Skip to content

Commit fc6ff96

Browse files
jc-sumokimsaucejpipkin1
authored
CSIEM Content Release Notes 2025-01-28 (#5003)
* CSIEM Content Release Notes 2025-01-28 * Update 2025-01-14-content.md * Update blog-cse/2025/01-28.md Co-authored-by: Kim (Sumo Logic) <[email protected]> * Updates from review --------- Co-authored-by: Kim (Sumo Logic) <[email protected]> Co-authored-by: John Pipkin (Sumo Logic) <[email protected]>
1 parent cdd5a42 commit fc6ff96

File tree

2 files changed

+30
-4
lines changed

2 files changed

+30
-4
lines changed

blog-cse/2025-01-14-content.md

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -20,7 +20,7 @@ This content release includes:
2020
In two weeks, MATCH-S00604 "OneLogin - API Credentials - Key Used from Untrusted Location" will be deleted from the out-of-the-box Cloud SIEM rules due to unmanageable deny list logic and low adoption. To retain this rule, a duplicate must be made prior to the deletion.
2121
:::
2222

23-
## Log Mappers
23+
### Log Mappers
2424
- [New] Azure DevOps Auditing Catch All
2525
- [New] Check Point Application Control URL Filtering
2626
- [New] Cisco ISE Radius Diagnostics
@@ -40,15 +40,15 @@ In two weeks, MATCH-S00604 "OneLogin - API Credentials - Key Used from Untrusted
4040
- [Updated] Cloudflare - Logpush
4141
- Adds mapping for `dns_query`, `http_hostname`, `http_response_contentLength`, `http_response_contentType`, and an alternative value for `ipProtocol`.
4242
- [Updated] Linux OS Syslog - Process sshd - SSH Session Closed|disconnect
43-
- Adds mapping for `normalizedActio`n
43+
- Adds mapping for `normalizedAction`
4444
- [Updated] Linux OS Syslog - Process systemd - Systemd Session Start and Systemd File Configuration
4545
- Added support for additional events and mapping of `file_path`
4646

47-
## Parsers
47+
### Parsers
4848
- [New] /Parsers/System/Pfsense/Pfsense Firewall
4949
- [Updated] /Parsers/System/Check Point/Check Point Firewall JSON
5050
- [Updated] /Parsers/System/Cisco/Cisco ISE
5151
- [Updated] /Parsers/System/Cloudflare/Cloudflare Logpush
5252
- [Updated] /Parsers/System/Linux/Linux OS Syslog
5353
- [Updated] /Parsers/System/Linux/Shared/Linux Shared Syslog Headers
54-
- [Updated] /Parsers/System/Linux/Shared/Linux Shared Syslog Headers
54+
- [Updated] /Parsers/System/Linux/Shared/Linux Shared Syslog Headers

blog-cse/2025-01-28-content.md

Lines changed: 26 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,26 @@
1+
---
2+
title: January 28, 2025 - Content Release
3+
image: https://help.sumologic.com/img/sumo-square.png
4+
keywords:
5+
- log mappers
6+
- parsers
7+
hide_table_of_contents: true
8+
---
9+
10+
import useBaseUrl from '@docusaurus/useBaseUrl';
11+
12+
<a href="https://help.sumologic.com/release-notes-cse/rss.xml"><img src={useBaseUrl('img/release-notes/rss-orange2.png')} alt="icon" width="50"/></a>
13+
14+
This content release includes:
15+
- Fix to Azure DevOps Auditing mapper to ensure only Azure DevOps logs are mapped by it when ingested via Event Hubs C2C.
16+
- Adds parsing and mapping support for additional OpenVPN events.
17+
- Adds additional timestamp format handling to Azure JSON log parsing.
18+
19+
### Log Mappers
20+
- [Updated] Azure DevOps Auditing Catch All
21+
- [Updated] OpenVPN Audit Event
22+
- [Updated] OpenVPN Network Event
23+
24+
### Parsers
25+
- [Updated] /Parsers/System/Microsoft/Microsoft Azure JSON
26+
- [Updated] /Parsers/System/OpenVPN/OpenVPN Syslog

0 commit comments

Comments
 (0)