Change log for FIREEYE_NX
| Date | Changes |
|---|---|
| 2026-07-24 |
Enhancement: - event.idm.read_only_udm.security_result.detection.fields: Removed mapping of cnc-services.cnc-service.sname from event.idm.read_only_udm.security_result.detection.fields UDM field as cnc-services.cnc-service.sname represents the specific detection signature or rule.- event.idm.read_only_udm.security_result.rule_name: Mapped cnc-services.cnc-service.sname raw log field with event.idm.read_only_udm.security_result.rule_name UDM field.
|
| 2026-07-09 |
Enhancement: - event.idm.read_only_udm.security_result.rule_name: Removed mapping of alert.name from event.idm.read_only_udm.security_result.rule_name UDM field as alert.name represents the product's event category.- event.idm.read_only_udm.metadata.product_event_type: Mapped alert.name raw log field with event.idm.read_only_udm.metadata.product_event_type UDM field.- event.idm.read_only_udm.metadata.product_log_id: Newly mapped entry.data.alert.uuid raw log field with event.idm.read_only_udm.metadata.product_log_id UDM field.- event.idm.read_only_udm.network.http.user_agent and event.idm.read_only_udm.network.http.parsed_user_agent: Newly mapped User-Agent raw log field with event.idm.read_only_udm.network.http.user_agent and event.idm.read_only_udm.network.http.parsed_user_agent UDM field.- event.idm.read_only_udm.network.http.method: Newly mapped method raw log field with event.idm.read_only_udm.network.http.method UDM field.- event.idm.read_only_udm.network.tls.version_protocol: Newly mapped protocol_version raw log field with event.idm.read_only_udm.network.tls.version_protocol UDM field.- event.idm.read_only_udm.target.mac and event.idm.read_only_udm.target.asset.mac: Newly mapped entry.data.alert.dst.mac raw log field with event.idm.read_only_udm.target.mac and event.idm.read_only_udm.target.asset.mac UDM fields.- event.idm.read_only_udm.observer.hostname and event.idm.read_only_udm.observer.asset.hostname: Newly mapped entry.data.appliance raw log field with event.idm.read_only_udm.observer.hostname and event.idm.read_only_udm.observer.asset.hostname UDM fields.- event.idm.read_only_udm.principal.user.attribute.labels: Newly mapped event_item_details_user raw log field with event.idm.read_only_udm.principal.user.attribute.labels UDM field.- event.idm.read_only_udm.principal.resource.attribute.labels: Newly mapped event_item_details_domain raw log field with event.idm.read_only_udm.principal.resource.attribute.labels UDM field.- event.idm.read_only_udm.security_result.rule_id: Added a condition to map alert.id raw log field with event.idm.read_only_udm.security_result.rule_id UDM field when alert.signature_id is not present to avoid overwriting.- event.idm.read_only_udm.security_result.detection_fields: Newly mapped alert.explanation.cnc-services.cnc-service.host, alert.id, alert.explanation.cnc-services.cnc-service.protocol, alert.explanation.cnc-services.cnc-service.port, alert.explanation.cnc-services.cnc-service.address, alert.explanation.cnc-services.cnc-service.channel, alert.explanation.cnc-services.cnc-service.sid, alert.interface.mode, alert.interface.label, alert.interface.interface, alert.explanation.malware-detected.malware.sid, alert.explanation.cnc-services.cnc-service.type, alert.explanation.cnc-services.cnc-service.sname and alert.ack raw log fields with event.idm.read_only_udm.security_result.detection_fields UDM fields.- event.idm.read_only_udm.additional.fields: Newly mapped entry.data.appliance-id, alert.explanation.events.occurred, alert.explanation.events.details.payload, alert.explanation.events.vlan, alert.explanation.events.protocol, alert.explanation.events.details.app_data.payload_app, alert.explanation.events.details.app_data.service_app, alert.explanation.events.details.app_data.payload_app_id, alert.explanation.events.details.app_data.service_app_id, alert.explanation.events.details.workstation, alert.sc-version, alert.src.vlan, msg, alert.attack-time, alert.root-infection, alert.sensor, alert.sensor-ip, Accept-Encoding, Connection, Accept-Language, Content-Type and spring.cloud.function.routing-expression raw log fields with event.idm.read_only_udm.additional.fields UDM fields.- event.idm.read_only_udm.target.resource.attribute.labels: Newly mapped Host raw log field with event.idm.read_only_udm.target.resource.attribute.labels UDM field.
|
| 2026-07-06 |
Enhancement: - event.idm.read_only_udm.metadata.product_event_type: Newly mapped event_name log field with event.idm.read_only_udm.metadata.product_event_type UDM field.- event.idm.read_only_udm.additional.fields: Newly mapped device_event_class_id log field with event.idm.read_only_udm.additional.fields UDM field.
|
| 2026-06-28 |
Enhancement: - Added grok pattern to parse new log format. - event.idm.read_only_udm.security_result.description: Newly mapped alert_tag_1 raw log field with event.idm.read_only_udm.security_result.description UDM field.- event.idm.read_only_udm.about.file.mime_type: Newly mapped alert.explanation.malware-detected.malware.type raw log field with event.idm.read_only_udm.about.file.mime_type UDM field.- event.idm.read_only_udm.about.file.md5: Newly mapped alert.explanation.malware-detected.malware.md5sum raw log field with event.idm.read_only_udm.about.file.md5 UDM field.- event.idm.read_only_udm.additional.fields: Newly mapped alert.explanation.malware-detected.malware.submitted-at, alert.explanation.malware-detected.malware.executed-at, alert.attack-time raw log fields with event.idm.read_only_udm.additional.fields UDM field.- event.idm.read_only_udm.security_result.detection_fields: Newly mapped alert.explanation.malware-detected.malware.profile, alert.explanation.malware-detected.malware.malicious, alert.explanation.malware-detected.malware.original raw log fields with event.idm.read_only_udm.security_result.detection_fields UDM field.
|
| 2026-05-29 |
Enhancement: - event.idm.read_only_udm.metadata.description: Newly mapped body, description raw log fields with event.idm.read_only_udm.metadata.description UDM field.- event.idm.read_only_udm.target.application: Newly mapped alert.explanation.target-application raw log field with event.idm.read_only_udm.target.application UDM field.- event.idm.read_only_udm.target.platform: Newly mapped alert.explanation.target-os raw log field with event.idm.read_only_udm.target.platform UDM field.- event.idm.read_only_udm.security_result.detection_fields: Newly mapped alert.explanation.malware-detected.malware.content, alert.explanation.malware-detected.malware.stype, alert.explanation.malware-detected.malware.sid, alert.explanation.analysis, alert.explanation.cnc-services.cnc-service.sid, alert.explanation.cnc-services.cnc-service.sname, alert.explanation.cnc-services.cnc-service.type raw log fields with event.idm.read_only_udm.security_result.detection_fields UDM field.- event.idm.read_only_udm.metadata.event_timestamp: Newly mapped timestamp raw log field with event.idm.read_only_udm.metadata.event_timestamp UDM field.- event.idm.read_only_udm.principal.process.file.full_path: Newly mapped principal_process_full_path raw log field with event.idm.read_only_udm.principal.process.file.full_path UDM field.- event.idm.read_only_udm.network.ip_protocol: Newly mapped alert.explanation.protocol, transport raw log fields with event.idm.read_only_udm.network.ip_protocol UDM field.- event.idm.read_only_udm.principal.hostname, event.idm.read_only_udm.principal.asset.hostname: Newly mapped alert.src.host, attributes.net.peer.name, principal_hostname raw log fields with event.idm.read_only_udm.principal.hostname and event.idm.read_only_udm.principal.asset.hostname UDM fields.- event.idm.read_only_udm.about.hostname, event.idm.read_only_udm.about.asset.hostname: Newly mapped alert.explanation.cnc-services.cnc-service.address raw log field with event.idm.read_only_udm.about.hostname and event.idm.read_only_udm.about.asset.hostname UDM fields when not an IP address.- event.idm.read_only_udm.about.ip, event.idm.read_only_udm.about.asset.ip: Newly mapped alert.explanation.cnc-services.cnc-service.address raw log field with event.idm.read_only_udm.about.ip and event.idm.read_only_udm.about.asset.ip UDM fields when a valid IP address.- event.idm.read_only_udm.about.port: Newly mapped alert.explanation.cnc-services.cnc-service.port raw log field with event.idm.read_only_udm.about.port UDM field.- event.idm.read_only_udm.security_result.threat_name: Newly mapped alert.explanation.malware-detected.malware.name raw log field with event.idm.read_only_udm.security_result.threat_name UDM field.- event.idm.read_only_udm.intermediary.ip: Newly mapped net_host_ip_parsed raw log field with event.idm.read_only_udm.intermediary.ip UDM field.- event.idm.read_only_udm.intermediary.platform: Newly mapped resource_attributes.os.type raw log field with event.idm.read_only_udm.intermediary.platform UDM field.- event.idm.read_only_udm.intermediary.hostname: Newly mapped attributes.net.host.name, resource_attributes.host.name raw log fields with event.idm.read_only_udm.intermediary.hostname UDM field.- event.idm.read_only_udm.intermediary.port: Newly mapped attributes.net.host.port raw log field with event.idm.read_only_udm.intermediary.port UDM field.- event.idm.read_only_udm.principal.port: Newly mapped attributes.net.peer.port raw log field with event.idm.read_only_udm.principal.port UDM field when alert.src.port is not a number and event.idm.read_only_udm.principal.port is not mapped.- event.idm.read_only_udm.principal.ip, event.idm.read_only_udm.principal.asset.ip: Newly mapped net_peer_ip_parsed raw log field with event.idm.read_only_udm.principal.ip and event.idm.read_only_udm.principal.asset.ip UDM fields.- event.idm.read_only_udm.additional.fields: Newly mapped alert_tag, alert.sc-version, msg, attributes.log_type, rawmsg.dns.tx_id, rawmsg.dns.type, rawmsg.flow_id, rawmsg.iface, rawmsg.session_key, attributes.net.peer.name, attributes.net.peer.port, alert.explanation.cnc-services.cnc-service.protocol, alert.explanation.cnc-services.cnc-service.channel, alert.explanation.service, alert.explanation.urls raw log fields with event.idm.read_only_udm.additional.fields UDM field.
|
| 2026-04-20 |
Enhancement: - event.idm.read_only_udm.about.file.full_path: Removed mapping of filePath raw log field from event.idm.read_only_udm.about.file.full_path UDM field as filePath field corresponds to target details.- event.idm.read_only_udm.target.file.full_path: Mapped filePath raw log field with event.idm.read_only_udm.target.file.full_path UDM field.- event.idm.read_only_udm.about.file.mime_type: Removed mapping of fileType raw log field from event.idm.read_only_udm.about.file.mime_type UDM field as fileType field corresponds to target details.- event.idm.read_only_udm.target.file.mime_type: Mapped fileType raw log field with event.idm.read_only_udm.target.file.mime_type UDM field.- event.idm.read_only_udm.about.file.size: Removed mapping of fsize raw log field from event.idm.read_only_udm.about.file.size UDM field as fsize field corresponds to target details.- event.idm.read_only_udm.target.file.size: Mapped fsize raw log field with event.idm.read_only_udm.target.file.size UDM field.- event.idm.read_only_udm.about.file.sha256: Removed mapping of fileHash raw log field from event.idm.read_only_udm.about.file.sha256 UDM field as fileHash field corresponds to target details.- event.idm.read_only_udm.target.file.md5: Mapped fileHash raw log field with event.idm.read_only_udm.target.file.md5 UDM field if fileHash is an MD5 hash.- event.idm.read_only_udm.target.file.sha256: Mapped fileHash raw log field with event.idm.read_only_udm.target.file.sha256 UDM field if fileHash is a SHA256 hash.- event.idm.read_only_udm.additional.fields: Removed mapping of fname raw log field from event.idm.read_only_udm.additional.fields UDM field as fname field corresponds to target details.- event.idm.read_only_udm.target.file.names: Mapped fname raw log field with event.idm.read_only_udm.target.file.names UDM field.- event.idm.read_only_udm.additional.fields: Removed mapping of flexString1 raw log field from event.idm.read_only_udm.additional.fields UDM field as flexString1 field corresponds to target details.- event.idm.read_only_udm.target.file.sha256: Mapped flexString1 raw log field with event.idm.read_only_udm.target.file.sha256 UDM field if flexString1 is a SHA256 hash.- event.idm.read_only_udm.additional.fields: Newly mapped device_vendor raw log field with event.idm.read_only_udm.additional.fields UDM field.- Added a grok pattern on temp_data to extract Type.
|
| 2026-03-31 |
Enhancement: - event.idm.read_only_udm.metadata.product_name: Removed mapping of product, entry.data.product, device_product and _source.alert_product raw log fields from event.idm.read_only_udm.metadata.product_name UDM as we are mapping a static value (NX) across all events.- event.idm.read_only_udm.metadata.product_name: Mapped NX static value to event.idm.read_only_udm.metadata.product_name UDM field.- event.idm.read_only_udm.additional.fields: Mapped product, entry.data.product, device_product and _source.alert_product raw log fields with event.idm.read_only_udm.additional.fields UDM field.
|
| 2026-03-27 |
Enhancement: - event.idm.read_only_udm.additional.fields: Removed mapping of cs5 (where cs5Label is cncHost) from event.idm.read_only_udm.additional.fields UDM field, because this data more appropriately belongs in the specific fields within the event.idm.read_only_udm.target UDM noun, depending on whether cs5 contains an IP address or a hostname.- event.idm.read_only_udm.target.hostname and event.idm.read_only_udm.target.asset.hostname: Mapped cs5 raw log field with event.idm.read_only_udm.target.hostname and event.idm.read_only_udm.target.asset.hostname UDM fields, moving it from additional fields for better UDM alignment when it represents a hostname.- event.idm.read_only_udm.target.ip and event.idm.read_only_udm.target.asset.ip: Mapped cs5 raw log field with event.idm.read_only_udm.target.ip and event.idm.read_only_udm.target.asset.ip UDM fields, as this field now correctly represents the destination Command and Control host's IP address within the target noun, rather than a generic additional field.- event.idm.read_only_udm.about.hostname: Removed mapping of dvchost from event.idm.read_only_udm.about.hostname UDM field, because the device is better represented as an intermediary device.- event.idm.read_only_udm.intermediary.hostname and event.idm.read_only_udm.intermediary.asset.hostname: Mapped dvchost raw log field with event.idm.read_only_udm.intermediary.hostname and event.idm.read_only_udm.intermediary.asset.hostname UDM fields, as this more accurately represents the device's role.- event.idm.read_only_udm.about.ip: Removed mapping of dvc from event.idm.read_only_udm.about.ip UDM field, because the device is better represented as an intermediary device.- event.idm.read_only_udm.intermediary.ip and event.idm.read_only_udm.intermediary.asset.ip: Mapped dvc raw log field with event.idm.read_only_udm.intermediary.ip and event.idm.read_only_udm.intermediary.asset.ip UDM fields,when it is a valid IP address, as this more accurately represents the device's role.- event.idm.read_only_udm.about.mac: Removed mapping of dvcmac from event.idm.read_only_udm.about.mac UDM field, because the device is better represented as an event.idm.read_only_udm.intermediary device.- event.idm.read_only_udm.intermediary.mac and event.idm.read_only_udm.intermediary.asset.mac: Mapped dvcmac raw log field with event.idm.read_only_udm.intermediary.mac and event.idm.read_only_udm.intermediary.asset.mac UDM fields, as this more accurately represents the device's role.
|
| 2026-03-05 |
Enhancement: - event.idm.read_only_udm.metadata.product_name: Mapping static value (NX) to event.idm.read_only_udm.metadata.product_name UDM field when event.idm.read_only_udm.metadata.product_name is empty.- event.idm.read_only_udm.network.received_bytes: Newly mapped rawmsg.dcerpc.response_stub_data_len raw log field with event.idm.read_only_udm.network.received_bytes UDM field.- event.idm.read_only_udm.network.sent_bytes: Newly mapped rawmsg.dcerpc.request_stub_data_len raw log field with event.idm.read_only_udm.network.sent_bytes UDM field.- event.idm.read_only_udm.target.resource.attribute.labels: Newly mapped rawmsg.dcerpc.interface.uuid, rawmsg.dcerpc.interface.version, and rawmsg.dcerpc.interface.minor-version raw log fields with event.idm.read_only_udm.target.resource.attribute.labels UDM field.- event.idm.read_only_udm.additional.fields: Newly mapped rawmsg.dcerpc.request_stub_data (key: dcerpc_request_stub_data), rawmsg.dcerpc.response_stub_data (key: dcerpc_response_stub_data), and rawmsg.dcerpc.opnum (key: dcerpc_opnum) raw log fields with event.idm.read_only_udm.additional.fields UDM field.
|
| 2026-02-26 |
Enhancement: - event.idm.read_only_udm.security_result.rule_id: If cn2Label is signatureId or sid, set the value of event.idm.read_only_udm.security_result.rule_id with the value of cn2 raw log field.- event.idm.read_only_udm.security_result.rule_name: If cs1Label is sname, set the value of event.idm.read_only_udm.security_result.rule_name with the value of cs1 raw log field.- event.idm.read_only_udm.target.url: If cs4Lablel is link, set the value of event.idm.read_only_udm.target.url with the value of cs4 raw log field.- Added support for a nested JSON format within the raw message. - event.idm.read_only_udm.metadata.event_timestamp: Newly mapped rawmsg.timestamp raw log field with event.idm.read_only_udm.metadata.event_timestamp UDM field.- event.idm.read_only_udm.metadata.product_event_type: Newly mapped rawmsg.event_type raw log field with event.idm.read_only_udm.metadata.product_event_type UDM field.- event.idm.read_only_udm.principal.ip: Newly mapped rawmsg.src_ip raw log field with event.idm.read_only_udm.principal.ip UDM field.- event.idm.read_only_udm.principal.asset.ip: Newly mapped rawmsg.src_ip raw log field with event.idm.read_only_udm.principal.asset.ip UDM field.- event.idm.read_only_udm.principal.port: Newly mapped rawmsg.src_port raw log field with event.idm.read_only_udm.principal.port UDM field.- event.idm.read_only_udm.target.ip: Newly mapped rawmsg.dest_ip raw log field with event.idm.read_only_udm.target.ip UDM field.- event.idm.read_only_udm.target.asset.ip: Newly mapped rawmsg.dest_ip raw log field with event.idm.read_only_udm.target.asset.ip UDM field.- event.idm.read_only_udm.target.port: Newly mapped rawmsg.dest_port raw log field with event.idm.read_only_udm.target.port UDM field.- event.idm.read_only_udm.network.ip_protocol: Newly mapped rawmsg.proto raw log field with event.idm.read_only_udm.network.ip_protocol UDM field.- event.idm.read_only_udm.network.dns.id: Newly mapped rawmsg.dns.id raw log field with event.idm.read_only_udm.network.dns.id UDM field.- event.idm.read_only_udm.network.dns.questions.name: Newly mapped rawmsg.dns.rrname raw log fields with event.idm.read_only_udm.network.dns.questions.name UDM field.- event.idm.read_only_udm.network.dns.questions.type: Newly mapped rawmsg.dns.rrtype raw log field with event.idm.read_only_udm.network.dns.questions.type UDM field.- event.idm.read_only_udm.additional.fields: Newly mapped rawmsg.dns.tx_id (key: dns_tx_id), rawmsg.dns.type (key: dns_type), rawmsg.flow_id (key: flow_id), rawmsg.iface (key: iface), rawmsg.session_key (key: session_key), meta_oml (key: meta_oml), cn2Lablel (key: signature_id), cn4Lablel (key: link) raw log fields with event.idm.read_only_udm.additional.fields UDM field.- event.idm.read_only_udm.intermediary.ip: Newly mapped meta_sip4 raw log field with event.idm.read_only_udm.intermediary.ip UDM field.- event.idm.read_only_udm.target.asset_id: Newly mapped deviceid raw log field with event.idm.read_only_udm.target.asset_id UDM field.- event.idm.read_only_udm.target.asset.asset_id: Newly mapped deviceid raw log field with event.idm.read_only_udm.target.asset.asset_id UDM field.- event.idm.read_only_udm.intermediary.hostname: Newly mapped meta_cbname raw log field with event.idm.read_only_udm.intermediary.hostname UDM field.- event.idm.read_only_udm.intermediary.asset.hostname: Newly mapped meta_cbname raw log field with event.idm.read_only_udm.intermediary.asset.hostname UDM field.- event.idm.read_only_udm.network.application_protocol: Setting the value of event.idm.read_only_udm.network.application_protocol to DNS when network DNS data is present.- event.idm.read_only_udm.security_result.detection_fields: Newly mapped entry.data.alert.explanation.malware-detected.malware.stype (key: malware_stype) raw log field with event.idm.read_only_udm.security_result.detection_fields UDM field.- event.idm.read_only_udm.metadata.event_type:- Setting the value of event.idm.read_only_udm.metadata.event_type to NETWORK_DNS when network DNS data is present.- Modified conditional logic for setting event.idm.read_only_udm.metadata.event_type to SCAN_UNCATEGORIZED and NETWORK_CONNECTION.
|
| 2026-01-01 |
Enhancement: - event.idm.read_only_udm.network.application_protocol: Removed mapping where event.idm.read_only_udm.network.application_protocol was set to HTTP based on the raw log field message since the logic is too broad and improperly sets application_protocol to HTTP based on unrelated string matches.- The raw field entry.data.alert.occurred is now aliased to alert_occurred before being used in the date filter.- The raw field entry.data.alert.name is now aliased to alert_name before being used for sec_category and product_event_type.- event.idm.read_only_udm.metadata.event_type: If has_http is true and (has_principal_host is true or has_principal_ip is true) and (has_target_host is true or has_target_ip is true) OR (src is not empty and dst is not empty and has_http is true) OR has_http is true, updated to NETWORK_HTTP.- event.idm.read_only_udm.network.application_protocol: Newly mapped HTTP to event.idm.read_only_udm.network.application_protocol when the event type is determined to be NETWORK_HTTP.- event.idm.read_only_udm.metadata.product_name: Newly mapped product raw log field with event.idm.read_only_udm.metadata.product_name UDM field.- event.idm.read_only_udm.security_result.action_details: Newly mapped alert.action raw log field with event.idm.read_only_udm.security_result.action_details UDM field.- event.idm.read_only_udm.additional.fields: Newly mapped alert.vlan, version raw log fields with event.idm.read_only_udm.additional.fields UDM field.- event.idm.read_only_udm.security_result.detection_fields: Newly mapped alert.explanation.ips-detected.action-taken, alert.explanation.ips-detected.signature-name, alert.interface.interface, alert.interface.label raw log fields with event.idm.read_only_udm.security_result.detection_fields UDM field.
|
| 2025-12-31 |
Enhancement: - event.idm.read_only_udm.principal.port: Newly mapped alert.src.port raw log field with event.idm.read_only_udm.principal.port UDM field.- event.idm.read_only_udm.principal.ip and event.idm.read_only_udm.principal.asset.ip: Newly mapped alert.src.ip raw log field with event.idm.read_only_udm.principal.ip and event.idm.read_only_udm.principal.asset.ip UDM field.- event.idm.read_only_udm.principal.mac and event.idm.read_only_udm.principal.asset.mac: Newly mapped alert.src.mac raw log field with event.idm.read_only_udm.principal.mac and event.idm.read_only_udm.principal.asset.mac UDM field.- event.idm.read_only_udm.target.ip and event.idm.read_only_udm.target.asset.ip: Newly mapped alert.dst.ip, event_item.dst_ip raw log fields with event.idm.read_only_udm.target.ip and event.idm.read_only_udm.target.asset.ip UDM field.- event.idm.read_only_udm.target.port: Newly mapped alert.dst.port raw log field with event.idm.read_only_udm.target.port UDM field.- event.idm.read_only_udm.target.mac and event.idm.read_only_udm.target.asset.mac: Newly mapped alert.dst.mac raw log field with event.idm.read_only_udm.target.mac and event.idm.read_only_udm.target.asset.mac UDM fields.- event.idm.read_only_udm.security_result.rule_id: Newly mapped alert.signature_id, alert.id raw log fields with event.idm.read_only_udm.security_result.rule_id UDM field.- event.idm.read_only_udm.security_result.rule_name: Newly mapped alert.name raw log field with event.idm.read_only_udm.security_result.rule_name UDM field.- event.idm.read_only_udm.security_result.description: Newly mapped alert.description raw log field with event.idm.read_only_udm.security_result.description UDM field.- event.idm.read_only_udm.observer.hostname: Newly mapped appliance raw log field with event.idm.read_only_udm.observer.hostname UDM field.- event.idm.read_only_udm.metadata.event_timestamp: Newly mapped alert.occurred raw log field with event.idm.read_only_udm.metadata.event_timestamp UDM field.- event.idm.read_only_udm.additional.fields: Newly mapped appliance-id, alert.class, alert.count, event_item.id, event_item.sequence, event_item.src_port, event_item.dst_port, event_item.details.geo_org, event_item.details.ratio, alert.src.vlan, alert.root-infection, alert.ack raw log fields with event.idm.read_only_udm.additional.fields UDM field.- event.idm.read_only_udm.metadata.product_log_id: Newly mapped alert.uuid raw log field with event.idm.read_only_udm.metadata.product_log_id UDM field.- event.idm.read_only_udm.network.ip_protocol: Newly mapped alert.protocol raw log field with event.idm.read_only_udm.network.ip_protocol UDM field.- event.idm.read_only_udm.security_result.severity: Newly mapped alert.severity raw log field with event.idm.read_only_udm.security_result.severity UDM field.- event.idm.read_only_udm.security_result.url_back_to_product: Newly mapped alert.alert-url raw log field with event.idm.read_only_udm.security_result.url_back_to_product UDM field.- event.idm.read_only_udm.security_result.category_details: Newly mapped alert.category raw log field with event.idm.read_only_udm.security_result.category_details UDM field.- event.idm.read_only_udm.observer.ip: Newly mapped event_item.src_ip raw log field with event.idm.read_only_udm.observer.ip UDM field.- event.idm.read_only_udm.target.hostname and event.idm.read_only_udm.target.asset.hostname: Newly mapped event_item.details.dest_ip_resolved raw log field with event.idm.read_only_udm.target.hostname and event.idm.read_only_udm.target.asset.hostname UDM field.- event.idm.read_only_udm.network.session_duration.seconds: Newly mapped event_item.details.duration_seconds raw log field with event.idm.read_only_udm.network.session_duration.seconds UDM field.- event.idm.read_only_udm.network.received_bytes: Newly mapped event_item.details.inbound_mb raw log field with event.idm.read_only_udm.network.received_bytes UDM field.- event.idm.read_only_udm.network.sent_bytes: Newly mapped event_item.details.outbound_mb raw log field with event.idm.read_only_udm.network.sent_bytes UDM field.- event.idm.read_only_udm.security_result.summary: Newly mapped event_item.name raw log field with event.idm.read_only_udm.security_result.summary UDM field.- event.idm.read_only_udm.metadata.product_version: Newly mapped version raw log field with event.idm.read_only_udm.metadata.product_version UDM field.- event.idm.read_only_udm.metadata.event_type: If alert.class is SmartVision, updated to NETWORK_FLOW.
|
| 2025-08-13 |
Enhancement: - Modified mutate filter to handle escaped backslashes in the cs4 field. - event.idm.read_only_udm.security_result.first_discovered_time: Newly mapped start raw log field with event.idm.read_only_udm.security_result.first_discovered_time UDM field.- event.idm.read_only_udm.security_result.last_discovered_time: Newly mapped end raw log field with event.idm.read_only_udm.security_result.last_discovered_time UDM field.- event.idm.read_only_udm.about.mac: Added a regex validation to ensure dvc_mac values match a standard MAC address format before proceeding with parsing. This prevents invalid values from being merged into the about.mac field. - Modified the conditional logic for assigning security_result.action to ALLOW or BLOCK based on the value of the act raw field.
|
| 2025-06-05 |
Enhancement: - Added Grok patterns to parse the unparsed logs. - Added JSON block to support the new format of SYSLOG+JSON logs. - event.idm.read_only_udm.metadata.event_timestamp - Newly Mapped timestamp raw log field with event.idm.read_only_udm.metadata.event_timestamp UDM Field.- event.idm.read_only_udm. - Newly Mapped event_type raw log field with event.idm.read_only_udm.metadata.event_type UDM Field.- event.idm.read_only_udm.principal.user.userid - Newly Mapped user_name raw log field with event.idm.read_only_udm.principal.user.userid UDM Field.- event.idm.read_only_udm.principal.hostname and event.idm.read_only_udm.principal.asset.hostname - Newly Mapped hostname raw log field with event.idm.read_only_udm.principal.hostname and event.idm.read_only_udm.principal.asset.hostname UDM Field.- event.idm.read_only_udm.principal.user.userid - Newly Mapped user raw log field with event.idm.read_only_udm.principal.user.userid UDM Field.- event.idm.read_only_udm.target.ip and event.idm.read_only_udm.target.asset.ip - Newly Mapped dstip raw log field with event.idm.read_only_udm.target.ip and event.idm.read_only_udm.target.asset.ip UDM Field.- event.idm.read_only_udm.target.file.sha1 - Newly Mapped file_hash raw log field with event.idm.read_only_udm.target.file.sha1 UDM Field.- event.idm.read_only_udm.target.file.sha256 - Newly Mapped file_sha256 raw log field with event.idm.read_only_udm.target.file.sha256 UDM Field.- event.idm.read_only_udm.target.file.full_path - Newly Mapped file_name raw log field with event.idm.read_only_udm.target.file.full_path UDM Field.- event.idm.read_only_udm.target.file.size - Newly Mapped size raw log field with event.idm.read_only_udm.target.file.size UDM Field.- event.idm.read_only_udm.principal.port - Newly Mapped srcports raw log field with event.idm.read_only_udm.principal.port UDM Field.- event.idm.read_only_udm.target.file.mime_type - Newly Mapped file_type raw log field with event.idm.read_only_udm.target.file.mime_type UDM Field.- event.idm.read_only_udm.security_result.detection_fields - Newly Mapped file_id,ba_sid, reqid, conn_count, failed_conn_count, message_id, app_data.service_app_id, accept,, message_type, app_data.client_app_id, attackdir, oversize, smb, is_icap, ha_is_active, ha_is_mirror_traffic, is_vxlan, is_websocket and attack_time' raw log field with event.idm.read_only_udm.security_result.detection_fields UDM Field.- event.idm.read_only_udm.target.port - Newly Mapped dstports raw log field with event.idm.read_only_udm.target.port UDM Field.- event.idm.read_only_udm.primcipal.mac and event.idm.read_only_udm.principal.asset.mac - Newly Mapped src_mac raw log field with event.idm.read_only_udm.principal.mac and event.idm.read_only_udm.principal.asset.mac UDM Field.- event.idm.read_only_udm.target.mac and event.idm.read_only_udm.target.asset.mac - Newly Mapped dst_mac raw log field with event.idm.read_only_udm.target.mac and event.idm.read_only_udm.target.asset.mac UDM Field.- event.idm.read_only_udm.principal.application - Newly Mapped process raw log field with event.idm.read_only_udm.principal.application UDM Field.- event.idm.read_only_udm.network.ip_protocol - Newly Mapped protocol raw log field with event.idm.read_only_udm.network.ip_protocol UDM Field.- event.idm.read_only_udm.target.resource.attribute.labels - Newly Mapped db_action raw log field with event.idm.read_only_udm.target.resource.attribute.labels UDM Field.- event.idm.read_only_udm.principal.process.pid - Newly Mapped pid raw log field with event.idm.read_only_udm.principal.process.pid UDM Field.- event.idm.read_only_udm.additional.fields - Newly Mapped tid, sa_only, incomplete, clientapp, is_erspan, thread_pool, updated_meas_list, inserted_meas_list, insert_count, update_count, epoch_time, segment_date, request_message_id and ssl_decrypted raw log field with event.idm.read_only_udm.additional.fields UDM Field.- event.idm.read_only_udm.target.resource.name - Newly Mapped db_pool raw log field with event.idm.read_only_udm.target.resource.name UDM Field.- event.idm.read_only_udm.target.resource.product_object_id - Newly Mapped db_handler raw log field with event.idm.read_only_udm.target.resource.product_object_id UDM Field.- event.idm.read_only_udm.security_result.summary - Newly Mapped db_details raw log field with event.idm.read_only_udm.security_result.summary UDM Field.- event.idm.read_only_udm.security_result.severity - Newly Mapped log_level raw log field with event.idm.read_only_udm.security_result.severity UDM Field.- event.idm.read_only_udm.security_result.description - Newly Mapped log_message raw log field with event.idm.read_only_udm.security_result.description UDM Field.- event.idm.read_only_udm.target.process.command_line - Newly Mapped command_line raw log field with event.idm.read_only_udm.target.process.command_line UDM Field.- event.idm.read_only_udm.network.http.method - Newly Mapped http_method raw log field with event.idm.read_only_udm.network.http.method UDM Field.- event.idm.read_only_udm.target.url - Newly Mapped request_uri raw log field with event.idm.read_only_udm.target.url UDM Field.- event.idm.read_only_udm.network.http.referral_url - Newly Mapped http_referer raw log field with event.idm.read_only_udm.network.http.referral_url UDM Field.- event.idm.read_only_udm.principal.ip and event.idm.read_only_udm.principal.asset.ip - Newly Mapped srcip raw log field with event.idm.read_only_udm.principal.ip and event.idm.read_only_udm.principal.asset.ip UDM Field- event.idm.read_only_udm.network.http.user_agent - Newly Mapped user_agent raw log field with event.idm.read_only_udm.network.http.user_agent UDM Field.- event.idm.read_only_udm.target.port - Newly Mapped http_port raw log field with event.idm.read_only_udm.target.port UDM Field.- event.idm.read_only_udm.target.hostname and event.idm.read_only_udm.target.asset.hostname - Newly Mapped http_host' raw log field with event.idm.read_only_udm.target.hostname and event.idm.read_only_udm.target.asset.hostname` UDM Field.- event.idm.read_only_udm.network.received_bytes - Newly Mapped request_length raw log field with event.idm.read_only_udm.network.received_bytes UDM Field.- event.idm.read_only_udm.network.application_protocol_version - Newly Mapped http_version raw log field with event.idm.read_only_udm.network.application_protocol_version UDM Field.- event.idm.read_only_udm.target.process.file.full_path - Newly Mapped binary_path raw log field with event.idm.read_only_udm.target.process.file.full_path UDM Field.- event.idm.read_only_udm.target.resource.name - Newly Mapped resource_path raw log field with event.idm.read_only_udm.target.resource.name UDM Field.- event.idm.read_only_udm.target.user.userid - Newly Mapped target_user raw log field with event.idm.read_only_udm.target.user.userid UDM Field.- event.idm.read_only_udm.security_result.action - Newly Mapped log_message raw log field when it is nearly same as authorized to ALLOW and denied to BLOCK with event.idm.read_only_udm.security_result.action UDM Field.- event.idm.read_only_udm.intermediary.hostname and event.idm.read_only_udm.intermediary.asset.hostname - Newly Mapped incoming_peer_name raw log field with event.idm.read_only_udm.intermediary.hostname and event.idm.read_only_udm.intermediary.asset.hostname UDM Field.- event.idm.read_only_udm.network.session_id - Newly Mapped incoming_session_id and session_id raw log field with event.idm.read_only_udm.network.session_id UDM Field.- event.idm.read_only_udm.target.hostname and event.idm.read_only_udm.target.asset.hostname - Newly Mapped client raw log field with event.idm.read_only_udm.target.hostname and event.idm.read_only_udm.target.asset.hostname UDM Field.- event.idm.read_only_udm.principal.group_product_object_id - Newly Mapped group_id raw log field with event.idm.read_only_udm.principal.group_product_object_id UDM Field.- event.idm.read_only_udm.target.process.pid - Newly Mapped target_pid raw log field with event.idm.read_only_udm.target.process.pid UDM Field.
|
| 2024-10-17 |
Enhancement: - Added gsub for dvcmac to parse CEF pattern logs.
|
| 2024-10-10 |
Enhancement: - Added support for new pattern of CEF logs. |
| 2022-05-18 |
Enhancement - The newly ingested logs have been parsed and mapped to the following fields:_source.alert.attack-time mapped to metadata.ingested_timestamp._source.srcport mapped to principal.port._source.srcipv4 mapped to principal.ip._source.mac mapped to principal.mac._source.dstport mapped to target.port._source.dstipv4 mapped to target.ip._source.dstmac mapped to target.mac._source.alerturl mapped to metadata.url_back_to_product._source.alert_product mapped to metadata.product_name._source.alert_version mapped to metadata.product_version._source.eventlog mapped to metadata.product_name._source.virus mapped to security_result.threatname._source.url mapped to target.url._source.severity mapped to security_result.severity.__source.detect_rulematches mapped to security_result.rule_id._source.alert_deviceid mapped to principal.asset.asset_id._source.deviceid mapped to asset.asset_id._source.devicename mapped to target.asset.attribute.labels._source.domain mapped to target.hostname.entry.data.alert.mitre-mapping.code.id mapped to security_result.rule_id.entry.data.alert.mitre-mapping.code.name mapped to security_result.rule_name.entry.data.alert.dst.smtp-to mapped to network.email.to.entry.data.alert.severity mapped to security_result.severity._source.action mapped to security_result.action.
|