Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
54 changes: 54 additions & 0 deletions blog-cse/2025-01-31-content.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,54 @@
---
title: January 31, 2025 - Content Release
image: https://help.sumologic.com/img/sumo-square.png
keywords:
- log mappers
- parsers
hide_table_of_contents: true
---

import useBaseUrl from '@docusaurus/useBaseUrl';

<a href="https://help.sumologic.com/release-notes-cse/rss.xml"><img src={useBaseUrl('img/release-notes/rss-orange2.png')} alt="icon" width="50"/></a>

This content release includes:
- Removal and updates to Cloud SIEM rules.
- Parsing and mapping support for new products.
- Updates to existing parsing and mappers to support additional events and field mappings.

Changes are enumerated below.

### Rules
- [Deleted] MATCH-S00604 OneLogin - API Credentials - Key Used from Untrusted Location
- [Updated] FIRST-S00044 First Seen AppID Generating MailItemsAccessed Event from User
- Corrected typo in "MailItemsAccessed".
- [Updated] FIRST-S00046 First Seen Client Generating MailItemsAccessed Event from User
- Corrected typo in "MailItemsAccessed".

### Log Mappers
- [New] Crowdstrike FileVantage Catch All
- [New] Dragos Communication
- [New] Dragos Indicator
- [New] Dragos System|Asset
- [New] Extrahop JSON Catch All
- [New] F5 TMM Http Request|TMM Network|TMM Connection error
- [New] F5 TMSH - Custom Parser
- [New] Zendesk - Login events
#### Updated Field Mappings
- [Updated] Code42 Incydr Alerts C2C
- [Updated] Cyber Ark EPM AggregateEvent
- [Updated] Google G Suite - meet
- [Updated] Palo Alto GlobalProtect - Custom Parser
- [Updated] Palo Alto GlobalProtect Auth - Custom Parser
- [Updated] Zendesk Catch All

### Parsers
- [New] /Parsers/System/CrowdStrike/CrowdStrike Filevantage
- [New] /Parsers/System/Extrahop/Extrahop JSON
#### Updated parsers to handle additional events and field parsing
- [Updated] /Parsers/System/Code42/Code42 Incydr
- [Updated] /Parsers/System/Dragos/Dragos
- [Updated] /Parsers/System/F5/F5 Syslog
- [Updated] /Parsers/System/Microsoft/Microsoft Azure JSON
- [Updated] /Parsers/System/Microsoft/Office 365
- [Updated] /Parsers/System/Palo Alto/PAN Firewall CSV