Skip to content

Commit e67dde7

Browse files
authored
Merge branch 'main' into Ddecember-Release-(apps)
2 parents 7fa4c1a + 9067fe4 commit e67dde7

File tree

89 files changed

+1535
-394
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

89 files changed

+1535
-394
lines changed

blog-cse/2024-12-20-content.md

Lines changed: 58 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,58 @@
1+
---
2+
title: December 20, 2024 - Content Release
3+
hide_table_of_contents: true
4+
keywords:
5+
- log mappers
6+
- log parsers
7+
- detection rules
8+
image: https://help.sumologic.com/img/sumo-square.png
9+
---
10+
11+
import useBaseUrl from '@docusaurus/useBaseUrl';
12+
13+
<a href="https://help.sumologic.com/release-notes-cse/rss.xml"><img src={useBaseUrl('img/release-notes/rss-orange2.png')} alt="icon" width="50"/></a>
14+
15+
This content release includes:
16+
- New product support for Dragos WorldView Threat Intelligence, Mindpoint Proactive Security Services, and Trust IAM (Identity and Access Management).
17+
- AWS Cloudtrail updates.
18+
- Adds alternate mapping for `user_userId` in anticipation of AWS Identity Center CloudTrail logging change. For more information on the change, see [Important changes to CloudTrail events for AWS IAM Identity Center](https://aws.amazon.com/blogs/security/modifications-to-aws-cloudtrail-event-data-of-iam-identity-center/).
19+
- Parsing and mapping updates for Palo Alto Firewall and Cisco Firepower.
20+
- Rule updates.
21+
22+
Changes are are enumerated below.
23+
24+
## Rules
25+
- [Deleted] FIRST-S00029 First Seen Successful Authentication From Unexpected Country
26+
- Rule has been replaced by FIRST-S00065 as this version was not enabled by default.
27+
- [Updated] FIRST-S00046 First Seen Client Generating MailIItemsAccessed Event from User
28+
- Updated "First Seen" value from ClientInfoString to Client to reduce false positives.
29+
- [Updated] FIRST-S00065 First Seen Successful Authentication From Unexpected Country
30+
- Replaces FIRST-S00029.
31+
32+
## Log Mappers
33+
- [New] Dragos Catch All
34+
- [New] Mindpoint Group Keeper Authentication
35+
- [New] Mindpoint Group Keeper Catch All
36+
- [New] Trust Login Authentication
37+
- [New] Trust Login Catch All
38+
- [Updated] CloudTrail - application-insights.amazonaws.com - ListApplications
39+
- [Updated] CloudTrail - signin.amazonaws.com - All AwsConsoleSignIn events
40+
- [Updated] CloudTrail - sso.amazonaws.com - Federate|ListProfilesForApplication
41+
- [Updated] CloudTrail Default Mapping
42+
- [Updated] Firepower Catch All
43+
- Additional new field mappings to support Firepower events and improve records classification.
44+
- [Updated] Palo Alto Config - Custom Parser
45+
- Adds alternate field mappings.
46+
- [Updated] Palo Alto System - Custom Parser
47+
- Adds alternate field mappings.
48+
- [Updated] Palo Alto System Auth - Custom Parser
49+
- Support additional panorama-auth-success and alternate fields for mapped fields.
50+
51+
## Parsers
52+
- [New] /Parsers/System/Dragos/Dragos
53+
- [New] /Parsers/System/Mindpoint Group/Mindpoint Group Keeper
54+
- [New] /Parsers/System/Trust Login/Trust Login
55+
- [Updated] /Parsers/System/Cisco/Cisco Firepower Syslog
56+
- Adds support for FTD 430002 and 430003 events.
57+
- [Updated] /Parsers/System/Palo Alto/PAN Firewall LEEF
58+
- Adds support for 'panorama-auth-success' events and improves timestamp handling.

cid-redirects.json

Lines changed: 10 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -82,6 +82,7 @@
8282
"/Start_Here/About_Sumo_Logic/Status_and_Scheduled_Maintenance": "/docs/get-started/help",
8383
"/Start_Here/About_Sumo_Logic/Sumo_Logic_Support_Terms_and_Conditions": "/docs/get-started/support-terms",
8484
"/Start_Here/Analyst_or_Administrator": "/docs/get-started/onboarding-checklists",
85+
"/Start_Here/Customize_Your_Sumo_Logic_Experience": "/docs/get-started",
8586
"/Start_Here/Getting_Started": "/docs/get-started",
8687
"/Start_Here/Getting_Started/Analyst_or_Administrator": "/docs/get-started/onboarding-checklists",
8788
"/Start-Here/09Customize-Your-Sumo-Logic-Experience/Preferences-Page": "/docs/get-started/account-settings-preferences",
@@ -296,6 +297,7 @@
296297
"/03Send-Data/Sources/02Sources-for-Hosted-Collectors/Cloud-to-Cloud_Integration_Framework/Google_Workspace_Source": "/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/google-workspace-source",
297298
"/03Send-Data/Sources/02Sources-for-Hosted-Collectors/Google": "/docs/send-data/hosted-collectors/google-source",
298299
"/03Send-Data/Sources/02Sources-for-Hosted-Collectors/Google-Cloud-Platform-Source": "/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/google-workspace-source",
300+
"/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/config-based-source": "/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/universal-connector-source",
299301
"/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/gmail-bigquery": "/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/gmail-tracelogs-source",
300302
"/03Send-Data/Sources/02Sources-for-Hosted-Collectors/Cloud-to-Cloud_Integration_Framework/Microsoft_Azure_AD_Inventory_Source": "/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/microsoft-graph-azure-ad-reporting-source",
301303
"/03Send-Data/Sources/02Sources-for-Hosted-Collectors/Cloud-to-Cloud_Integration_Framework/Microsoft_Graph_Security_API_Source": "/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/microsoft-graph-security-api-source",
@@ -2967,7 +2969,9 @@
29672969
"/Internal_Writers/Topic_Archive/Parse_by_Data_Type/Parse_Apache_Logs/Parse_Apache_Access_Logs": "/docs/search/get-started-with-search/suggested-searches/apache-access-parser",
29682970
"/Internal_Writers/Topic_Archive/Parse_by_Data_Type/Parse_Apache_Logs/Parse_Apache_Error_Logs": "/docs/search/get-started-with-search/suggested-searches/apache-errors-parser",
29692971
"/Internal_Writers/Topic_Archive/Parse_by_Data_Type/Parse_Cisco_ASA_Logs": "/",
2972+
"/Knowledge_Base/Apps": "/docs/integrations",
29702973
"/Knowledge_Base/Search/How_to_Prevent_your_Scheduled_Search_from_Timing_Out": "/docs/alerts/scheduled-searches/faq",
2974+
"/Limited_Availability/Lookup_Tables/lookupContains_Operator": "/docs/search/search-query-language/search-operators/lookupcontains",
29712975
"/Manage": "/docs/manage",
29722976
"/Manage/01Manage_Subscription": "/docs/manage/manage-subscription",
29732977
"/Manage/01Manage_Subscription/00Cloud_Flex_Credits_Accounts": "/docs/manage/manage-subscription/upgrade-sumo-logic-credits-account",
@@ -3351,11 +3355,13 @@
33513355
"/Observability_Solution/AWS_Observability_Solution/AWS_Observability_Apps/AWS_API_Gateway/AWS_API_Gateway_Dashboards": "/docs/observability/aws/integrations/aws-api-gateway",
33523356
"/Observability_Solution/AWS_Observability_Solution/AWS_Observability_Apps/AWS_Application_Load_Balancer": "/docs/observability/aws/integrations/aws-application-load-balancer",
33533357
"/Observability_Solution/AWS_Observability_Solution/AWS_Observability_Apps/AWS_Application_Load_Balancer/AWS_Application_Load_Balancer_Dashboards": "/docs/observability/aws/integrations/aws-application-load-balancer",
3358+
"/Observability_Solution/AWS_Observability_Solution/AWS_Observability_Apps/AWS_Observability_DynamoDB/View_the_AWS_Observability_DynamoDB_Dashboards": "/docs/observability/aws/integrations/aws-dynamodb",
33543359
"/Observability_Solution/AWS_Observability_Solution/AWS_Observability_Apps/AWS_DynamoDB": "/docs/observability/aws/integrations/aws-dynamodb",
33553360
"/Observability_Solution/AWS_Observability_Solution/AWS_Observability_Apps/AWS_DynamoDB/AWS_DynamoDB_Dashboards": "/docs/observability/aws/integrations/aws-dynamodb",
33563361
"/Observability_Solution/AWS_Observability_Solution/AWS_Observability_Apps/AWS_EC2": "/docs/observability/aws/integrations/aws-ec2-host-metrics",
33573362
"/Observability_Solution/AWS_Observability_Solution/AWS_Observability_Apps/AWS_EC2_Metrics/AWS_EC2_Metrics_Dashboards": "/docs/observability/aws/integrations/aws-ec2-host-metrics",
33583363
"/Observability_Solution/AWS_Observability_Solution/AWS_Observability_Apps/AWS_EC2/AWS_EC2_Dashboards": "/docs/observability/aws/integrations/aws-ec2-host-metrics",
3364+
"/Observability_Solution/AWS_Observability_Solution/AWS_Observability_EC2_Metrics": "/docs/observability/aws/integrations/aws-ec2-metrics",
33593365
"/Observability_Solution/AWS_Observability_Solution/AWS_Observability_Apps/AWS_EC2_Metrics": "/docs/observability/aws/integrations/aws-ec2-metrics",
33603366
"/Observability_Solution/AWS_Observability_Solution/AWS_Observability_Apps/AWS_Lambda": "/docs/observability/aws/integrations/aws-lambda",
33613367
"/Observability_Solution/AWS_Observability_Solution/AWS_Observability_Apps/AWS_Lambda/AWS_Lambda_Dashboards": "/docs/observability/aws/integrations/aws-lambda",
@@ -3850,6 +3856,7 @@
38503856
"/Search/Search-Query-Language/Aggregate-Functions/stats-count": "/docs/search/search-query-language/group-aggregate-operators/count-count-distinct-and-count-frequent",
38513857
"/Search/Search-Query-Language/Search-Operators/save": "/docs/search/search-query-language/search-operators/save",
38523858
"/Search/Search-Query-Language/Search-Operators/where": "/docs/search/search-query-language/search-operators/where",
3859+
"/Send_Data/Collect_from_Other_Data_Sources": "/docs/send-data/collect-from-other-data-sources",
38533860
"/Send_Data/Collect_from_Other_Data_Sources/Amazon_CloudWatch_Logs": "/docs/send-data/collect-from-other-data-sources/amazon-cloudwatch-logs",
38543861
"/Send_Data/Data_Types/016Amazon_S3_Audit_App": "/docs/integrations/amazon-aws/s3-audit",
38553862
"/Send_Data/Data_Types/Akamai_Cloud_Monitor/01_Collect_Logs_for_Akamai_Cloud_Monitor_App": "/docs/integrations/saas-cloud/akamai-cloud-monitor",
@@ -3874,6 +3881,7 @@
38743881
"/Send_Data/Installed_Collectors/05Reference_Information_for_Collector_Installation/04Add_a_Collector_to_a_Linux_Machine_Image": "/docs/send-data/installed-collectors/collector-installation-reference/add-collector-linux-machine-image",
38753882
"/Send_Data/Installed_Collectors/05Reference_Information_for_Collector_Installation/02Download_a_Collector_from_a_Static_URL": "/docs/send-data/installed-collectors/collector-installation-reference/download-collector-from-static-url",
38763883
"/Send_Data/Installed_Collectors/05Reference_Information_for_Collector_Installation/Advanced_UI_Installer_Settings": "/docs/send-data/installed-collectors/collector-installation-reference/advanced-ui-installer-settings",
3884+
"/Send_Data/Installed_Collectors/Configure_Limits_for_Collector_Caching": "/docs/send-data/installed-collectors/configuration",
38773885
"/Send_Data/Installed_Collectors/Supporting_Information_for_Collector_Installation/Set_a_Collector_as_Ephemeral": "/docs/send-data/installed-collectors/collector-installation-reference/set-collector-as-ephemeral",
38783886
"/Send_Data/Sources/02Sources_for_Hosted_Collectors/AWS_S3_Source": "/docs/send-data/hosted-collectors/amazon-aws/aws-s3-source",
38793887
"/Send_Data/Sources/02Sources_for_Hosted_Collectors/AWS_IP_Address_Range": "/docs/send-data/hosted-collectors/amazon-aws",
@@ -3910,6 +3918,7 @@
39103918
"/Send-Data/Applications-and-Other-Data-Sources/Azure_SQL/Collect_Logs_and_Metrics_for_Azure_SQL": "/docs/integrations/microsoft-azure/sql",
39113919
"/Send-Data/Applications-and-Other-Data-Sources/Azure_SQL/Install_the_Azure_SQL_App_and_View_the_Dashboards": "/docs/integrations/microsoft-azure/sql",
39123920
"/Send-Data/Applications-and-Other-Data-Sources/Cylance/Cylance-App-Dashboard": "/docs/integrations/security-threat-detection/cylance",
3921+
"/Send-Data/Applications-and-Other-Data-Sources/DynamoDB/Install-the-DynamoDB-App-and-view-the-Dashboards": "/docs/integrations/amazon-aws/dynamodb",
39133922
"/Send-Data/Applications-and-Other-Data-Sources/Fastly": "/docs/integrations/saas-cloud/fastly",
39143923
"/Send-Data/Applications-and-Other-Data-Sources/Fastly/01Collect-Logs-for-Fastly": "/docs/integrations/saas-cloud/fastly",
39153924
"/Send-Data/Applications-and-Other-Data-Sources/Fastly/03Fastly-App-Dashboards": "/docs/integrations/saas-cloud/fastly",
@@ -4080,7 +4089,7 @@
40804089
"/docs/cse/records-signals-entities-insights/insight-generation-process": "/docs/cse/get-started-with-cloud-siem/insight-generation-process",
40814090
"/docs/cse/get-started-with-cloud-siem/introduction-to-cloud-siem": "/docs/cse/get-started-with-cloud-siem",
40824091
"/docs/cse/cloud-siem-content-catalog": "/docs/cse/get-started-with-cloud-siem/cloud-siem-content-catalog",
4083-
"/docs/cse/introduction-to-cloud-sie": "/docs/cse/get-started-with-cloud-siem",
4092+
"/docs/cse/introduction-to-cloud-siem": "/docs/cse/get-started-with-cloud-siem",
40844093
"/docs/integrations/sumo-apps/security-foundations": "/docs/integrations/sumo-apps/security-analytics",
40854094
"/docs/send-data/collect-from-other-data-sources/amazon-cloudwatch-logs/collect-with-amazon-kinesis": "/docs/send-data/collect-from-other-data-sources/amazon-cloudwatch-logs",
40864095
"/docs/send-data/collect-from-other-data-sources/amazon-cloudwatch-logs/collect-with-collector-script": "/docs/send-data/collect-from-other-data-sources/amazon-cloudwatch-logs",

docs/alerts/monitors/alert-response.md

Lines changed: 15 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -20,6 +20,20 @@ import Iframe from 'react-iframe';
2020

2121
Learn how to use alert response.
2222

23+
24+
<Iframe url="https://fast.wistia.net/embed/iframe/elkucyy4ap?web_component=true&seo=true&videoFoam=false"
25+
width="854px"
26+
height="480px"
27+
title="Micro Lesson: Using Alert Response Video"
28+
id="wistiaVideo"
29+
className="video-container"
30+
display="initial"
31+
position="relative"
32+
allow="autoplay; fullscreen"
33+
allowfullscreen
34+
/>
35+
36+
<!-- old
2337
<Iframe url="https://www.youtube.com/embed/3FHomBuFyV8?rel=0"
2438
width="854px"
2539
height="480px"
@@ -30,6 +44,7 @@ Learn how to use alert response.
3044
allow="accelerometer; clipboard-write; encrypted-media; gyroscope; picture-in-picture"
3145
allowfullscreen
3246
/>
47+
-->
3348

3449
:::
3550

docs/alerts/monitors/create-monitor.md

Lines changed: 31 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -5,6 +5,7 @@ description: Learn how to create a Sumo Logic monitor.
55
---
66

77
import useBaseUrl from '@docusaurus/useBaseUrl';
8+
import Iframe from 'react-iframe';
89

910
This guide will walk you through the steps of creating a monitor in Sumo Logic, from setting up trigger conditions to configuring advanced settings, notifications, and playbooks.
1011

@@ -87,7 +88,7 @@ Set specific threshold conditions for well-defined KPIs with constant thresholds
8788

8889
#### Anomaly
8990

90-
Leverage machine learning to identify unusual behavior and suspicious patterns by establishing baselines for normal activity. This [*AI-driven alerting*](https://www.youtube.com/watch?v=nMRoYb1YCfg) system uses historical data to minimize false positives and alerts you to deviations.
91+
Leverage machine learning to identify unusual behavior and suspicious patterns by establishing baselines for normal activity. This *AI-driven alerting* system uses historical data to minimize false positives and alerts you to deviations.
9192

9293
* **Model-driven detection**. Machine learning models create accurate baselines, eliminating guesswork and noise.
9394
* **AutoML**. The system self-tunes with seasonality detection, minimizing user intervention and adjusting for recurring patterns to reduce false positives.
@@ -96,6 +97,35 @@ Leverage machine learning to identify unusual behavior and suspicious patterns b
9697
* **Auto-diagnosis and recovery**. The Automation Service handles diagnosis and resolution, closing the loop from alert to recovery.
9798
* **Customizable detection**. Use advanced rules like "Cluster anomalies" to detect multiple data points exceeding thresholds within a set timeframe.
9899

100+
:::sumo Micro Lesson
101+
Learn about AI-driven alerting.
102+
103+
<Iframe url="https://fast.wistia.net/embed/iframe/8z9b2zqtc3?web_component=true&seo=true&videoFoam=false"
104+
width="854px"
105+
height="480px"
106+
title="Micro Lesson: AI-driven Alerting Video"
107+
id="wistiaVideo"
108+
className="video-container"
109+
display="initial"
110+
position="relative"
111+
allow="autoplay; fullscreen"
112+
allowfullscreen
113+
/>
114+
115+
<!-- old
116+
<Iframe url="https://www.youtube.com/embed/nMRoYb1YCfg?rel=0"
117+
width="854px"
118+
height="480px"
119+
id="myId"
120+
className="video-container"
121+
display="initial"
122+
position="relative"
123+
allow="accelerometer; clipboard-write; encrypted-media; gyroscope; picture-in-picture"
124+
allowfullscreen
125+
/>
126+
-->
127+
:::
128+
99129
**Use Outlier**
100130

101131
If you want to trigger alerts on outlier direction rather than anomaly detection, select **Anomaly** and enable **Use Outlier**. This detects unusual changes or spikes in a time series of a key indicator. Use this detection method when you are alerting on KPIs that don't have well-defined constant thresholds for what's good and bad. You want the monitor to automatically detect and alert on unusual changes or spikes on the alerting query. For example, application KPIs like page request, throughput, and latency. <br/><img src={useBaseUrl('img/alerts/monitors/monitor-detector-types-for-anomaly.png')} alt="Screenshot of the Monitor Type and Detection Method options in Sumo Logic's 'New Monitor' setup page. Logs is selected as the Monitor Type, and Anomaly is selected as the Detection Method. There is an option to use Outlier detection, which is currently toggled off." width="300"/>

docs/alerts/monitors/use-playbooks-with-monitors.md

Lines changed: 26 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -6,6 +6,7 @@ description: Learn how to use Automation Service playbooks with monitors.
66
---
77

88
import useBaseUrl from '@docusaurus/useBaseUrl';
9+
import Iframe from 'react-iframe';
910

1011
This article describes how to configure automated playbooks in monitors. An *automated playbook* is a [playbook in the Automation Service](/docs/platform-services/automation-service/automation-service-playbooks/), and is a predefined set of actions and conditional statements that run in an automated workflow to respond to an event. For example, suppose that a monitor detects suspicious behavior that could indicate a security problem. When the monitor sends the alert, it could also run an automated playbook to respond to the event.
1112

@@ -83,21 +84,34 @@ An anomaly monitor is triggered when unusual conditions are detected. Anomaly mo
8384
Weekly seasonality detection is turned off by default to optimize performance. [Contact Sumo Logic Customer Support](https://support.sumologic.com/support/s/contactsupport) to activate it for specific monitors. (*Weekly seasonality detection* is the optimization of baseline calculations to account for the variations of data flow that can occur in a work week.)
8485
:::
8586

87+
:::sumo Micro Lesson
8688
Watch this micro lesson to learn about anomaly monitors.
8789

90+
<Iframe url="https://fast.wistia.net/embed/iframe/8z9b2zqtc3?web_component=true&seo=true&videoFoam=false"
91+
width="854px"
92+
height="480px"
93+
title="Micro Lesson: AI-driven Alerting Video"
94+
id="wistiaVideo"
95+
className="video-container"
96+
display="initial"
97+
position="relative"
98+
allow="autoplay; fullscreen"
99+
allowfullscreen
100+
/>
101+
102+
<!-- old
88103
<Iframe url="https://www.youtube.com/embed/nMRoYb1YCfg?rel=0"
89-
width="854px"
90-
height="480px"
91-
id="myId"
92-
className="video-container"
93-
display="initial"
94-
position="relative"
95-
allow="accelerometer; clipboard-write; encrypted-media; gyroscope; picture-in-picture"
96-
allowfullscreen
97-
/>
98-
99-
import Iframe from 'react-iframe';
100-
104+
width="854px"
105+
height="480px"
106+
id="myId"
107+
className="video-container"
108+
display="initial"
109+
position="relative"
110+
allow="accelerometer; clipboard-write; encrypted-media; gyroscope; picture-in-picture"
111+
allowfullscreen
112+
/>
113+
-->
114+
:::
101115

102116
To create an anomaly monitor that runs an automated playbook in response to an alert:
103117

docs/apm/real-user-monitoring/configure-data-collection.md

Lines changed: 14 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -14,6 +14,19 @@ To collect [traces](/docs/apm/traces) and RUM metrics from a browser, you'll fir
1414
:::sumo Micro Lesson
1515
Using the RUM HTTP Traces App for Manual Testing.
1616

17+
<Iframe url="https://fast.wistia.net/embed/iframe/qmxk5wxqu5?web_component=true&seo=true&videoFoam=false"
18+
width="854px"
19+
height="480px"
20+
title="Using the RUM HTTP Traces App for Manual Testing Video"
21+
id="wistiaVideo"
22+
className="video-container"
23+
display="initial"
24+
position="relative"
25+
allow="autoplay; fullscreen"
26+
allowfullscreen
27+
/>
28+
29+
<!-- old
1730
<Iframe url="https://www.youtube.com/embed/CduT1sqSPmE?rel=0"
1831
width="854px"
1932
height="480px"
@@ -24,7 +37,7 @@ Using the RUM HTTP Traces App for Manual Testing.
2437
allow="accelerometer; clipboard-write; encrypted-media; gyroscope; picture-in-picture"
2538
allowfullscreen
2639
/>
27-
40+
-->
2841
:::
2942

3043
## Prerequisites

0 commit comments

Comments
 (0)