Skip to content

Commit f18b069

Browse files
authored
Merge branch 'main' into SUMO-254673-doc-changes-for-v-1-to-v-2-migrations-apps
2 parents 7041463 + 20163a1 commit f18b069

File tree

42 files changed

+524
-89
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

42 files changed

+524
-89
lines changed

.clabot

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -173,7 +173,8 @@
173173
"JamoCA",
174174
"darshan-sumo",
175175
"mahendrak-sumo",
176-
"chvik"
176+
"chvik",
177+
"Apoorvkudesia-sumologic"
177178
],
178179
"message": "Thank you for your contribution! As this is an open source project, we require contributors to sign our Contributor License Agreement and do not have yours on file. To proceed with your PR, please [sign your name here](https://forms.gle/YgLddrckeJaCdZYA6) and we will add you to our approved list of contributors.",
179180
"label": "cla-signed",

blog-cse/2025-01-14-content.md

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -20,7 +20,7 @@ This content release includes:
2020
In two weeks, MATCH-S00604 "OneLogin - API Credentials - Key Used from Untrusted Location" will be deleted from the out-of-the-box Cloud SIEM rules due to unmanageable deny list logic and low adoption. To retain this rule, a duplicate must be made prior to the deletion.
2121
:::
2222

23-
## Log Mappers
23+
### Log Mappers
2424
- [New] Azure DevOps Auditing Catch All
2525
- [New] Check Point Application Control URL Filtering
2626
- [New] Cisco ISE Radius Diagnostics
@@ -40,15 +40,15 @@ In two weeks, MATCH-S00604 "OneLogin - API Credentials - Key Used from Untrusted
4040
- [Updated] Cloudflare - Logpush
4141
- Adds mapping for `dns_query`, `http_hostname`, `http_response_contentLength`, `http_response_contentType`, and an alternative value for `ipProtocol`.
4242
- [Updated] Linux OS Syslog - Process sshd - SSH Session Closed|disconnect
43-
- Adds mapping for `normalizedActio`n
43+
- Adds mapping for `normalizedAction`
4444
- [Updated] Linux OS Syslog - Process systemd - Systemd Session Start and Systemd File Configuration
4545
- Added support for additional events and mapping of `file_path`
4646

47-
## Parsers
47+
### Parsers
4848
- [New] /Parsers/System/Pfsense/Pfsense Firewall
4949
- [Updated] /Parsers/System/Check Point/Check Point Firewall JSON
5050
- [Updated] /Parsers/System/Cisco/Cisco ISE
5151
- [Updated] /Parsers/System/Cloudflare/Cloudflare Logpush
5252
- [Updated] /Parsers/System/Linux/Linux OS Syslog
5353
- [Updated] /Parsers/System/Linux/Shared/Linux Shared Syslog Headers
54-
- [Updated] /Parsers/System/Linux/Shared/Linux Shared Syslog Headers
54+
- [Updated] /Parsers/System/Linux/Shared/Linux Shared Syslog Headers

blog-cse/2025-01-28-content.md

Lines changed: 26 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,26 @@
1+
---
2+
title: January 28, 2025 - Content Release
3+
image: https://help.sumologic.com/img/sumo-square.png
4+
keywords:
5+
- log mappers
6+
- parsers
7+
hide_table_of_contents: true
8+
---
9+
10+
import useBaseUrl from '@docusaurus/useBaseUrl';
11+
12+
<a href="https://help.sumologic.com/release-notes-cse/rss.xml"><img src={useBaseUrl('img/release-notes/rss-orange2.png')} alt="icon" width="50"/></a>
13+
14+
This content release includes:
15+
- Fix to Azure DevOps Auditing mapper to ensure only Azure DevOps logs are mapped by it when ingested via Event Hubs C2C.
16+
- Adds parsing and mapping support for additional OpenVPN events.
17+
- Adds additional timestamp format handling to Azure JSON log parsing.
18+
19+
### Log Mappers
20+
- [Updated] Azure DevOps Auditing Catch All
21+
- [Updated] OpenVPN Audit Event
22+
- [Updated] OpenVPN Network Event
23+
24+
### Parsers
25+
- [Updated] /Parsers/System/Microsoft/Microsoft Azure JSON
26+
- [Updated] /Parsers/System/OpenVPN/OpenVPN Syslog

blog-service/2023/12-31.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -57,7 +57,7 @@ Here are some of the key features the new solution offers:
5757
* **Misconfigurations**. See areas in your environment that need to be addressed because they fail best practice security controls.
5858
* **Suspicious activity assessment**. See suspicious activity across users, web interactions, networks, and Identity Access Management (IAM).
5959

60-
To learn how you can set up and use Cloud Infrastructure Security for AWS, and for preview limitations, check out our technical documentation [here](/docs/security/cloud-infrastructure-security/cloud-infrastructure-security-for-aws/).
60+
To learn how you can set up and use Cloud Infrastructure Security for AWS, and for preview limitations, check out our technical documentation [here](/docs/security/additional-security-features/cloud-infrastructure-security/cloud-infrastructure-security-for-aws/).
6161

6262
:::note
6363
To use the solution, you are required to sign up and activate Amazon GuardDuty and AWS Security Hub.

blog-service/2024/12-31.md

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -401,7 +401,7 @@ You can now more easily configure sources on a simplified screen, allowing you t
401401

402402
<img src={useBaseUrl('img/integrations/amazon-aws/cis-for-aws-install-0.png')} alt="Configure Sources screen" style={{border: '1px solid gray'}} width="700"/>
403403

404-
[Learn more](/docs/security/cloud-infrastructure-security/cloud-infrastructure-security-for-aws/).
404+
[Learn more](/docs/security/additional-security-features/cloud-infrastructure-security/cloud-infrastructure-security-for-aws/).
405405

406406
### October 21, 2024 (Apps)
407407

@@ -807,7 +807,7 @@ We're excited to announce increased visibility into your AWS Cloud environment w
807807

808808
This functionality is in preview. To participate, reach out to your Sumo Logic account executive.
809809

810-
[Learn more](/docs/security/cloud-infrastructure-security/cloud-infrastructure-security-for-aws/).
810+
[Learn more](/docs/security/additional-security-features/cloud-infrastructure-security/cloud-infrastructure-security-for-aws/).
811811

812812
:::note
813813
As part of the preview, you can use CloudQuery logs with Cloud Infrastructure Security for AWS. To use the logs, configure the CloudQuery source when you deploy the solution.
@@ -1077,7 +1077,7 @@ Here are some of the key features the new solution offers:
10771077
* **Misconfigurations**. See areas in your environment that need to be addressed because they fail best practice security controls.
10781078
* **Suspicious activity assessment**. See suspicious activity across users, web interactions, networks, and Identity Access Management (IAM).
10791079

1080-
To learn how you can set up and use Cloud Infrastructure Security for AWS, check out our [technical documentation](/docs/security/cloud-infrastructure-security/cloud-infrastructure-security-for-aws/).
1080+
To learn how you can set up and use Cloud Infrastructure Security for AWS, check out our [technical documentation](/docs/security/additional-security-features/cloud-infrastructure-security/cloud-infrastructure-security-for-aws/).
10811081

10821082

10831083
:::note Action Required

blog-service/2025-01-28-apps.md

Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,14 @@
1+
---
2+
title: VMware Workspace ONE (Apps)
3+
image: https://help.sumologic.com/img/sumo-square.png
4+
keywords:
5+
- apps
6+
- vmware-workspace-one
7+
hide_table_of_contents: true
8+
---
9+
10+
import useBaseUrl from '@docusaurus/useBaseUrl';
11+
12+
<a href="https://help.sumologic.com/release-notes-service/rss.xml"><img src={useBaseUrl('img/release-notes/rss-orange2.png')} alt="icon" width="50"/></a>
13+
14+
We're excited to introduce the new VMware Workspace ONE app for Sumo Logic. This app leverages the Sumo Logic Cloud-to-Cloud VMware Workspace ONE source that collects audit logs data from the VMware Workspace ONE platform. This app helps security analysts monitor device compliance, encryption, and overall security status, offering a powerful solution for effective risk analysis, policy enforcement, and device security. [Learn more](/docs/integrations/saas-cloud/vmware-workspace-one/).

cid-redirects.json

Lines changed: 16 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -362,6 +362,7 @@
362362
"/docs/send-data/sumo-distribution-opentelemetry": "/docs/send-data/opentelemetry-collector",
363363
"/03Send-Data/Sources/03Use-JSON-to-Configure-Sources/Local-Configuration-File-Management/Local-File-Configuration-Management-for-New-Collectors-and-Sources": "/docs/send-data/use-json-configure-sources/local-configuration-file-management/new-collectors-and-sources",
364364
"/03Search/Search-Query-Language/01Introduction-to-Search-Query-Language": "/docs/search/search-query-language",
365+
"/03Sumo-Logic-Applications/Cloud_SIEM": "/docs/integrations/sumo-apps/cse",
365366
"/05Search": "/docs/search",
366367
"/05Search/Library": "/docs/get-started/library",
367368
"/05Search/Library/Apps-in-Sumo-Logic": "/docs/integrations",
@@ -1324,6 +1325,7 @@
13241325
"/07Sumo-Logic-Apps/Cloud_Security_Monitoring_and_Analytics/AWS_CloudTrail_-_Cloud_Security_Monitoring_and_Analytics/Collect_Logs_for_the_AWS_CloudTrail_-_Cloud_Security_Monitoring_and_Analytics": "/docs/integrations/cloud-security-monitoring-analytics/aws-cloudtrail",
13251326
"/07Sumo-Logic-Apps/Cloud_Security_Monitoring_and_Analytics/AWS_CloudTrail_-_Cloud_Security_Monitoring_and_Analytics/Install_the_Cloud_Security_Monitoring_and_Analytics_for_AWS_CloudTrail_App_and_view_the_Dashboards": "/docs/integrations/cloud-security-monitoring-analytics/aws-cloudtrail",
13261327
"/07Sumo-Logic-Apps/Cloud_Security_Monitoring_and_Analytics/Amazon_CloudTrail_-_Cloud_Security_Monitoring_and_Analytics": "/docs/integrations/cloud-security-monitoring-analytics/aws-cloudtrail",
1328+
"/07Sumo-Logic-Apps/Cloud_Security_Monitoring_and_Analytics/Amazon_CloudTrail_-_Cloud_Security_Monitoring_and_Analytics/Collect_Logs_for_the_Amazon_CloudTrail_-_Cloud_Security_Monitoring_and_Analytics": "/docs/integrations/cloud-security-monitoring-analytics/aws-cloudtrail",
13271329
"/07Sumo-Logic-Apps/Cloud_Security_Monitoring_and_Analytics/AWS_Security_Hub_-_Cloud_Security_Monitoring_and_Analytics": "/docs/integrations/cloud-security-monitoring-analytics/aws-security-hub",
13281330
"/07Sumo-Logic-Apps/Cloud_Security_Monitoring_and_Analytics/AWS_Security_Hub_-_Cloud_Security_Monitoring_and_Analytics/Collect_findings_for_the_AWS_Security_Hub_-_Cloud_Security_Monitoring_and_Analytics_App": "/docs/integrations/cloud-security-monitoring-analytics/aws-security-hub",
13291331
"/07Sumo-Logic-Apps/Cloud_Security_Monitoring_and_Analytics/AWS_Security_Hub_-_Cloud_Security_Monitoring_and_Analytics/Install_the_AWS_Security_Hub_App_-_Cloud_Security_Monitoring_and_Analytics%2C_and_view_the_Dashboards": "/docs/integrations/cloud-security-monitoring-analytics/aws-security-hub",
@@ -1602,6 +1604,7 @@
16021604
"/cid/10207": "/docs/integrations/saas-cloud/symantec-endpoint-security-service",
16031605
"/cid/10197": "/docs/integrations/saas-cloud/symantec-web-security-service",
16041606
"/cid/6016": "/docs/integrations/saas-cloud/trend-micro-vision-one",
1607+
"/cid/6024": "/docs/integrations/saas-cloud/vmware-workspace-one",
16051608
"/cid/10112": "/docs/integrations/app-development/jfrog-xray",
16061609
"/cid/10113": "/docs/observability/root-cause-explorer",
16071610
"/cid/10116": "/docs/manage/fields",
@@ -1793,7 +1796,7 @@
17931796
"/cid/1094": "/docs/dashboards/share-dashboard-outside-org",
17941797
"/cid/1095": "/docs/integrations/amazon-aws/cis-aws-foundations-benchmark",
17951798
"/cid/1096": "/docs/dashboards/explore-view",
1796-
"/cid/1097": "/docs/security/cloud-infrastructure-security/cloud-infrastructure-security-for-aws",
1799+
"/cid/1097": "/docs/security/additional-security-features/cloud-infrastructure-security/cloud-infrastructure-security-for-aws",
17971800
"/cid/1100": "/docs/integrations/amazon-aws/vpc-flow-logs-pci-compliance",
17981801
"/cid/1101": "/docs/search/search-query-language/math-expressions/floor",
17991802
"/cid/1102": "/docs/search/search-query-language/math-expressions/ceil",
@@ -2981,9 +2984,11 @@
29812984
"/Internal_Writers/Topic_Archive/Parse_by_Data_Type/Parse_Apache_Logs/Parse_Apache_Access_Logs": "/docs/search/get-started-with-search/suggested-searches/apache-access-parser",
29822985
"/Internal_Writers/Topic_Archive/Parse_by_Data_Type/Parse_Apache_Logs/Parse_Apache_Error_Logs": "/docs/search/get-started-with-search/suggested-searches/apache-errors-parser",
29832986
"/Internal_Writers/Topic_Archive/Parse_by_Data_Type/Parse_Cisco_ASA_Logs": "/",
2987+
"/Knowledge_Base/APIs": "/docs/api",
29842988
"/Knowledge_Base/Apps": "/docs/integrations",
29852989
"/Knowledge_Base/Parsing/Using_line_breaks_as_an_anchor_within_parse": "/docs/search/search-query-language/parse-operators/parse-predictable-patterns-using-an-anchor",
29862990
"/Knowledge_Base/Search/How_to_Prevent_your_Scheduled_Search_from_Timing_Out": "/docs/alerts/scheduled-searches/faq",
2991+
"/Limited_Availability/Lookup_Tables": "/docs/search/search-query-language/search-operators/lookupcontains",
29872992
"/Limited_Availability/Lookup_Tables/lookupContains_Operator": "/docs/search/search-query-language/search-operators/lookupcontains",
29882993
"/Manage": "/docs/manage",
29892994
"/Manage/01Manage_Subscription": "/docs/manage/manage-subscription",
@@ -3137,6 +3142,7 @@
31373142
"/Manage/Connections-and-Integrations/Webhook-Connections/Webhook_Connection_for_PagerDuty": "/docs/alerts/webhook-connections/pagerduty",
31383143
"/Manage/Connections-and-Integrations/Webhook-Connections/Webhook_Connection_for_Slack": "/docs/alerts/webhook-connections/slack",
31393144
"/Manage/Connections-and-Integrations/Webhook-Connections/Webhook_Connections_for_Jira": "/docs/alerts/webhook-connections/jira-server",
3145+
"/Manage/Connections-and-Integrations/Webhook-Connections/Webhook_Connections_for_Jira/Webhook_Connection_for_Jira_Cloud": "/docs/alerts/webhook-connections/jira-cloud",
31403146
"/Manage/Content_Sharing": "/docs/manage/content-sharing",
31413147
"/Manage/Content_Sharing/Share_Content": "/docs/manage/content-sharing",
31423148
"/Manage/Content_Sharing/Admin_Mode": "/docs/manage/content-sharing/admin-mode",
@@ -4029,6 +4035,7 @@
40294035
"/Start-Here": "/docs/get-started/account-settings-preferences",
40304036
"/Start-Here/02Getting-Started/01-How-to-Sign-Up-for-Sumo-Logic": "/docs/get-started/account-settings-preferences",
40314037
"/Start-Here/03Welcome-to-the-New-Sumo-Logic-UI": "/docs/get-started/sumo-logic-ui",
4038+
"/Start-Here/01About-Sumo-Logic/Sumo-Logic-Support-Terms-and-Conditions": "/docs/get-started/help",
40324039
"/Start-Here/01About-Sumo-Logic/System-Requirements/Supported-Browsers": "/docs/get-started/system-requirements",
40334040
"/Start-Here/01About-Sumo-Logic/System-Requirements/Installed-Collector-Requirements": "/docs/get-started/system-requirements",
40344041
"/Traces/02Working_with_Tracing_data/Spans": "/docs/apm/traces/spans",
@@ -4151,15 +4158,18 @@
41514158
"/cid/-1": "/",
41524159
"/docs/api/beta": "/docs/api",
41534160
"/docs/api/dashboard-data": "/docs/api/dashboard",
4154-
"/docs/cloud-security-analytics": "/docs/security/cloud-infrastructure-security",
4155-
"/docs/cloud-security-analytics/introduction-to-cloud-security-analytics": "/docs/security/cloud-infrastructure-security/introduction",
4161+
"/docs/cloud-security-analytics": "/docs/security/additional-security-features/cloud-infrastructure-security",
4162+
"/docs/cloud-security-analytics/introduction-to-cloud-security-analytics": "/docs/security/additional-security-features/cloud-infrastructure-security/introduction",
41564163
"/docs/cloud-security-analytics/data-lake": "/docs/security/additional-security-features/data-lake",
41574164
"/docs/cloud-security-analytics/audit-and-compliance": "/docs/security/additional-security-features/audit-and-compliance",
41584165
"/docs/cloud-security-analytics/threat-detection-and-investigation": "/docs/security/additional-security-features/threat-detection-and-investigation",
41594166
"/docs/cloud-security-analytics/application-security": "/docs/security/additional-security-features/application-security",
4160-
"/docs/integrations/amazon-aws/cloud-infrastructure-security-for-aws": "/docs/security/cloud-infrastructure-security/cloud-infrastructure-security-for-aws",
4161-
"/docs/cloud-infrastructure-security": "/docs/security/cloud-infrastructure-security",
4162-
"/docs/cloud-infrastructure-security/introduction-to-cloud-infrastructure-security": "/docs/security/cloud-infrastructure-security/introduction",
4167+
"/docs/integrations/amazon-aws/cloud-infrastructure-security-for-aws": "/docs/security/additional-security-features/cloud-infrastructure-security/cloud-infrastructure-security-for-aws",
4168+
"/docs/cloud-infrastructure-security": "/docs/security/additional-security-features/cloud-infrastructure-security",
4169+
"/docs/cloud-infrastructure-security/introduction-to-cloud-infrastructure-security": "/docs/security/additional-security-features/cloud-infrastructure-security/introduction",
4170+
"/docs/security/cloud-infrastructure-security": "/docs/security/additional-security-features/cloud-infrastructure-security",
4171+
"/docs/security/cloud-infrastructure-security/introduction": "/docs/security/additional-security-features/cloud-infrastructure-security/introduction",
4172+
"/docs/security/cloud-infrastructure-security/cloud-infrastructure-security-for-aws": "/docs/security/additional-security-features/cloud-infrastructure-security/cloud-infrastructure-security-for-aws",
41634173
"/docs/cloud-infrastructure-security/data-lake": "/docs/security/additional-security-features/data-lake",
41644174
"/docs/cloud-infrastructure-security/audit-and-compliance": "/docs/security/additional-security-features/audit-and-compliance",
41654175
"/docs/cloud-infrastructure-security/threat-detection-and-investigation": "/docs/security/additional-security-features/threat-detection-and-investigation",

docs/api/search-job.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -620,7 +620,7 @@ The metadata fields `_sourceHost`, `_sourceName`, and `_sourceCategory`, which a
620620
### Page through the records found by a Search Job
621621

622622
<details>
623-
<summary><span className="api get">GET</span><code>/v1/search/jobs/&#123;SEARCH_JOB_ID&#125;/records?offset=&#123;OFFSET]&limit=&#123;LIMIT&#125;</code></summary>
623+
<summary><span className="api get">GET</span><code>/v1/search/jobs/&#123;SEARCH_JOB_ID&#125;/records?offset=&#123;OFFSET&#125;&limit=&#123;LIMIT&#125;</code></summary>
624624
<p/>
625625

626626
The search job status informs the user as to the number of produced records, if the query performs an aggregation. Those records can be requested using a paging API call (step 6 in the process flow), just as the message can be requested.

docs/cse/get-started-with-cloud-siem/about-cse-insight-ui.md

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -76,11 +76,11 @@ You can use the **Filters** area near the top of the page to narrow down the ins
7676

7777
### Multi-insights list page
7878

79-
We offer an insights list page where you can see a list of all insights across multiple child organizations. This is useful if your company is a large enterprise with many organizations or is a Managed Security Service Provider (MSSP), and you'd like to see all insights across all areas in a single page.
79+
If you are logged in to a parent organization with child organizations that also use Cloud SIEM, the insights list page shows all insights across all your child organizations. This is useful if your company is a large enterprise with many organizations or is a Managed Security Service Provider (MSSP), and you'd like to see all insights across all areas in a single page.
8080

81-
This multi-insights list page (also known as a "federated" page) shows insights just as in a normal [insights list page](#insights-list-page). However, when you click an insight on the page, it opens the insight's details in the child organization's UI. You can use also use the [board view](#board-view) on the multi-insights page to move insights to different statuses.
81+
This multi-insights list page (also known as a "federated" page) shows insights just as in a normal [insights list page](#insights-list-page). However, when you click an insight on the page, it opens the insight's details in the child organization's UI. You can also use the [board view](#board-view) on the multi-insights page to move insights to different statuses.
8282

83-
The multi-insights list page requires a special environment be set up for it. To have a multi-insights list page set up for your company, contact your Sumo Logic account representative, or contact [Sumo Logic Support](https://support.sumologic.com/support/s/).
83+
To be able to see insights in child organizations, [add child organizations](/docs/manage/manage-subscription/create-manage-orgs/) that use Cloud SIEM. Then when the parent organization user goes to their Cloud SIEM insights list page, all the child organizations' insights appear in the list.
8484

8585
## Insight details page
8686

docs/integrations/amazon-aws/index.md

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -379,5 +379,12 @@ This guide has documentation for all of the apps that Sumo provides for Amazon a
379379
<h4><a href="/docs/integrations/amazon-aws/threat-intel">AWS Foundations Benchmark App</a></h4>
380380
<p>A guide to the Sumo Logic app for AWS Threat Intel.</p>
381381
</div>
382+
</div>
383+
<div className="box smallbox card">
384+
<div className="container">
385+
<img src={useBaseUrl('img/integrations/amazon-aws/cis-for-aws-logo.png')} alt="Thumbnail icon" width="50"/>
386+
<h4><a href="/docs/security/additional-security-features/cloud-infrastructure-security/cloud-infrastructure-security-for-aws">Cloud Infrastructure Security for AWS</a></h4>
387+
<p>A guide to our Cloud Infrastructure Security for AWS app.</p>
388+
</div>
382389
</div>
383390
</div>

0 commit comments

Comments
 (0)