Skip to content

Commit c813255

Browse files
authored
Merge branch 'main' into csiem-ga-docs
2 parents 241e67d + 893b56e commit c813255

30 files changed

+455
-13
lines changed

blog-service/2025-08-29-apps.md

Lines changed: 12 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,12 @@
1+
---
2+
title: Zimperium (Apps)
3+
image: https://help.sumologic.com/img/reuse/rss-image.jpg
4+
keywords:
5+
- apps
6+
- zimperium
7+
hide_table_of_contents: true
8+
---
9+
10+
import useBaseUrl from '@docusaurus/useBaseUrl';
11+
12+
We're excited to introduce the new Zimperium app for Sumo Logic. This app provides visibility into mobile threats by centralizing threat intelligence and device telemetry, and collects threat logs for analysis in Sumo Logic. [Learn more](/docs/integrations/saas-cloud/zimperium/).

blog-service/2025-08-31-apps.md

Lines changed: 35 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,35 @@
1+
---
2+
title: Apps, Solutions, and Collection Integrations - August Release
3+
image: https://help.sumologic.com/img/reuse/rss-image.jpg
4+
keywords:
5+
- apps
6+
- august-release
7+
hide_table_of_contents: true
8+
---
9+
10+
import useBaseUrl from '@docusaurus/useBaseUrl';
11+
12+
13+
14+
### New release
15+
16+
We’re excited to announce the release of the new Azure Event Hubs app and OpenTelemetry Collector Insights app for Sumo Logic.
17+
18+
- **Azure Event Hubs**. The Azure Event Hubs app helps monitor data plane operations, such as sending or receiving events, and tracks performance metrics, including consumer lag, throughput, and active connections. [Learn more](/docs/integrations/microsoft-azure/azure-event-hubs/).
19+
- **OpenTelemetry Collector Insights**. The OpenTelemetry Collector Insights app provides end-to-end monitoring for your OpenTelemetry Collector instances, enabling you to track performance, data flow, and resource utilization. Use preconfigured dashboards and alerts to troubleshoot issues and ensure your telemetry pipeline runs smoothly and efficiently. [Learn more](/docs/integrations/sumo-apps/opentelemetry-collector-insights/).
20+
21+
### Enhancements
22+
23+
- **Azure Virtual Machine**. Automated Metric Rule creation during app install. [Learn more](/docs/integrations/microsoft-azure/azure-virtual-machine/#installing-the-azure-virtual-machine-app).
24+
- **CircleCI Integration**. Updated the CircleCI integration to handle the BLOCKED job state.
25+
- **AWS Serverless Application Model (SAM)**. Released the following SAM:
26+
- `sumologic-app-utils` - SemanticVersion 2.0.21
27+
- `sumologic-s3-logging-auto-enable` - SemanticVersion 1.0.18
28+
- `sumologic-guardduty-benchmark` - SemanticVersion 1.0.18
29+
- `sumologic-aws-cloudtrail-benchmark` - SemanticVersion 1.0.21
30+
- **Windows ST**. A flag to prevent the collector from shutting down when it fails to open the event log channel; instead, it logs a warning.
31+
32+
### Bug Fixes
33+
34+
- **Groovy script of Jenkins plugin**. The Groovy script used in the Jenkins plugin has been updated to automate input handling with the correct data type.
35+
- **Jenkins plugin**. Released with dependency upgrades and vulnerability fixes.

cid-redirects.json

Lines changed: 16 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -574,6 +574,8 @@
574574
"/Search/Search-Query-Language": "/docs/search/search-query-language",
575575
"/docs/search/search-syntax": "/docs/search/search-query-language",
576576
"/docs/search/search-query-language/operators/eval": "/docs/metrics/metrics-operators/eval",
577+
"/docs/search/search-query-language/search-operators/eval": "/docs/metrics/metrics-operators/eval",
578+
"/docs/search/search-query-language/search-operators/eval-operator": "/docs/metrics/metrics-operators/eval",
577579
"/Search/Search-Query-Language/Search-Operators/join": "/docs/search/search-query-language/search-operators/join",
578580
"/05Search/Search-Query-Language/Search-Operators/length": "/docs/search/search-query-language/search-operators/length",
579581
"/05Search/Search-Query-Language/Search-Operators/limit": "/docs/search/search-query-language/search-operators/limit",
@@ -1416,7 +1418,8 @@
14161418
"/Send_Data": "/docs/send-data",
14171419
"/Send_Data/Collector_Management_API/Sumo_Logic_Endpoints": "/docs/api/collector-management",
14181420
"/Send_Data/Collector_Management_API/About_the_Collector_Management_API": "/docs/api/collector-management",
1419-
"/Send_Data/Collector_FAQs/How_to_Ingest_Old_or_Historical_Data": "/docs/send-data/opentelemetry-collector/faq",
1421+
"/Send_Data/Collector_FAQs/How_to_Ingest_Old_or_Historical_Data": "/docs/send-data/collector-faq",
1422+
"/Send_Data/Collector_FAQs/How_to_tell_which_version_of_the_Collector_is_installed": "/docs/send-data/collector-faq",
14201423
"/APIs/General-API-Information/Sumo-Logic-Endpoints-by-Deployment-and-Firewall-Security": "/docs/api/about-apis/getting-started",
14211424
"/APIs/General-API-Information/Sumo-Logic-Endpoints-and-Firewall-Security": "/docs/api/about-apis/getting-started",
14221425
"/APIs/Partition_Management_API": "/docs/api/partition-management",
@@ -1466,6 +1469,7 @@
14661469
"/Dashboards-and-Alerts/Dashboards/Chart-Panel-Types": "/docs/dashboards/panels",
14671470
"/Dashboards-and-Alerts/Dashboards/Chart-Panel-Types/Area-Charts": "/docs/dashboards/panels/area-charts",
14681471
"/Dashboards_and_Alerts/Dashboards/Chart_Panel_Types/Line_Charts": "/docs/dashboards/panels/line-charts",
1472+
"/Dashboards_and_Alerts/Dashboards/Troubleshoot_Dashboards/Why_can't_I_view_a_search_from_a_Dashboard": "/docs/dashboards",
14691473
"/Dashboards-and-Alerts/Dashboards/Edit-Dashboards-and-Panels/Change-Gridlines-on-the-Y-Axis": "/docs/dashboards/panels",
14701474
"/Dashboards-and-Alerts/Dashboards/Edit-Dashboards-and-Panels/Change-the-Color-of-a-Chart-by-Value-Range-on-the-Search-Page": "/docs/dashboards",
14711475
"/Dashboards-and-Alerts/Dashboards/Edit-Dashboards-and-Panels/Change-the-Color-of-a-Chart": "/docs/dashboards",
@@ -2081,6 +2085,7 @@
20812085
"/cid/22674": "/docs/integrations/google/cloud-functions",
20822086
"/cid/22675": "/docs/integrations/google/cloud-sql",
20832087
"/cid/23233": "/docs/integrations/saas-cloud/zendesk",
2088+
"/cid/23234": "/docs/integrations/saas-cloud/zimperium",
20842089
"/cid/2323": "/docs/integrations/saas-cloud/zoom",
20852090
"/cid/23239": "/docs/integrations/saas-cloud/lastpass",
20862091
"/cid/2324": "/docs/integrations/saas-cloud/workday",
@@ -3051,6 +3056,7 @@
30513056
"/Cloud_SIEM_Enterprise/Records%2C_Signals%2C_Entities%2C_and_Insights/00Insight_Generation_Process": "/docs/cse/get-started-with-cloud-siem/insight-generation-process",
30523057
"/Cloud_SIEM_Enterprise/Records%2C_Signals%2C_Entities%2C_and_Insights/05Set_Insight_Generation_Window_and_Threshold": "/docs/cse/records-signals-entities-insights/set-insight-generation-window-threshold",
30533058
"/docs/cse/records-signals-entities-insights/signal-index-migration-faq": "/docs/cse/records-signals-entities-insights/search-cse-records-in-sumo",
3059+
"/docs/cse/records-signals-entities-insights/signals-overview": "/docs/cse/records-signals-entities-insights",
30543060
"/Cloud_SIEM_Enterprise/Records%2C_Signals%2C_Entities%2C_and_Insights/07Entity_Criticality": "/docs/cse/records-signals-entities-insights/entity-criticality",
30553061
"/Cloud_SIEM_Enterprise/Records%2C_Signals%2C_Entities%2C_and_Insights/11Create_a_Custom_Entity_Type": "/docs/cse/records-signals-entities-insights/create-custom-entity-type",
30563062
"/Cloud_SIEM_Enterprise/Records%2C_Signals%2C_Entities%2C_and_Insights/13Using_Tags_with_Insights%2C_Signals%2C_Entities%2C_and_Rules": "/docs/cse/records-signals-entities-insights/tags-insights-signals-entities-rules",
@@ -3632,11 +3638,13 @@
36323638
"/Send_Data/Sources": "/docs/send-data",
36333639
"/Send_Data/Sources/01Sources_for_Installed_Collectors/Preconfigure_a_Machine_to_Collect_Remote_Windows_Events": "/docs/send-data/installed-collectors/sources/preconfigure-machine-collect-remote-windows-events",
36343640
"/Send_Data/Sources/01Sources_for_Installed_Collectors/Script_Action": "/docs/send-data/installed-collectors/sources/script-action",
3641+
"/Send_Data/Sources/01Sources_for_Installed_Collectors/Script_Source/Calling_PowerShell_from_a_Sumo_Logic_Script_Source": "/docs/send-data/installed-collectors/sources/script-source",
36353642
"/Send_Data/Sources/01Sources_for_Installed_Collectors/Syslog_Source": "/docs/send-data/hosted-collectors/cloud-syslog-source",
36363643
"/Send_Data/Sources/01Sources_for_Installed_Collectors/Local_File_Source": "/docs/send-data/installed-collectors/sources/local-file-source",
36373644
"/Send_Data/Sources/01Sources_for_Installed_Collectors/Local_File_Source/Define_Boundary_Regex_for_Multiline_Messages": "/docs/send-data/installed-collectors/sources/define-boundary-regex-multiline-messages",
36383645
"/Search/Search-FAQs/Compare-Log-Messages-by-Day-of-the-Week": "/docs/search/faq",
36393646
"/Search/Search-FAQs/Export-the-Results-of-a-Saved-File": "/docs/search/faq",
3647+
"/Search/Search_FAQs/How_to_reference_a_field_name_that_contains_a_special_character": "/docs/search/faq",
36403648
"/Search/Search_Cheat_Sheets/Search-Operators-Cheat-Sheet": "/docs/search/search-cheat-sheets",
36413649
"/Search/Search_Cheat_Sheets/Search_Operators_Cheat_Sheet": "/docs/search/search-cheat-sheets",
36423650
"/Search/Search_Job_API/Search_Job_API": "/docs/api/search-job",
@@ -3894,6 +3902,7 @@
38943902
"/Beta": "/docs/beta",
38953903
"/Beta/APIs": "/docs/api",
38963904
"/Beta/APIs/APIs": "/docs/api",
3905+
"/Beta/Audit_Event_Index": "/docs/manage/security/audit-indexes/audit-event-index",
38973906
"/Beta/AWS_Kinesis_Firehose_for_Logs_Source": "/docs/send-data/hosted-collectors/amazon-aws/aws-kinesis-firehose-logs-source",
38983907
"/Beta/AWS_Lambda_-_Python_function_instrumentation_with_Sumo_Logic_tracing": "/docs/apm/traces/get-started-transaction-tracing/opentelemetry-instrumentation/python",
38993908
"/Beta/AWS_Lambda_-_Java_function_instrumentation_with_Sumo_Logic_tracing": "/docs/apm/traces/get-started-transaction-tracing/opentelemetry-instrumentation/aws-lambda/java",
@@ -3929,6 +3938,7 @@
39293938
"/Beta/Saved_beta_content/Beta---Library/Apps_in_Sumo_Logic/01_Sumo_Logic_Apps": "/docs/integrations",
39303939
"/Beta/SLO_Reliability_Management": "/docs/observability/reliability-management-slo",
39313940
"/Beta/SLO_Reliability_Management/Access_and_Create_SLOs": "/docs/observability/reliability-management-slo",
3941+
"/Beta/Traces/HTTP_Traces_Source": "/docs/send-data/hosted-collectors/http-source/traces",
39323942
"/Beta/Workday/Collect_Logs_for_the_Workday_App": "/docs/integrations/saas-cloud/workday",
39333943
"/docs/beta/search-log-level": "/docs/search/get-started-with-search/search-page/log-level",
39343944
"/docs/search/get-started-with-search/search-page/event-analytics/": "/docs/search/get-started-with-search/search-page",
@@ -4017,15 +4027,18 @@
40174027
"/Search/Search-Query-Language/Search-Operators/format": "/docs/search/search-query-language/search-operators/formatdate",
40184028
"/Search/Search_Query_Language/Search_Operators/Geo_Lookup": "/docs/search/search-query-language/search-operators/geo-lookup-map",
40194029
"/Search/Search-Query-Language/Search-Operators/Geo-Lookup-(Map)": "/docs/search/search-query-language/search-operators/geo-lookup-map",
4030+
"/Search/Search_Query_Language/Search_Operators/ipv4ToNumber": "/docs/search/search-query-language/search-operators/ipv4tonumber",
40204031
"/Search/Search_Query_Language/Search_Operators/num": "/docs/search/search-query-language/search-operators/num",
40214032
"/Search/Search-Query-Language/Search-Operators/sessionize": "/docs/search/search-query-language/search-operators/sessionize",
40224033
"/Search/Search_Query_Language/Search_Operators/outlier": "/docs/search/search-query-language/search-operators/outlier",
40234034
"/Search/Search_Query_Language/Search_Operators/where": "/docs/search/search-query-language/search-operators/where",
40244035
"/Search/Search_Query_Language/Transaction_Analytics": "/docs/search/search-query-language/transaction-analytics",
4036+
"/Search/Search_Query_Language/Transaction_Analytics/Merge_Operator": "/docs/search/search-query-language/transaction-analytics/merge-operator",
40254037
"/Search/Search_Query_Language/Search_Operators/join": "/docs/search/search-query-language/search-operators/join",
40264038
"/Search/Search_Query_Language/Search_Operators/lookup": "/docs/search/search-query-language/search-operators/lookup",
40274039
"/Search/Search_Query_Language/Search_Operators/smooth": "/docs/search/search-query-language/search-operators/smooth",
40284040
"/Search/Search_Query_Language/Search_Operators/toLowerCase_and_toUpperCase": "/docs/search/search-query-language/search-operators/tolowercase-touppercase",
4041+
"/Search/Search_Query_Language/Search_Operators/timeslice": "/docs/search/search-query-language/search-operators/timeslice",
40294042
"/Search/Search-Cheat-Sheets/General-Search-Examples-Cheat-Sheet": "/docs/search/search-cheat-sheets/general-search-examples",
40304043
"/Search/Search-Cheat-Sheets/Log-Operators-Cheat-Sheet": "/docs/search/search-cheat-sheets/log-operators",
40314044
"/Search/Search-Query-Language/01-Parse-Operators": "/docs/search/search-query-language/parse-operators",
@@ -4036,6 +4049,7 @@
40364049
"/Search/Search-Query-Language/01-Parse-Operators/07-Parse-XML-Formatted-Logs": "/docs/search/search-query-language/parse-operators/parse-xml-formatted-logs",
40374050
"/Search/Search-Query-Language/aaGroup/count,-count-distinct,-and-count-frequent": "/docs/search/search-query-language/group-aggregate-operators/count-count-distinct-and-count-frequent",
40384051
"/Search/Search-Query-Language/aaGroup/fillmissing": "/docs/search/search-query-language/search-operators/fillmissing",
4052+
"/Search/Search-Query-Language/aaGroup/standard-deviation": "/docs/search/search-query-language/group-aggregate-operators/stddev",
40394053
"/Search/Search-Query-Language/aaGroup/sum": "/docs/search/search-query-language/group-aggregate-operators/sum",
40404054
"/Search/Search-Query-Language/Search-Operators": "/docs/search/search-query-language/search-operators",
40414055
"/Search/Search-Query-Language/Search-Operators/lookup": "/docs/search/search-query-language/search-operators/lookup",
@@ -4110,6 +4124,7 @@
41104124
"/Send-Data/Applications-and-Other-Data-Sources/AWS-Lambda": "/docs/integrations/amazon-aws/lambda",
41114125
"/Send-Data/Applications-and-Other-Data-Sources/AWS-CloudTrail/04-Set-Up-Admin-Access-for-CloudTrail": "/docs/integrations/amazon-aws/cloudtrail",
41124126
"/Send-Data/Applications-and-Other-Data-Sources/AWS-Elastic-Load-Balancing-ULM-Application/Collect-Logs-and-Metrics-for-AWS-Elastic-Load-Balancing-ULM-Application": "/docs/integrations/amazon-aws/classic-load-balancer",
4127+
"/Send-Data/Applications-and-Other-Data-Sources/AWS-Elastic-Load-Balancing-ULM-CLB/Collect-Logs-and-Metrics-for-AWS-Elastic-Load-Balancing-ULM-CLB": "/docs/integrations/amazon-aws/classic-load-balancer",
41134128
"/Send-Data/Applications-and-Other-Data-Sources/Azure_Active_Directory": "/docs/integrations/microsoft-azure/active-directory-azure",
41144129
"/Send-Data/Applications-and-Other-Data-Sources/Azure_Active_Directory/Collect_Logs_for_Azure_Active_Directory": "/docs/integrations/microsoft-azure/active-directory-azure",
41154130
"/Send-Data/Applications-and-Other-Data-Sources/Azure_Active_Directory/Install_the_Azure_Active_Directory_App_and_View_the_Dashboards": "/docs/integrations/microsoft-azure/active-directory-azure",

docs/cse/rules/about-cse-rules.md

Lines changed: 38 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -9,10 +9,6 @@ import useBaseUrl from '@docusaurus/useBaseUrl';
99
import Iframe from 'react-iframe'; 
1010

1111
A Cloud SIEM rule is logic that fires based on information in incoming records. When a rule fires, it creates a signal.
12-
13-
[**Classic UI**](/docs/get-started/sumo-logic-ui-classic). To view rules, in the top menu select **Content > Rules**.
14-
15-
[**New UI**](/docs/get-started/sumo-logic-ui). To view rules, in the main Sumo Logic menu select **Cloud SIEM > Rules**. You can also click the **Go To...** menu at the top of the screen and select **Rules**.
1612

1713
:::tip
1814
For a complete list of out-of-the-box rules, see [Rules](https://github.com/SumoLogic/cloud-siem-content-catalog/blob/master/rules/README.md) in the [Cloud SIEM Content Catalog](https://github.com/SumoLogic/cloud-siem-content-catalog/blob/master/README.md).
@@ -36,6 +32,44 @@ Watch this micro lesson to learn more about rules.
3632

3733
:::
3834

35+
## Rules list view
36+
37+
[**Classic UI**](/docs/get-started/sumo-logic-ui-classic). To view rules, in the top menu select **Content > Rules**.
38+
39+
[**New UI**](/docs/get-started/sumo-logic-ui). To view rules, in the main Sumo Logic menu select **Cloud SIEM > Rules**. You can also click the **Go To...** menu at the top of the screen and select **Rules**.
40+
41+
<img src={useBaseUrl('img/cse/rules-list-page.png')} alt="Rules list page" style={{border: '1px solid gray'}} width="800" />
42+
43+
| Letter | Description |
44+
|:--|:--|
45+
| a | **Rules count**. The total number of rules in the list. |
46+
| b | **Filters**. Filter the list of rules by different parameters, such as name, type, severity, and so on. |
47+
| c | **Sort**. Sort rules by name, enabled, severity, created, updated, or signal count updated the past 7 days or 24 hours.  |
48+
| d | **Updated**. When the rule was last updated. |
49+
| e | **Status - Type**. The [rule status](/docs/cse/rules/rules-status/) and [rule type](/docs/cse/rules/about-cse-rules/#rule-types)|
50+
| f | **Severity**. The rule's severity, an estimate of the criticality of the detected activity, from 1 (lowest) to 10 (highest). |
51+
| g | **Signals Fired**. The number of signals that the rule fired in the last 24 hours as well as 7 days. |
52+
| h | **Export as JSON**. Export the rule information as a JSON file. |
53+
| i | **Tags**. Metadata [tags](/docs/cse/records-signals-entities-insights/tags-insights-signals-entities-rules/) that add context for the rule. Click a tag to see rules with that tag. |
54+
55+
## Rules details view
56+
57+
When you click a rule on the **Rules** page, a details page for the rule appears.
58+
59+
<img src={useBaseUrl('img/cse/rule-details.png')} alt="Rules details page" style={{border: '1px solid gray'}} width="800" />
60+
61+
| Letter | Description |
62+
|:--|:--|
63+
| a | **Rule ID**. The ID for the rule. |
64+
| b | **Rule name**. The name of the rule. |
65+
| c | **Dates**. When the rule was created, updated, and fired its most recent signal.  |
66+
| d | [**Status**](/docs/cse/rules/rules-status/), [**Rule Type**](/docs/cse/rules/about-cse-rules/#rule-types), **Severity**, and number of [**Tuning Expressions**](#about-tuning-expressions). |
67+
| e | **Signal Suppression**. When [signal suppression](/docs/cse/records-signals-entities-insights/about-signal-suppression/) occurred. Click a square on the calendar to see the number of signals suppressed on that day. |
68+
| f | **Rule Editor**. Click in fields to edit the rule. For information about the fields, see articles for the [rule types](#rule-types)|
69+
| g | **Prototype Rule**. Select the checkbox to [save the rule a prototype](/docs/cse/rules/write-chain-rule/#save-as-prototype). |
70+
| h | **History**. Change events for the rule, including who made the change and the type of change event. |
71+
| i | **Insights**. The [insights](/docs/cse/get-started-with-cloud-siem/about-cse-insight-ui/) that resulted from the rule's firing. |
72+
3973
## About rule expressions
4074

4175
The key element of a Cloud SIEM rule is a *rule expression*. A rule expression defines what conditions the rule will look for. A rule expression includes one or more equality statements, each of which evaluates a field value in incoming records, typically comparing it to a constant value, for example `description = 'CMS Domain Match'`. A simple rule expression might be a single equality expression, or multiple expressions combined with logical operators. A rule expression evaluates to a boolean value. When a rule’s conditions are met, it creates a signal. 

0 commit comments

Comments
 (0)