Skip to content

Commit c74045d

Browse files
committed
Updates from review
1 parent 0b5f3d6 commit c74045d

File tree

1 file changed

+10
-9
lines changed

1 file changed

+10
-9
lines changed

blog-cse/2025/01-14.md

Lines changed: 10 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -1,10 +1,12 @@
11
### January 14, 2025 - Content Release
22

33
This content release includes:
4-
- Parsing and mapping support for Azure DevOps Auditing via EventHubs, and Pfsense Firewall,
5-
- Parsing and mapping additions and updates for Cisco ISE, Cloudflare, Check Point Firewall, and Linux OS Syslog
4+
- Parsing and mapping support for Azure DevOps Auditing via EventHubs, and Pfsense Firewall.
5+
- Parsing and mapping additions and updates for Cisco ISE, Cloudflare, Check Point Firewall, and Linux OS Syslog.
66

7-
* Note: In ~2 weeks MATCH-S00604 "OneLogin - API Credentials - Key Used from Untrusted Location" will be deleted from OOTB Cloud SIEM Rules due to unmanageable deny list logic and low adoption. To retain this rule, a duplicate must be made prior to the deletion.
7+
:::note
8+
In two weeks, MATCH-S00604 "OneLogin - API Credentials - Key Used from Untrusted Location" will be deleted from the out-of-the-box Cloud SIEM rules due to unmanageable deny list logic and low adoption. To retain this rule, a duplicate must be made prior to the deletion.
9+
:::
810

911
## Log Mappers
1012
- [New] Azure DevOps Auditing Catch All
@@ -20,15 +22,15 @@ This content release includes:
2022
- [New] Pfsense Firewall openvpn_peer_info|openvpn_error|php_log|sshguard|sshd_log
2123
- [New] Pfsense Firewall openvpn_server_connected|openvpn_server_disconnected|cron_log
2224
- [Updated] Cisco ISE Authentication Failure
23-
- Adds normalizedSeverity mapping
25+
- Adds `normalizedSeverity` mapping
2426
- [Updated] Cisco ISE Authentication Success
25-
- Adds normalizedSeverity mapping
27+
- Adds `normalizedSeverity` mapping
2628
- [Updated] Cloudflare - Logpush
27-
- Adds mapping for dns_query, http_hostname,http_response_contentLength, http_response_contentType, and an alternative value for ipProtocol.
29+
- Adds mapping for `dns_query`, `http_hostname`, `http_response_contentLength`, `http_response_contentType`, and an alternative value for `ipProtocol`.
2830
- [Updated] Linux OS Syslog - Process sshd - SSH Session Closed|disconnect
29-
- Adds mapping for normalizedAction
31+
- Adds mapping for `normalizedActio`n
3032
- [Updated] Linux OS Syslog - Process systemd - Systemd Session Start and Systemd File Configuration
31-
- Added support for additional events and mapping of file_path
33+
- Added support for additional events and mapping of `file_path`
3234

3335
## Parsers
3436
- [New] /Parsers/System/Pfsense/Pfsense Firewall
@@ -37,5 +39,4 @@ This content release includes:
3739
- [Updated] /Parsers/System/Cloudflare/Cloudflare Logpush
3840
- [Updated] /Parsers/System/Linux/Linux OS Syslog
3941
- [Updated] /Parsers/System/Linux/Shared/Linux Shared Syslog Headers
40-
4142
- [Updated] /Parsers/System/Linux/Shared/Linux Shared Syslog Headers

0 commit comments

Comments
 (0)