Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
37 changes: 37 additions & 0 deletions blog-cse/2025-11-06-content.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,37 @@
---
title: November 6, 2025 - Content Release
image: https://assets-www.sumologic.com/company-logos/_800x418_crop_center-center_82_none/SumoLogic_Preview_600x600.jpg?mtime=1617040082
keywords:
- log mappers
- parsers
- rules
hide_table_of_contents: true
---

This content release includes:
- An updated parser and new log mappers for Netskope Cloud Security for improved handling of Netskope DLP logs.
- An updated mapper for Azure Audit Logs which repurposes the `changeTarget` field mapping for changed items such as groups.
- Updated Azure rules to accommodate the repurposed `changeTarget` field
- Updated Keeper Authentication mapper to include the `Success` field.

:::note
If you are ingesting Netskope Cloud Security Logs or Azure Audit Logs ensure that the log source is set to use the appropriate system parser:
- Netskope Cloud Security: /Parsers/System/Netskope/Netskope Security Cloud JSON
- Azure Audit Logs: /Parsers/System/Microsoft/Microsoft Azure JSON
:::

### Rules
- [Updated] MATCH-S00226 Azure - Add Member to Group
- [Updated] MATCH-S00220 Azure - Add Member to Role Outside of PIM
- [Updated] MATCH-S00231 Azure - Member Added to Global Administrator Role
- [Updated] MATCH-S00233 Azure - Member Added to Global Administrator Role Non-PIM
- [Updated] MATCH-S00229 Azure - Member Added to Non-Global Administrator Role

### Log Mappers
- [New] Netskope - DLP Alerts
- [New] Netskope - Incidents
- [Updated] AzureActivityLog AuditLogs
- [Updated] Keeper Authentication

### Parsers
- [Updated] /Parsers/System/Netskope/Netskope Security Cloud JSON