You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
- Parsing and mapping support for Azure DevOps Auditing via EventHubs, and Pfsense Firewall,
5
-
- Parsing and mapping additions and updates for Cisco ISE, Cloudflare, Check Point Firewall, and Linux OS Syslog
4
+
- Parsing and mapping support for Azure DevOps Auditing via EventHubs, and Pfsense Firewall.
5
+
- Parsing and mapping additions and updates for Cisco ISE, Cloudflare, Check Point Firewall, and Linux OS Syslog.
6
6
7
-
* Note: In ~2 weeks MATCH-S00604 "OneLogin - API Credentials - Key Used from Untrusted Location" will be deleted from OOTB Cloud SIEM Rules due to unmanageable deny list logic and low adoption. To retain this rule, a duplicate must be made prior to the deletion.
7
+
:::note
8
+
In two weeks, MATCH-S00604 "OneLogin - API Credentials - Key Used from Untrusted Location" will be deleted from the out-of-the-box Cloud SIEM rules due to unmanageable deny list logic and low adoption. To retain this rule, a duplicate must be made prior to the deletion.
9
+
:::
8
10
9
11
## Log Mappers
10
12
-[New] Azure DevOps Auditing Catch All
@@ -20,15 +22,15 @@ This content release includes:
- Adds mapping for dns_query, http_hostname,http_response_contentLength, http_response_contentType, and an alternative value for ipProtocol.
29
+
- Adds mapping for `dns_query`, `http_hostname`, `http_response_contentLength`, `http_response_contentType`, and an alternative value for `ipProtocol`.
28
30
-[Updated] Linux OS Syslog - Process sshd - SSH Session Closed|disconnect
29
-
- Adds mapping for normalizedAction
31
+
- Adds mapping for `normalizedActio`n
30
32
-[Updated] Linux OS Syslog - Process systemd - Systemd Session Start and Systemd File Configuration
31
-
- Added support for additional events and mapping of file_path
33
+
- Added support for additional events and mapping of `file_path`
0 commit comments