can select an option to generate insights only on those signals defined in your custom insight. Any additional signals related to the applicable entity are excluded. This allows you to generate insights for an immediate and targeted response.
17+
18+
[Learn more](/docs/cse/records-signals-entities-insights/configure-custom-insight/#for-only-signals-defined-in-the-custom-insight).
19+
20+
<img src={useBaseUrl('img/cse/strict-signal-configuration-checkbox.png')} alt="Strict Signal Configuration checkbox" style={{border: '1px solid gray'}} width="400"/>

blog-cse/2025-03-13-content.md

Lines changed: 87 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,87 @@
1+
---
2+
title: March 13, 2025 - Content Release
3+
image: https://help.sumologic.com/img/sumo-square.png
4+
keywords:
5+
- log mappers
6+
- parsers
7+
- rules
8+
hide_table_of_contents: true
9+
---
10+
11+
import useBaseUrl from '@docusaurus/useBaseUrl';
12+
13+
<a href="https://help.sumologic.com/release-notes-cse/rss.xml"><img src={useBaseUrl('img/release-notes/rss-orange2.png')} alt="icon" width="50"/></a>
14+
15+
16+
This release includes:
17+
- New detection rules for Azure DevOps to identify suspicious or sensitive activity in CI/CD pipelines
18+
- New support for Barracuda WAF and CloudGen Firewall
19+
- Support for CyberArk Audit events
20+
- Updates to 1Password mappers to realign field mappings to reflect proper directionality
21+
- Fix for normalizedActions in AWS CloudTrail Policy Change mapper
22+
- Additions to CrowdStrike Audit and UserActivity log mappers to map additional fields and add alternate values
23+
- Support for additional events from Kubernetes and Linux OS logs
24+
25+
## Rules
26+
- [New] CHAIN-S00022 Azure DevOps - Agent Pool Created and Deleted within a Short Period
27+
- This detection monitors for the creation and deletion of Agent Pools within 5 days by the same user, with the intent of finding Agent Pools active for short durations.
28+
- [New] MATCH-S00997 Azure DevOps - Browser Observed in Personal Access Token (PAT) Use
29+
- This detection monitors for the use of a PAT for authentication from a User Agent String indicating a web browser.
30+
- [New] MATCH-S00995 Azure DevOps - Change Made to Administrator Group
31+
- This detection monitors for additions to the following groups: Project Administrators, Project Collection Administrators, Project Collection Service Accounts, Build Administrators, Project Collection Build Administrators
32+
- [New] FIRST-S00098 Azure DevOps - First Seen Pull Request Policy Bypassed
33+
- This detection monitors for when a user performs a pull request bypass for the first time.
34+
- [New] FIRST-S00099 Azure DevOps - First Seen User Creating Agent Pool
35+
- This detection monitors for new users creating an agent pool. This user has not been observed creating agent pools during the baseline period and may be a new admin or involved in suspicious account activity.
36+
- [New] FIRST-S00092 Azure DevOps - First Seen User Creating Release Pipeline
37+
- This detection monitors for users creating a release pipeline for the first time after the baseline period (by default, 90 days).
38+
- [New] FIRST-S00097 Azure DevOps - First Seen User Modifying Build Variables
39+
- This detection monitors for a user modifying a variable group for the first time.
40+
- [New] FIRST-S00096 Azure DevOps - First Seen User Modifying Release Pipeline
41+
- This detection monitors for users modifying a release pipeline for the first time after the baseline period (by default, 90 days).
42+
- [New] MATCH-S00998 Azure DevOps - Known Malicious Tooling Detected ADOKit
43+
- This is a simple detection matching on “ADOKit” at the start of the HTTP User Agent String (UAS). This detection effectively catches basic ADOKit use. It is brittle to attackers changing the User Agent String to another more innocuous browser to mask the traffic.
44+
- [New] MATCH-S00994 Azure DevOps - Member Added to Sensitive Group
45+
- This detection monitors for changes to the following groups: Project Administrators, Project Collection Administrators, Project Collection Service Accounts, Build Administrator
46+
- [New] FIRST-S00095 Azure DevOps - New Agent OS Added to Agent Pool
47+
- This detection monitors for the addition of an agent to an agent pool when the OS of the agent has not been observed in this pool during the baseline period.
48+
- [New] FIRST-S00094 Azure DevOps - New Extension Installed
49+
- This detection monitors for new extensions installed organization-wide after a 30-day baseline, based on the user installing the new extension.
50+
- [New] OUTLIER-S00030 Azure DevOps - Outlier in Pools Deleted Rapidly
51+
- This detection identifies statistical outliers in user behavior for the number of pools deleted in an hourly window.
52+
- [New] MATCH-S00996 Azure DevOps - Personal Access Token (PAT) Misuse Observed
53+
- This detection monitors for use of a Personal Access Token in conjunction with categories of action that aren’t normally associated with PAT authentication.
54+
- [New] CHAIN-S00021 Azure DevOps - Pipeline Created and Deleted within a Short Period
55+
- This detection monitors for the creation and deletion of the same pipeline within a short period (by default, a day).
56+
- [New] MATCH-S00993 Azure DevOps - Pipeline Retention Settings Reduced
57+
- This detection monitors for any reduction in the pipeline retention settings.
58+
59+
60+
## Log Mappers
61+
- [New] Barracuda Authentication
62+
- [New] Barracuda Catch All
63+
- [New] Barracuda CloudGen Auth Service dcclient and events
64+
- [New] Barracuda CloudGen Firewall Activity
65+
- [New] Barracuda CloudGen Settings DNS
66+
- [New] Barracuda Network Firewall Event|Web Firewall Event|Access Firewall Event
67+
- [New] Barracuda System Event
68+
- [New] CyberArk Audit Authentication
69+
- [New] CyberArk Audit Catch All
70+
- [Updated] 1Password Item Audit Actions
71+
- [Updated] 1Password Item Usage Actions
72+
- [Updated] 1Password Item Usage C2C
73+
- [Updated] 1Password Signin C2C
74+
- [Updated] CloudTrail - iam.amazonaws.com - Policy Change
75+
- [Updated] CrowdStrike Audit Logs
76+
- [Updated] CrowdStrike Falcon Host API DetectionSummaryEvent
77+
- [Updated] CrowdStrike Falcon Host API DetectionSummaryEvent (CNC)
78+
- [Updated] CrowdStrike UserActivity Logs
79+
- [Updated] Linux OS Syslog - Process sshd - SSH Auth Failure
80+
- [Updated] Linux OS Syslog - Process sshd - SSH Bind Listening and negotiate event
81+
82+
## Parsers
83+
- [New] /Parsers/System/Barracuda/Barracuda CloudGen
84+
- [New] /Parsers/System/Barracuda/Barracuda WAF
85+
- [New] /Parsers/System/Cyber-Ark/CyberArk Audit
86+
- [Updated] /Parsers/System/Kubernetes/Kubernetes
87+
- [Updated] /Parsers/System/Linux/Linux OS Syslog

blog-csoar/2024/12-31.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -35,7 +35,7 @@ This release introduces new integrations, new playbooks, and several updates.
3535
#### Integrations
3636

3737
* [New] [Google Chat](/docs/platform-services/automation-service/app-central/integrations/google-chat)
38-
* [New] [Malwarebytes Oneview](/docs/platform-services/automation-service/app-central/integrations/malwarebytes-oneview)
38+
* [New] [Malwarebytes ThreatDown OneView](/docs/platform-services/automation-service/app-central/integrations/threatdown-oneview)
3939
* [New] [Silent Push](/docs/platform-services/automation-service/app-central/integrations/silent-push)
4040
* [New] [Sumo Logic Automation Tools](/docs/platform-services/automation-service/app-central/integrations/sumo-logic-automation-tools)
4141
* [New] [VirusTotal V3](/docs/platform-services/automation-service/app-central/integrations/virustotal-v3)

blog-service/2025-02-27-apps.md

Lines changed: 15 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,15 @@
1+
---
2+
title: Automox (Apps)
3+
image: https://help.sumologic.com/img/sumo-square.png
4+
keywords:
5+
- apps
6+
- automox
7+
hide_table_of_contents: true
8+
---
9+
10+
import useBaseUrl from '@docusaurus/useBaseUrl';
11+
12+
<a href="https://help.sumologic.com/release-notes-service/rss.xml"><img src={useBaseUrl('img/release-notes/rss-orange2.png')} alt="icon" width="50"/></a>
13+
14+
We're excited to introduce the new Automox app for Sumo Logic. This app leverages the Sumo Logic Cloud-to-Cloud Automox source to collect audit and event logs from the Automox platform. It provides security and IT teams with visibility into endpoint management and security. By using this app, teams can improve their security monitoring, streamline endpoint management, and strengthen operational resilience. [Learn more](/docs/integrations/saas-cloud/automox/).
15+
Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,14 @@
1+
---
2+
title: CyberArk Audit Source (Collection)
3+
image: https://help.sumologic.com/img/sumo-square.png
4+
keywords:
5+
- collection
6+
- cyberark-audit-source
7+
hide_table_of_contents: true
8+
---
9+
10+
import useBaseUrl from '@docusaurus/useBaseUrl';
11+
12+
<a href="https://help.sumologic.com/release-notes-service/rss.xml"><img src={useBaseUrl('img/release-notes/rss-orange2.png')} alt="icon" width="50"/></a>
13+
14+
We're excited to announce the release of our new cloud-to-cloud source for CyberArk Audit. This source aims to collect the audit events from the CyberArk platform using the CyberArk SIEM integrations API and send them to Sumo Logic for streamlined analysis. [Learn more](/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/cyberark-audit-source).

blog-service/2025-02-28-apps.md

Lines changed: 36 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,36 @@
1+
---
2+
title: Apps, Solutions, and Collection Integrations - February Release
3+
image: https://help.sumologic.com/img/sumo-square.png
4+
keywords:
5+
- apps
6+
- february-release
7+
hide_table_of_contents: true
8+
---
9+
10+
import useBaseUrl from '@docusaurus/useBaseUrl';
11+
12+
<a href="https://help.sumologic.com/release-notes-service/rss.xml"><img src={useBaseUrl('img/release-notes/rss-orange2.png')} alt="icon" width="50"/></a>
13+
14+
### New release
15+
16+
We’re excited to announce the release of the new Azure Container Instance app and three OpenTelemetry Remote Management source templates for Sumo Logic.
17+
18+
- **Azure Container Instance app**. Azure Container Instances is a fully managed serverless container service that enables you to deploy and manage containers in Azure without the need for virtual machines. This integration allows you to analyse logs and metrics pertaining to Azure Container Instances. [Learn more](/docs/integrations/microsoft-azure/azure-container-instances/).
19+
20+
- **OpenTelemetry Remote Management**. Released [MySQL](/docs/send-data/opentelemetry-collector/remote-management/source-templates/mysql/), [PostgreSQL](/docs/send-data/opentelemetry-collector/remote-management/source-templates/postgresql/), and [ElasticSearch](/docs/send-data/opentelemetry-collector/remote-management/source-templates/elasticsearch/) OpenTelemetry Remote Management source templates.
21+
22+
### Enhancements
23+
24+
- **AWS Serverless Application Models and CloudFormation templates**. Updated the following AWS Serverless Application Models (SAMs) and CloudFormation templates with the latest [Lambda runtimes](https://docs.aws.amazon.com/lambda/latest/dg/lambda-runtimes.html):
25+
- **[Node.js 22](https://github.com/SumoLogic/sumologic-aws-lambda/releases/tag/v1.2.18)**
26+
- [sumologic-loggroup-connector](https://github.com/SumoLogic/sumologic-aws-lambda/tree/main/loggroup-lambda-connector) - SAM SemanticVersion: 1.0.15.
27+
- [sumologic-guardduty-events-processor](https://github.com/SumoLogic/sumologic-aws-lambda/tree/main/cloudwatchevents/guardduty) - SAM SemanticVersion: 1.0.6.
28+
- [sumologic-guardduty-benchmark](https://github.com/SumoLogic/sumologic-aws-lambda/tree/main/cloudwatchevents/guarddutybenchmark) - SAM SemanticVersion: 1.0.17.
29+
- [AWS CloudWatch Logs With Dead Letter Queue](https://github.com/SumoLogic/sumologic-aws-lambda/tree/main/cloudwatchlogs-with-dlq)
30+
- **[Python 3.13](https://github.com/SumoLogic/sumologic-aws-lambda/releases/tag/v1.2.19)**
31+
- [sumologic-s3-logging-auto-enable](https://github.com/SumoLogic/sumologic-aws-lambda/tree/main/awsautoenableS3Logging) - SAM SemanticVersion: 1.0.17.
32+
- [sumologic-aws-cloudtrail-benchmark](https://github.com/SumoLogic/sumologic-aws-lambda/tree/main/cloudtrailbenchmark) - SAM SemanticVersion: 1.0.20.
33+
- [sumologic-app-utils](https://github.com/SumoLogic/sumologic-aws-lambda/tree/main/sumologic-app-utils) - SAM SemanticVersion: 2.0.20.
34+
- [sumologic-securityhub-collector](https://github.com/SumoLogic/sumologic-aws-lambda/tree/main/securityhub-collector/sam) - SAM SemanticVersion: 1.0.10.
35+
- [sumologic-securityhub-forwarder](https://github.com/SumoLogic/sumologic-aws-lambda/tree/main/securityhub-forwarder) - SAM SemanticVersion: 1.0.11.
36+
- [Kinesis Metric Collection](https://github.com/SumoLogic/sumologic-aws-lambda/tree/main/kinesis-firehose-cloudwatch-collection/metrics)
Lines changed: 41 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,41 @@
1+
---
2+
title: New in Copilot - Dynamic Titles, Alert Troubleshooting, and Pinned Suggestions (Copilot)
3+
image: https://help.sumologic.com/img/sumo-square.png
4+
keywords:
5+
- copilot
6+
- log-search
7+
- search
8+
hide_table_of_contents: true
9+
---
10+
11+
import useBaseUrl from '@docusaurus/useBaseUrl';
12+
13+
<a href="https://help.sumologic.com/release-notes-service/rss.xml"><img src={useBaseUrl('img/release-notes/rss-orange2.png')} alt="icon" width="50"/></a>
14+
15+
We've introduced three new features to improve your Copilot experience:
16+
17+
### Dynamic Conversation Titles
18+
19+
Copilot now automatically updates conversation titles based on your query, making it easier to track and revisit past investigations. You can also customize it by clicking the pencil icon next to the title.
20+
21+
* **Better organization**. Conversations now have meaningful names for easy navigation.
22+
* **Faster troubleshooting**. Quickly find and resume previous investigations.
23+
* **More control**. Rename conversations to match your workflow.
24+
25+
26+
### "Open in Copilot" for Alerts
27+
28+
We've added an **Open in Copilot** button to the Alert Response page, allowing you to troubleshoot alerts directly in Copilot. This preserves the alert context, making it seamless to investigate and resolve issues.
29+
30+
* **Faster root cause analysis**. Jump into Copilot instantly from an alert.
31+
* **Context-aware troubleshooting**. Maintain alert details while searching logs.
32+
33+
34+
### Suggestion Pinning
35+
36+
Now you can pin Copilot suggestions for easy reference. Just hover over a suggestion and click the pin icon to save it within your conversation.
37+
38+
* **Quick access**. Keep important suggestions handy for ongoing investigations.
39+
* **Improved workflow**. No need to scroll back to find key recommendations.
40+
41+
[Learn more](/docs/search/copilot).

0 commit comments

Comments
 (0)