You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: blog-cse/2025-01-14-content.md
+4-4Lines changed: 4 additions & 4 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -20,7 +20,7 @@ This content release includes:
20
20
In two weeks, MATCH-S00604 "OneLogin - API Credentials - Key Used from Untrusted Location" will be deleted from the out-of-the-box Cloud SIEM rules due to unmanageable deny list logic and low adoption. To retain this rule, a duplicate must be made prior to the deletion.
21
21
:::
22
22
23
-
## Log Mappers
23
+
###Log Mappers
24
24
-[New] Azure DevOps Auditing Catch All
25
25
-[New] Check Point Application Control URL Filtering
26
26
-[New] Cisco ISE Radius Diagnostics
@@ -40,15 +40,15 @@ In two weeks, MATCH-S00604 "OneLogin - API Credentials - Key Used from Untrusted
40
40
-[Updated] Cloudflare - Logpush
41
41
- Adds mapping for `dns_query`, `http_hostname`, `http_response_contentLength`, `http_response_contentType`, and an alternative value for `ipProtocol`.
42
42
-[Updated] Linux OS Syslog - Process sshd - SSH Session Closed|disconnect
43
-
- Adds mapping for `normalizedActio`n
43
+
- Adds mapping for `normalizedAction`
44
44
-[Updated] Linux OS Syslog - Process systemd - Systemd Session Start and Systemd File Configuration
45
45
- Added support for additional events and mapping of `file_path`
46
46
47
-
## Parsers
47
+
###Parsers
48
48
-[New] /Parsers/System/Pfsense/Pfsense Firewall
49
49
-[Updated] /Parsers/System/Check Point/Check Point Firewall JSON
0 commit comments