Skip to content

Commit d2fec5a

Browse files
committed
Merge branch 'main' into DOCS-467
2 parents 233649e + 5b87931 commit d2fec5a

File tree

50 files changed

+974
-301
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

50 files changed

+974
-301
lines changed

.clabot

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -170,7 +170,9 @@
170170
"ishaanahuja29",
171171
"raunakmandaokar",
172172
"bradtho",
173-
"Misterjohnson87"
173+
"Misterjohnson87",
174+
"lol3909",
175+
"Hellfire4959"
174176
],
175177
"message": "Thank you for your contribution! As this is an open source project, we require contributors to sign our Contributor License Agreement and do not have yours on file. To proceed with your PR, please [sign your name here](https://forms.gle/YgLddrckeJaCdZYA6) and we'll add you to our approved list of contributors.",
176178
"label": "cla-signed",

blog-service/2023/12-31.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -106,7 +106,7 @@ To learn more, see [Updating Your AWS Observability Stack](/docs/observability/a
106106

107107
We're excited to announce that you can use roles to restrict access to specific data in search indexes. When you create a role, you can select **Index based** filters to allow access to data based on indexes, or you can select **Advanced filter** to define a dataset to allow access based on search criteria. This ensures that users only see the data they are supposed to.
108108

109-
[Learn more](/docs/manage/users-roles/roles/rbac-for-indexes).
109+
[Learn more](/docs/manage/users-roles/roles/create-manage-roles/).
110110

111111
:::note
112112
This feature is in Beta. To participate, contact your Sumo Logic account executive or our Support Team.
Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,14 @@
1+
---
2+
title: Automox C2C Source (Collection)
3+
image: https://help.sumologic.com/img/sumo-square.png
4+
keywords:
5+
- collection
6+
- automox
7+
hide_table_of_contents: true
8+
---
9+
10+
import useBaseUrl from '@docusaurus/useBaseUrl';
11+
12+
<a href="https://help.sumologic.com/release-notes-service/rss.xml"><img src={useBaseUrl('img/release-notes/rss-orange2.png')} alt="icon" width="50"/></a>
13+
14+
We're excited to announce the release of our new cloud-to-cloud source for Automox. This source helps you to collect all events objects, audit trail events, and device inventory details from the Automox platform, and ingest them into Sumo Logic for streamlined analysis. [Learn more](/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/automox-source).

blog-service/2024-10-14-manage.md

Lines changed: 23 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,23 @@
1+
---
2+
title: Role Based Index Access (Manage)
3+
image: https://www.sumologic.com/img/logo.svg
4+
keywords:
5+
- rbac
6+
- index
7+
- roles
8+
hide_table_of_contents: true
9+
---
10+
11+
import useBaseUrl from '@docusaurus/useBaseUrl';
12+
13+
<a href="https://help.sumologic.com/release-notes-service/rss.xml"><img src={useBaseUrl('img/release-notes/rss-orange2.png')} alt="icon" width="50"/></a>
14+
15+
We're excited to announce that when you create a role, you can select **Index Access** to restrict access to data in specific indexes. In addition, when you now select **Search Filter**, you can create filtering to restrict access to log analytics, audit, and security data. These enhancements ensure that users only see the data they are supposed to.
16+
17+
This feature was [previously only available to participants in our beta program](/release-notes-service/2023/12/31/#october-27-2023-manage-account). It is now available for general use.
18+
19+
:::note
20+
These changes are rolling out across deployments incrementally and will be available on all deployments by October 25, 2024.
21+
:::
22+
23+
[Learn more](/docs/manage/users-roles/roles/create-manage-roles/#create-a-role).
Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,14 @@
1+
---
2+
title: Kandji C2C Source (Collection)
3+
image: https://help.sumologic.com/img/sumo-square.png
4+
keywords:
5+
- collection
6+
- kandji
7+
hide_table_of_contents: true
8+
---
9+
10+
import useBaseUrl from '@docusaurus/useBaseUrl';
11+
12+
<a href="https://help.sumologic.com/release-notes-service/rss.xml"><img src={useBaseUrl('img/release-notes/rss-orange2.png')} alt="icon" width="50"/></a>
13+
14+
We're excited to announce the release of our new cloud-to-cloud source for Kandji. This source helps you to collect threat details, device lists, activity logs, and device information from the Kandji platform, and ingest them into Sumo Logic for streamlined analysis. [Learn more](/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/kandji-source).

cid-redirects.json

Lines changed: 8 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -2616,6 +2616,8 @@
26162616
"/cid/19878": "/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/airtable-source",
26172617
"/cid/19879": "/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/knowbe4-api-source",
26182618
"/cid/16323": "/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/druva-source",
2619+
"/cid/13428": "/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/kandji-source",
2620+
"/cid/17343": "/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/automox-source",
26192621
"/cid/20172": "/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/cisco-vulnerability-management-source",
26202622
"/cid/19880": "/docs/metrics/metrics-operators/predict",
26212623
"/cid/19881": "/docs/metrics/metrics-operators/accum",
@@ -2725,7 +2727,7 @@
27252727
"/cid/21037": "/docs/integrations/google/cloud-vpn",
27262728
"/cid/21038": "/docs/integrations/containers-orchestration/vmware-tanzu-application-service",
27272729
"/cid/10999": "/docs/send-data/collect-from-other-data-sources/azure-monitoring/ms-azure-event-hubs-source",
2728-
"/cid/11000": "/docs/alerts/monitors/automation-payload-variables",
2730+
"/cid/11000": "/docs/platform-services/automation-service/automation-service-playbooks",
27292731
"/Cloud_SIEM_Enterprise": "/docs/cse",
27302732
"/Cloud_SIEM_Enterprise/Administration": "/docs/cse/administration",
27312733
"/Cloud_SIEM_Enterprise/Administration/Cloud_SIEM_Enterprise_Feature_Update_(2022)": "/docs/cse/administration",
@@ -3410,6 +3412,7 @@
34103412
"/Visualizations-and-Alerts/Alerts/02-Schedule-a-Search": "/docs/alerts/scheduled-searches",
34113413
"/Visualizations-and-Alerts/Alerts/Alert_Grouping": "/docs/alerts/monitors/alert-grouping",
34123414
"/Visualizations-and-Alerts/Alerts/Alert_Variables": "/docs/alerts/monitors/alert-variables",
3415+
"/docs/alerts/monitors/automation-payload-variables": "/docs/platform-services/automation-service/automation-service-playbooks",
34133416
"/Visualizations-and-Alerts/Alerts/Monitors": "/docs/alerts/monitors",
34143417
"/Visualizations-and-Alerts/Alerts/Monitors/About_Monitors": "/docs/alerts/monitors/overview",
34153418
"/Visualizations-and-Alerts/Alerts/Monitors/Monitor_FAQ": "/docs/alerts/monitors/monitor-faq",
@@ -3638,7 +3641,7 @@
36383641
"/Beta/Cloud-to-Cloud_Integration_Framework/Workday_Source": "/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/workday-source",
36393642
"/Beta/Dashboard-Data-API": "/docs/api/dashboard",
36403643
"/Beta/Dashboard_(New)": "/docs/dashboards",
3641-
"/Beta/Grant_Access_to_Data_in_Audit_Indexes": "/docs/manage/security/audit-indexes/audit-index-access",
3644+
"/Beta/Grant_Access_to_Data_in_Audit_Indexes": "/docs/manage/users-roles/roles/create-manage-roles",
36423645
"/Beta/Health_Events": "/docs/manage/health-events",
36433646
"/Beta/Ingest_Budgets": "/docs/manage/ingestion-volume/ingest-budgets",
36443647
"/docs/manage/ingestion-volume/ingest-budgets/assign-collector-ingest-budget": "/docs/manage/ingestion-volume/ingest-budgets/daily-volume/assign-collector-ingest-budget",
@@ -3993,7 +3996,9 @@
39933996
"/docs/manage/security/audit-index": "/docs/manage/security/audit-indexes/audit-index",
39943997
"/docs/manage/security/audit-event-index": "/docs/manage/security/audit-indexes/audit-event-index",
39953998
"/docs/manage/security/search-audit-index": "/docs/manage/security/audit-indexes/search-audit-index",
3996-
"/docs/manage/security/audit-index-access": "/docs/manage/security/audit-indexes/audit-index-access",
3999+
"/docs/manage/security/audit-index-access": "/docs/manage/users-roles/roles/create-manage-roles",
4000+
"/docs/manage/security/audit-indexes/audit-index-access/": "/docs/manage/users-roles/roles/create-manage-roles",
4001+
"/docs/manage/users-roles/roles/rbac-for-indexes": "/docs/manage/users-roles/roles/create-manage-roles",
39974002
"/cid/-1": "/",
39984003
"/docs/api/beta": "/docs/api",
39994004
"/docs/api/dashboard-data": "/docs/api/dashboard",

docs/alerts/monitors/automation-payload-variables.md

Lines changed: 0 additions & 132 deletions
This file was deleted.

docs/alerts/monitors/index.md

Lines changed: 0 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -78,10 +78,4 @@ In this section, we'll introduce the following concepts:
7878
<p>Learn how to use Automation Service playbooks with monitors.</p>
7979
</div>
8080
</div>
81-
<div className="box smallbox card">
82-
<div className="container">
83-
<a href="/docs/alerts/monitors/automation-payload-variables"><img src={useBaseUrl('img/icons/operations/monitor-and-visualize.png')} alt="icon" width="40"/><h4>Automation Payload Variables</h4></a>
84-
<p>Learn details about variables passed from a monitor to a playbook in the Automation Service.</p>
85-
</div>
86-
</div>
8781
</div>

docs/alerts/monitors/use-playbooks-with-monitors.md

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -155,7 +155,7 @@ Some integrations that have useful actions for monitors include:
155155

156156
### Pass custom fields from a monitor to playbooks
157157

158-
Results from an alert query are passed to a playbook through the [automation payload](/docs/alerts/monitors/automation-payload-variables/). The variables from the payload can be used as inputs for different nodes in the playbook after they are defined as parameters in the start node.
158+
Results from an alert query are passed to a playbook through the [alert payload](/docs/platform-services/automation-service/automation-service-playbooks/#alert-payload). The variables from the payload can be used as inputs for different nodes in the playbook after they are defined as parameters in the start node.
159159

160160
:::note
161161
You must use [alert grouping](/docs/alerts/monitors/alert-grouping/) in the monitor configuration to pass fields from the query to the playbook.
@@ -165,12 +165,12 @@ You must use [alert grouping](/docs/alerts/monitors/alert-grouping/) in the moni
165165

166166
1. Click **Edit** on the Start Node.
167167
1. Select **Alert** from the dropdown. <br/><img src={useBaseUrl('img/alerts/parse_from_alert.png')} alt="Payload parameters from an alert" style={{border: '1px solid gray'}} width="700" />
168-
1. The parameters from the default [automation payload variables](/docs/alerts/monitors/automation-payload-variables/) will be defined, along with some placeholders for custom fields that may be passed from the alert query. To reference a field passed from the alert query, use `customPlaceholderMap[].FIELDNAME`.
168+
1. The parameters from the default [alert payload variables](/docs/platform-services/automation-service/automation-service-playbooks/#alert-payload) will be defined, along with some placeholders for custom fields that may be passed from the alert query. To reference a field passed from the alert query, use `customPlaceholderMap[].FIELDNAME`.
169169

170-
#### Configure Parameters from a JSON Payload
170+
#### Configure parameters from a JSON payload
171171

172172
1. Click **Edit** on the Start Node.
173173
1. Select **Parse from Json** from the dropdown. <br/><img src={useBaseUrl('img/alerts/parse_from_json.png')} alt="Payload parameters from a Json payload" style={{border: '1px solid gray'}} width="700" />
174-
1. Copy the payload from a previously triggered automation. You can view the playbook payload of a previously triggered alert by following the steps [here](/docs/alerts/monitors/automation-payload-variables/#view-playbook-payload).
174+
1. Copy the payload from a previously triggered automation. You can view the playbook payload of a previously triggered alert by following the steps [here](/docs/platform-services/automation-service/automation-service-playbooks/#alert-payload).
175175
1. Paste the payload into the **Enter Json payload** text box and click **Parse**. The fields from the payload will be auto parsed to parameters. <br/><img src={useBaseUrl('img/alerts/parse_from_json_payload.png')} alt="Parse from Json payload" style={{border: '1px solid gray'}} width="700" />
176176
1. Add or remove parameters based on the playbook requirements and click **Update**. <br/><img src={useBaseUrl('img/alerts/parse_from_json_parameters.png')} alt="Json Payload parameters" style={{border: '1px solid gray'}} width="700" />

0 commit comments

Comments
 (0)