Change log for DELL_SWITCH

Date Changes
2026-05-27 Enhancement:
- Added a new grok pattern to extract raw log fields.
- Modified a grok pattern to extract inter_host from the raw log.
- event.idm.read_only_udm.additional.fields: Newly mapped source_file_description, message_id raw log fields with event.idm.read_only_udm.additional.fields UDM field.
- event.idm.read_only_udm.target.application: Newly mapped tar_app raw log field with event.idm.read_only_udm.target.application UDM field.
- event.idm.read_only_udm.target.user.userid: Newly mapped tar_userid raw log field with event.idm.read_only_udm.target.user.userid UDM field.
- event.idm.read_only_udm.principal.ip and event.idm.read_only_udm.principal.asset.ip: Newly mapped principal_ip raw log field with event.idm.read_only_udm.principal.ip and event.idm.read_only_udm.principal.asset.ip UDM field.
- event.idm.read_only_udm.security_result.severity: Set event.idm.read_only_udm.security_result.severity to INFORMATIONAL when severity is INFO in the raw log.
- event.idm.read_only_udm.metadata.description: Newly mapped msg_desc raw log field with event.idm.read_only_udm.metadata.description UDM field.
- event.idm.read_only_udm.metadata.event_type: Updated the event.idm.read_only_udm.metadata.event_type to USER_LOGIN and USER_LOGOUT when necessary raw log fields are present.
- event.idm.read_only_udm.extensions.auth.type: Set event.idm.read_only_udm.extensions.auth.type to MACHINE for USER_LOGIN and USER_LOGOUT events.
2026-01-29 Enhancement:
- event.idm.read_only_udm.security_result.detection_fields: Newly mapped reason_code raw log field(s) with event.idm.read_only_udm.security_result.detection_fields UDM field.
- Added a new grok pattern to parse logs containing Reason Code.
2026-01-09 Enhancement:
- Added grok patterns to parse the raw log.
- event.idm.read_only_udm.intermediary.hostname, event.idm.read_only_udm.intermediary.asset.hostname : Newly mapped inter_host field with event.idm.read_only_udm.intermediary.hostname and event.idm.read_only_udm.intermediary.asset.hostname UDM field.
- event.idm.read_only_udm.additional.fields : Newly mapped application_task,sequence_number,MSTID fields with event.idm.read_only_udm.additional.fields UDM field.
- Added a new date format to map datetime field with event.idm.read_only_udm.metadata.event_timestamp UDM field.
- event.idm.read_only_udm.principal.resource.attribute.labels : Newly mapped interface field with event.idm.read_only_udm.principal.resource.attribute.labels UDM field.
2025-06-19 Enhancement:
- Added grok pattern to support for SYSLOG format.
- event.idm.read_only_udm.metadata.product_version: Newly mapped version field with event.idm.read_only_udm.metadata.product_version UDM field.
- event.idm.read_only_udm.target.process.pid: Newly mapped process_id raw log field with event.idm.read_only_udm.target.process.pid UDM field.
- event.idm.read_only_udm.target.application: Newly mapped app_name raw log field with event.idm.read_only_udm.target.application UDM field.
- event.idm.read_only_udm.target.resource.name: Newly mapped node raw log field with event.idm.read_only_udm.target.resource.name UDM field.
- event.idm.read_only_udm.metadata.product_event_type: Newly mapped log_type raw log field with event.idm.read_only_udm.metadata.product_event_type UDM field.
- event.idm.read_only_udm.principal.user.attribute.roles: Newly mapped role raw log field with event.idm.read_only_udm.principal.user.attribute.roles UDM field.
- event.idm.read_only_udm.security_result.summary: Newly mapped log_message raw log field with event.idm.read_only_udm.security_result.summary UDM field.
2025-04-02 Enhancement:
- Added support for JSON format.
- event.idm.read_only_udm.principal.hostname: Newly mapped hostname raw log field with event.idm.read_only_udm.principal.hostname UDM field.
- event.idm.read_only_udm.principal.asset.hostname: Newly mapped hostname raw log field with event.idm.read_only_udm.principal.asset.hostname UDM field.
- event.idm.read_only_udm.intermediate.hostname: Newly mapped hostname raw log field with event.idm.read_only_udm.intermediate.hostname UDM field.
- event.idm.read_only_udm.principal.process.pid: Newly mapped proc_id raw log field with event.idm.read_only_udm.principal.process.pid UDM field.
- event.idm.read_only_udm.security_result.summary: Newly Mapped error_detail raw log field with event.idm.read_only_udm.security_result.summary UDM field.
- event.idm.read_only_udm.security_result.severity: Newly mapped error_type raw log field with event.idm.read_only_udm.security_result.severity UDM field.
- event.idm.read_only_udm.target.mac: Newly mapped mac_address raw log field with event.idm.read_only_udm.target.mac UDM field.
- event.idm.read_only_udm.target.url: Newly mapped hostname_string raw log field with event.idm.read_only_udm.target.url UDM field.
- event.idm.read_only_udm.target.ip: Newly Mapped ipv6, ipv4 raw log fields with event.idm.read_only_udm.target.ip.
- event.idm.read_only_udm.target.asset.ip: Newly mapped ipv6, ipv4 raw log fields with event.idm.read_only_udm.target.asset.ip.
2024-10-09 Enhancement:
- Added a Grok pattern to parse a new type of logs.
- Mapped Eventid to metadata.product_log_id.
- Mapped Eventseverity to security_result.severity.
- Mapped Computer to principal.hostname and principal.asset.hostname.
- Mapped Program to principal.application.
- Mapped Description to security_result.description.
2024-08-20 Enhancement:
- Added support to handle unparsed SYSLOG logs.
2024-04-25 Enhancement:
- Added Grok patterns to parse a new log type.
- Mapped op to metadata.product_event_type.
- Mapped mac to principal.mac.
- Mapped addr to principal.ip.
- Mapped hostname to principal.ip.
- Mapped server_ip to principal.ip.
- Mapped server_port to principal.port.
- Mapped acct to principal.user.userid.
- Mapped target_ip to target.ip.
- Mapped local_ip to target.ip.
- Mapped local_port to target.port.
- Mapped File to target.file.full_path.
- Mapped target_host to target.hostname.
- Mapped target_user_id to target.user.userid.
- Mapped Server_ID to target.resource.product_object_id.
- Mapped tzknown, is_synced and exe to security_result.detection_fields.
- Mapped res to security_result.summary.
- If value of the field res is ", then mapped status to security_result.summary".
- Mapped uid, enterpriseId, auid, terminal, subj, grantors, and ID to principal.resource.attribute.labels.
2024-04-04 - Added Grok patterns to parse new log type.
- Mapped prod_event_type to metadata.product_event_type.
- Mapped ip to principal.ip.
- Mapped dest_ip to target.ip.
- Mapped target_url to target.url.
- Mapped sec_description to security_result.description.
- Mapped action_details to security_result.action_details.
2024-01-04 - Added Grok patterns for newly ingested logs.
- Added date block when datetime is in SYSLOGTIMESTAMP format.
- Mapped softwareName to principal.asset.software.name.
- Mapped swVersion to principal.asset.software.version.
- Mapped port to principal_port.
- Mapped user to principal.user.userid and set metadata.event_type to USER_UNCATEGORIZED when user is present.
- Mapped application to principal.application.
- Mapped ip to principal.ip.
- Set sec_result.severity to INFORMATIONAL when severity is IFMGR-5-OSTATE_DN.
- Mapped msg to metadata.description.
2023-11-02 - Newly created parser.