Skip to content

Commit ca0024b

Browse files
authored
Merge branch 'main' into docs-1281-add-back-crowdstrike-threat-intel-info
2 parents 82043a8 + 816c0e4 commit ca0024b

File tree

9 files changed

+125
-12
lines changed

9 files changed

+125
-12
lines changed

blog-cse/2025-12-05-content.md

Lines changed: 96 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,96 @@
1+
---
2+
title: December 05, 2025 - Content Release
3+
image: https://assets-www.sumologic.com/company-logos/_800x418_crop_center-center_82_none/SumoLogic_Preview_600x600.jpg?mtime=1617040082
4+
keywords:
5+
- log mappers
6+
- parsers
7+
- rules
8+
hide_table_of_contents: true
9+
---
10+
11+
This new and updated content is effective as of December 4, 2025.
12+
13+
This content release includes:
14+
- Updates to product naming from "G Suite" to "Google Workspace" across rules, log mappers, and parsers to reflect the current branding.
15+
- Update to product naming from "Dell SonicWall" to "SonicWall Firewall" in parsers and log mappers.
16+
- New support for Asana audit logging.
17+
18+
Additional changes are enumerated below.
19+
20+
## Rules
21+
- [Updated] MATCH-S00630 GCP Audit IAM DeleteServiceAccount Observed
22+
- [Updated] MATCH-S00629 GCP Audit IAM DisableServiceAccount Observed
23+
- [Updated] MATCH-S00117 Google Workspace - Access - Access Transparency
24+
- [Updated] MATCH-S00115 Google Workspace - Admin - User Settings - Turn Off 2SV
25+
- [Updated] MATCH-S00133 Google Workspace - Admin Activity
26+
- [Updated] MATCH-S00125 Google Workspace - Drive - Drive Open To Public
27+
- [Updated] MATCH-S00301 Google Workspace - Excessive OAuth Application Permissions Scope
28+
- [Updated] MATCH-S00128 Google Workspace - Login - Account Warning
29+
- [Updated] MATCH-S00129 Google Workspace - Login - Government Attack Warning
30+
- [Updated] MATCH-S00121 Google Workspace - Mobile - Suspicious Activity
31+
- [Updated] MATCH-S00227 Google Workspace - Unauthorized OAuth Application
32+
- [Updated] MATCH-S00120 Google Workspace - User Accounts - 2SV Disabled
33+
34+
## Log Mappers
35+
- [New] Asana Audit Authentication
36+
- [New] Asana Audit Catch All
37+
- [Updated] Azure ResourceHealth and ServiceHealth
38+
- [Updated] AzureActivityLog AuditLogs
39+
- [Updated] Google Workspace - access_transparency/GSUITE_RESOURCE/ACCESS
40+
- [Updated] Google Workspace - admin
41+
- [Updated] Google Workspace - calendar
42+
- [Updated] Google Workspace - drive.access
43+
- [Updated] Google Workspace - drive.acl_change
44+
- [Updated] Google Workspace - gcp
45+
- [Updated] Google Workspace - gplus
46+
- [Updated] Google Workspace - groups
47+
- [Updated] Google Workspace - groups_enterprise
48+
- [Updated] Google Workspace - login - password_change/recovery_info_change
49+
- [Updated] Google Workspace - login - risky_sensitive_action_allowed
50+
- [Updated] Google Workspace - login challenge
51+
- [Updated] Google Workspace - login-blocked_sender_change
52+
- [Updated] Google Workspace - login-email_forwarding_change
53+
- [Updated] Google Workspace - login.account_warning
54+
- [Updated] Google Workspace - login.gov_attack_warning
55+
- [Updated] Google Workspace - login.login
56+
- [Updated] Google Workspace - logout
57+
- [Updated] Google Workspace - meet
58+
- [Updated] Google Workspace - mobile
59+
- [Updated] Google Workspace - rules
60+
- [Updated] Google Workspace - saml
61+
- [Updated] Google Workspace - token
62+
- [Updated] Google Workspace - user_accounts
63+
- [Updated] Google Workspace Alert Center - AppMaker Editor
64+
- [Updated] Google Workspace Alert Center - Data Loss Prevention
65+
- [Updated] Google Workspace Alert Center - Domain wide takeout
66+
- [Updated] Google Workspace Alert Center - Gmail phishing
67+
- [Updated] Google Workspace Alert Center - Gmail phishing (Misconfigured whitelist)
68+
- [Updated] Google Workspace Alert Center - Google Operations
69+
- [Updated] Google Workspace Alert Center - Google identity
70+
- [Updated] Google Workspace Alert Center - Mobile device management (Device compromised)
71+
- [Updated] Google Workspace Alert Center - Mobile device management (Suspicious activity)
72+
- [Updated] Google Workspace Alert Center - Security Center rules
73+
- [Updated] Google Workspace Alert Center - Sensitive Admin Action
74+
- [Updated] Google Workspace Alert Center - State Sponsored Attack
75+
- [Updated] Google Workspace Alert Center - User Changes
76+
- [Updated] Netskope - Alerts
77+
- Updated action and normalizedAction field mappings.
78+
- [Updated] SonicWall Firewall - Custom Parser
79+
- [Updated] SonicWall Flows
80+
- [Updated] Thinkst Canary Parser - Catch All
81+
- Added additional field mappings.
82+
- [Updated] Windows - Security - 5145
83+
- Removes redundant mapping of `baseimage` and `device_ip` fields.
84+
85+
## Parsers
86+
- [New] /Parsers/System/Asana/Asana Audit
87+
- [New] /Parsers/System/Google/Google Workspace Alert Center
88+
- [New] /Parsers/System/Google/Google Workspace Audit
89+
- [New] /Parsers/System/SonicWall/SonicWall Firewall
90+
- [Updated] /Parsers/System/Dell/Dell SonicWall
91+
- [Updated] /Parsers/System/Google/G Suite Alert Center
92+
- [Updated] /Parsers/System/Google/G Suite Audit
93+
- [Updated] /Parsers/System/Linux/Linux OS Syslog
94+
- Updated parser to drop certain systemd events not useful for security monitoring.
95+
- [Updated] /Parsers/System/Thinkst Canary/Thinkst Canary
96+
- Modified parser to improve field extraction.

docs/get-started/sumo-logic-ui-classic.md

Lines changed: 4 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -7,12 +7,14 @@ description: Get to know the Sumo Logic platform user interface.
77

88
import useBaseUrl from '@docusaurus/useBaseUrl';
99

10+
:::note
11+
This page describes the Classic UI. For the most streamlined navigation and the newest user experience, switch to the [New UI](/docs/get-started/sumo-logic-ui).
12+
:::
13+
1014
This page provides an overview of the Sumo Logic Classic UI, designed to help you navigate and utilize its features effectively.
1115

1216
<img src={useBaseUrl('img/get-started/overview-classic-ui.png')} alt="Overview screenshot of the Classic UI" style={{border: '1px solid gray'}} width="800" />
1317

14-
The Classic UI will be retired in 2025 and will no longer receive updates. The exact date will be communicated closer to the transition. For the latest features, performance improvements, and future innovations, switch to the [New UI](/docs/get-started/sumo-logic-ui) as soon as possible.
15-
1618
## Switching between the Classic and New UI
1719

1820
If you're using the New UI and need to navigate back to the Classic UI, click the **Return to classic UI** option in the left navigation menu. And to switch back to the New UI, follow the same steps, selecting **Switch to New UI** instead.

docs/search/search-query-language/search-operators/macro.md

Lines changed: 22 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -39,18 +39,18 @@ To create a macro, follow the steps below:
3939
1. [**New UI**](/docs/get-started/sumo-logic-ui/). In the main Sumo Logic menu, select **Data Management**, and then under **Logs**, select **Macros**. You can also click the **Go To...** menu at the top of the screen and select **Macros**.<br/>[**Classic UI**](/docs/get-started/sumo-logic-ui-classic). In the main Sumo Logic menu, select **Manage Data** > **Logs** > **Macros**.
4040
1. Click **+ Add Macro**.<br/><img src={useBaseUrl('img/search/searchquerylanguage/search-operators/macro-logs-page.png')} alt="macro-logs-page" style={{border: '1px solid gray'}} width="800" />
4141
1. Or, in the log search page, select the part of search query language that needs to be reused and click on **Create Macro**.<br/><img src={useBaseUrl('img/search/searchquerylanguage/search-operators/macro-search-page.png')} alt="macro-search-page" style={{border: '1px solid gray'}} width="800" />
42-
1. **Macro Details**. Enter the name for the macro. Description is optional.
43-
1. **Macro Definition**. Enter the definition for the macro. To add arguments use the `{{Arg}}` syntax or select a part of the definition and click on **Add Argument**.
44-
1. (Optional) **Arguments**. Enter the name and select the data type for the argument selected.
45-
1. (Optional) **Argument Validation**. Define the validation condition and enter the error message that needs to be shown when the validation expression returns false.
46-
1. **Usage**. Preview of how you use the macro in the log search.
47-
1. Click **Submit** to save the macro.
42+
1. In the **Create Macro** page, enter the following details: <br/><img src={useBaseUrl('img/search/searchquerylanguage/search-operators/create-macro.png')} alt="create-macro" style={{border: '1px solid gray'}} width="800" />
43+
1. **Macro Details**. Enter the name for the macro. Description is optional.
44+
1. **Macro Definition**. Enter the definition for the macro. To add arguments use the `{{Arg}}` syntax or select a part of the definition and click on **Add Argument**.
45+
1. (Optional) **Arguments**. Enter the name and select the data type for the argument selected.
46+
1. (Optional) **Argument Validation**. Define the validation condition and enter the error message that needs to be shown when the validation expression returns false.
47+
1. **Usage**. Preview of how you use the macro in the log search.
48+
1. Click **Submit** to save the macro.
4849

4950
### Limitations
5051

5152
- You can create a maximum of 50 macros.
5253
- You can add a maximum of 5 arguments.
53-
- You cannot edit or delete the macro. Submit a customer request to Sumo Logic if you still need to edit or delete a macro.
5454
- You are only allowed to use single expression.
5555
- You can only use the below listed argument validations:
5656
- `isValidIpV4`
@@ -110,3 +110,18 @@ To view any existing macro, follow the steps below:
110110
1. [**New UI**](/docs/get-started/sumo-logic-ui/). In the main Sumo Logic menu, select **Data Managemenu**, and then under **Logs**, select **Macros**. You can also click the **Go To...** menu at the top of the screen and select **Macros**.<br/>[**Classic UI**](/docs/get-started/sumo-logic-ui-classic). In the main Sumo Logic menu, select **Manage Data** > **Logs** > **Macros**.
111111
1. In the **Macros** page, click on any of the macros that you want to view the macro details.<br/><img src={useBaseUrl('img/search/searchquerylanguage/search-operators/view-macro-logs-page.png')} alt="macro-logs-page" style={{border: '1px solid gray'}} width="800" />
112112
1. To use the selected macro in your log search query, copy the suggested **Usage** of the macro and include it in your query syntax. <br/><img src={useBaseUrl('img/search/searchquerylanguage/search-operators/view-macro-logs-details.png')} alt="view-macro-logs-details" style={{border: '1px solid gray'}} width="400" />
113+
114+
## Edit a macro operator
115+
116+
1. [**New UI**](/docs/get-started/sumo-logic-ui/). In the main Sumo Logic menu, select **Data Management**, and then under **Logs**, select **Macros**. You can also click the **Go To...** menu at the top of the screen and select **Macros**.<br/>[**Classic UI**](/docs/get-started/sumo-logic-ui-classic). In the main Sumo Logic menu, select **Manage Data** > **Logs** > **Macros**.
117+
1. In the **Macros** page, click on any of the macros that you want to edit.<br/><img src={useBaseUrl('img/search/searchquerylanguage/search-operators/view-macro-logs-page.png')} alt="macro-logs-page" style={{border: '1px solid gray'}} width="800" />
118+
1. Click **Edit** button to open the pane for editing. <br/><img src={useBaseUrl('img/search/searchquerylanguage/search-operators/macro-edit-button.png')} alt="macro-delete-pop-up" style={{border: '1px solid gray'}} width="400" />
119+
1. In the **Edit [macroname] macro** pop-up, click on **Continue**. You can also check where your macros have been used to avoid broken queries by clicking on **check queries that reference this macro**. <br/><img src={useBaseUrl('img/search/searchquerylanguage/search-operators/macro-edit-pop-up.png')} alt="macro-delete-pop-up" style={{border: '1px solid gray'}} width="400" />
120+
1. In the macro editing pane, perform the required editing and click **Submit**.
121+
122+
## Delete a macro operator
123+
124+
1. [**New UI**](/docs/get-started/sumo-logic-ui/). In the main Sumo Logic menu, select **Data Management**, and then under **Logs**, select **Macros**. You can also click the **Go To...** menu at the top of the screen and select **Macros**.<br/>[**Classic UI**](/docs/get-started/sumo-logic-ui-classic). In the main Sumo Logic menu, select **Manage Data** > **Logs** > **Macros**.
125+
1. In the **Macros** page, click on any of the macros that you want to delete.<br/><img src={useBaseUrl('img/search/searchquerylanguage/search-operators/view-macro-logs-page.png')} alt="macro-logs-page" style={{border: '1px solid gray'}} width="800" />
126+
1. Click **Delete** button to delete the macro. <br/><img src={useBaseUrl('img/search/searchquerylanguage/search-operators/macro-delete-button.png')} alt="macro-delete-button" style={{border: '1px solid gray'}} width="400" />
127+
1. In the **Delete [macroname] macro** pop-up, click on **Delete**. You can also check where your macros have been used to avoid broken queries by clicking on **check queries that reference this macro**. <br/><img src={useBaseUrl('img/search/searchquerylanguage/search-operators/macro-delete-pop-up.png')} alt="macro-delete-pop-up" style={{border: '1px solid gray'}} width="400" />
212 KB
Loading
71.2 KB
Loading
43.9 KB
Loading
71.7 KB
Loading
36.5 KB
Loading

yarn.lock

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -9748,9 +9748,9 @@ mdast-util-phrasing@^4.0.0:
97489748
unist-util-is "^6.0.0"
97499749

97509750
mdast-util-to-hast@^13.0.0:
9751-
version "13.2.0"
9752-
resolved "https://registry.yarnpkg.com/mdast-util-to-hast/-/mdast-util-to-hast-13.2.0.tgz#5ca58e5b921cc0a3ded1bc02eed79a4fe4fe41f4"
9753-
integrity sha512-QGYKEuUsYT9ykKBCMOEDLsU5JRObWQusAolFMeko/tYPufNkRffBAQjIE+99jbA87xv6FgmjLtwjh9wBWajwAA==
9751+
version "13.2.1"
9752+
resolved "https://registry.yarnpkg.com/mdast-util-to-hast/-/mdast-util-to-hast-13.2.1.tgz#d7ff84ca499a57e2c060ae67548ad950e689a053"
9753+
integrity sha512-cctsq2wp5vTsLIcaymblUriiTcZd0CwWtCbLvrOzYCDZoWyMNV8sZ7krj09FSnsiJi3WVsHLM4k6Dq/yaPyCXA==
97549754
dependencies:
97559755
"@types/hast" "^3.0.0"
97569756
"@types/mdast" "^4.0.0"

0 commit comments

Comments
 (0)