Change log for IMPERVA_SECURESPHERE
| Date | Changes |
|---|---|
| 2026-07-19 |
Enhancement: - event.idm.read_only_udm.intermediary.hostname: Removed mapping of inter_host from event.idm.read_only_udm.intermediary.hostname UDM field.- event.idm.read_only_udm.additional.fields: Newly mapped syslog_header_domain, Authorization, X-Office-Major-Version, X-FeatureVersion, Accept-Auth, X-MS-CookieUri-Requested, X-IDCRL_ACCEPTED raw log fields with event.idm.read_only_udm.additional.fields UDM field.
|
| 2026-07-08 |
Enhancement: - Added a grok pattern to support the new format of Syslog+KV(CEF) logs. - Modified the KV filters to parse the kv_data4 and kv_data2 fields.- event.idm.read_only_udm.observer.hostname: Newly mapped dvc raw log field with event.idm.read_only_udm.observer.hostname UDM field.
|
| 2026-06-25 |
Enhancement: - event.idm.read_only_udm.principal.hostname and event.idm.read_only_udm.principal.asset.hostname: Removed mapping of cs3 from event.idm.read_only_udm.principal.hostname and event.idm.read_only_udm.principal.asset.hostname UDM fields when cs3Label is ServiceName as this is a duplicate mapping.- event.idm.read_only_udm.network.http.user_agent and event.idm.read_only_udm.network.http.parsed_user_agent: Removed mapping of cs6 from event.idm.read_only_udm.network.http.user_agent and event.idm.read_only_udm.network.http.parsed_user_agent UDM fields as the cs6 field does not contain user agent data.- Added a KV filter to parse the cs6 raw log field.- event.idm.read_only_udm.security_result.summary: Removed mapping of msg from event.idm.read_only_udm.security_result.summary UDM field in order to introduce more accurate mapping.- event.idm.read_only_udm.security_result.threat_name: Mapped msg raw log field with event.idm.read_only_udm.security_result.threat_name UDM field.- event.idm.read_only_udm.network.http.method: Removed mapping of requestMethod and http.request.method from event.idm.read_only_udm.network.http.method UDM field when invalid http method is present.- event.idm.read_only_udm.target.application: Mapped cs3 raw log field with event.idm.read_only_udm.target.application UDM field when cs3Label is GeneralApplicationName.- event.idm.read_only_udm.network.http.user_agent: Newly mapped User-Agent raw log field with event.idm.read_only_udm.network.http.user_agent UDM field.- event.idm.read_only_udm.network.http.parsed_user_agent: Newly mapped User-Agent raw log field with event.idm.read_only_udm.network.http.parsed_user_agent UDM field.- event.idm.read_only_udm.network.http.referral_url: Newly mapped Referer raw log field with event.idm.read_only_udm.network.http.referral_url UDM field.- event.idm.read_only_udm.principal.asset.platform_software.platform: Newly mapped sec-ch-ua-platform raw log field with event.idm.read_only_udm.principal.asset.platform_software.platform UDM field.- event.idm.read_only_udm.target.hostname and event.idm.read_only_udm.target.asset.hostname: Newly mapped Host raw log field with event.idm.read_only_udm.target.hostname and event.idm.read_only_udm.target.asset.hostname UDM fields when Host field contains a hostname.- event.idm.read_only_udm.target.ip and event.idm.read_only_udm.target.asset.ip: Newly mapped Host raw log field with event.idm.read_only_udm.target.ip and event.idm.read_only_udm.target.asset.ip UDM fields when Host field contains an IP address.- event.idm.read_only_udm.additional.fields: Newly mapped Accept, Accept-Encoding, Accept-Language, Connection, DNT, Sec-Fetch-Dest, Sec-Fetch-Mode, Sec-Fetch-Site, Sec-Fetch-User, Upgrade-Insecure-Requests, sec-ch-ua, sec-ch-ua-mobile raw log fields with event.idm.read_only_udm.additional.fields UDM field.- event.idm.read_only_udm.metadata.event_type and event.idm.read_only_udm.network.application_protocol: Setting the value of event.idm.read_only_udm.metadata.event_type to NETWORK_HTTP and event.idm.read_only_udm.network.application_protocol to HTTP when principal machine details are present and target machine details are present and http details are present.
|
| 2026-06-21 |
Enhancement: - Added a grok pattern to parse the new format of logs. - event.idm.read_only_udm.observer.hostname: Newly mapped dvc raw log field with event.idm.read_only_udm.observer.hostname UDM field.- event.idm.read_only_udm.additional.fields: Newly mapped cs6, cs7 raw log fields with event.idm.read_only_udm.additional.fields UDM field.
|
| 2026-05-21 |
Enhancement: - Added a new grok pattern to parse the new SYSLOG_KV format logs.- event.idm.read_only_udm.metadata.event_timestamp: Newly mapped timestamp raw log field with event.idm.read_only_udm.metadata.event_timestamp UDM field.- event.idm.read_only_udm.additional.fields: Newly mapped externalId, deviceCustomDate1, flexString1, flexString2, flexString2Label, requestContext, flexNumber1, cn2 raw log fields with event.idm.read_only_udm.additional.fields UDM field.- event.idm.read_only_udm.metadata.product_log_id: Newly mapped cn1 raw log field with event.idm.read_only_udm.metadata.product_log_id UDM field when cn1Label is EventId.- event.idm.read_only_udm.observer.hostname: Newly mapped ad.host raw log field with event.idm.read_only_udm.observer.hostname UDM field.- event.idm.read_only_udm.network.http.method: Newly mapped requestMethod raw log field with event.idm.read_only_udm.network.http.method UDM field.- event.idm.read_only_udm.target.url: Newly mapped request raw log field with event.idm.read_only_udm.target.url UDM field.- event.idm.read_only_udm.security_result.summary: Newly mapped msg raw log field with event.idm.read_only_udm.security_result.summary UDM field.- event.idm.read_only_udm.network.received_bytes: Newly mapped flexNumber2 raw log field with event.idm.read_only_udm.network.received_bytes UDM field when flexNumber2Label is ResponseSize.- event.idm.read_only_udm.network.http.response_code: Newly mapped flexString2 raw log field with event.idm.read_only_udm.network.http.response_code UDM field when flexString2Label is ResponseCode.- event.idm.read_only_udm.network.http.user_agent: Newly mapped cs6 raw log field with event.idm.read_only_udm.network.http.user_agent UDM field when cs6Label is UserAgent.
|
| 2026-05-13 |
Enhancement: - Added a new grok pattern to parse the new format logs. - event.idm.read_only_udm.metadata.description: Newly mapped name raw log field with event.idm.read_only_udm.metadata.description UDM field.- event.idm.read_only_udm.additional.fields: Newly mapped cs2, cs3, cs4 raw log fields with event.idm.read_only_udm.additional.fields UDM field.- event.idm.read_only_udm.principal.user.userid: Newly mapped suser raw log field with event.idm.read_only_udm.principal.user.userid UDM field.- event.idm.read_only_udm.principal.user.user_display_name: Newly mapped login_user raw log fields with event.idm.read_only_udm.principal.user.user_display_name UDM field.- event.idm.read_only_udm.principal.ip and event.idm.read_only_udm.principal.asset.ip: Newly mapped princ_ip raw log field with event.idm.read_only_udm.principal.ip and event.idm.read_only_udm.principal.asset.ip UDM fields.- event.idm.read_only_udm.security_result.action:- If act contains none, set the value of event.idm.read_only_udm.security_result.action to ALLOW.- If act contains block, set the value of event.idm.read_only_udm.security_result.action to BLOCK.- event.idm.read_only_udm.security_result.rule_name: Newly mapped cs1 raw log field with event.idm.read_only_udm.security_result.rule_name UDM field when cs1Label is Policy.- event.idm.read_only_udm.security_result.description: Newly mapped cs5 raw log field with event.idm.read_only_udm.security_result.description UDM field.- event.idm.read_only_udm.metadata.vendor_name: Newly mapped device_vendor raw log field with event.idm.read_only_udm.metadata.vendor_name UDM field when both device_vendor and device_product raw log fields are not empty.- event.idm.read_only_udm.metadata.product_name: Newly mapped device_product raw log field with event.idm.read_only_udm.metadata.product_name UDM field when both device_vendor and device_product raw log fields are not empty.- event.idm.read_only_udm.metadata.event_type: Newly set the value of event.idm.read_only_udm.metadata.event_type to NETWORK_CONNECTION when both principal and target information are present.- event.idm.read_only_udm.metadata.event_type: Newly set the value of event.idm.read_only_udm.metadata.event_type to USER_UNCATEGORIZED when principal user related information is present.- event.idm.read_only_udm.metadata.event_type: Updated the value of event.idm.read_only_udm.metadata.event_type to USER_RESOURCE_ACCESS when the current event.idm.read_only_udm.metadata.event_type is not set and principal information is present.
|
| 2026-04-16 |
Enhancement: - event.idm.read_only_udm.additional.fields: Newly mapped descrip log field with event.idm.read_only_udm.additional.fields UDM field.- The gsub pattern for kv_data2 was updated to ensure correct key-value pair parsing.- Added gsub on message to remove field newline characters.
|
| 2026-03-22 |
Enhancement: - Modified a grok pattern to correctly parse logs where the product_type field contains spaces. Added a new test case to validate the change. Due to this change, the following UDM fields are now being mapped correctly: - event.idm.read_only_udm.metadata.description- event.idm.read_only_udm.metadata.event_timestamp.seconds- event.idm.read_only_udm.metadata.event_type- event.idm.read_only_udm.metadata.log_type- event.idm.read_only_udm.metadata.product_event_type- event.idm.read_only_udm.metadata.product_name- event.idm.read_only_udm.metadata.product_version- event.idm.read_only_udm.metadata.vendor_name- event.idm.read_only_udm.network.ip_protocol- event.idm.read_only_udm.principal.asset.hostname- event.idm.read_only_udm.principal.hostname- event.idm.read_only_udm.principal.asset.ip- event.idm.read_only_udm.principal.ip- event.idm.read_only_udm.principal.group.group_display_name- event.idm.read_only_udm.principal.port- event.idm.read_only_udm.security_result.action_details- event.idm.read_only_udm.security_result.category_details- event.idm.read_only_udm.security_result.rule_name- event.idm.read_only_udm.security_result.severity- event.idm.read_only_udm.security_result.severity_details- event.idm.read_only_udm.target.application- event.idm.read_only_udm.target.asset.ip- event.idm.read_only_udm.target.ip- event.idm.read_only_udm.target.port- event.idm.read_only_udm.target.resource.attribute.labels.key- event.idm.read_only_udm.target.resource.attribute.labels.value- event.idm.read_only_udm.target.user.userid
|
| 2025-11-05 |
Enhancement: - event.idm.read_only_udm.additional.fields: Newly mapped cs9, cs9Label raw log field(s) with event.idm.read_only_udm.additional.fields UDM field.- Added on_error for rt. - Modified the date filter to add support for the ISO8601 date format for the rt raw log field. - Modified conditional logic to process cs9 and cs9Label fields independently of the cs8 and cs8Label fields. |
| 2025-10-31 |
Enhancement: - event.idm.read_only_udm.metadata.product_log_id: Newly mapped cs5 raw log field to event.idm.read_only_udm.metadata.product_log_id when cs5Label is EventId.- event.idm.read_only_udm.principal.application: Newly mapped cs10 raw log field to event.idm.read_only_udm.principal.application when cs10Label is SourceApplication.- event.idm.read_only_udm.principal.application: Newly mapped app raw log field to event.idm.read_only_udm.principal.application.- event.idm.read_only_udm.principal.user.userid: Newly mapped cs11 raw log field to event.idm.read_only_udm.principal.user.userid when cs11Label is OSUser.- event.idm.read_only_udm.principal.user.userid: Newly mapped osUser raw log field to event.idm.read_only_udm.principal.user.userid.- event.idm.read_only_udm.principal.hostname: Newly mapped cs12 raw log field to event.idm.read_only_udm.principal.hostname when cs12Label is HostName.- event.idm.read_only_udm.principal.asset.hostname: Newly mapped cs12 raw log field to event.idm.read_only_udm.principal.asset.hostname when cs12Label is HostName.- event.idm.read_only_udm.target.resource.attribute.labels: Newly mapped cs3 raw log field to event.idm.read_only_udm.target.resource.attribute.labels with key ServiceName when cs3Label is ServiceName.- event.idm.read_only_udm.principal.user.user_display_name: Newly mapped suser raw log field to event.idm.read_only_udm.principal.user.user_display_name.- event.idm.read_only_udm.target.resource.name: Newly mapped cs13 raw log field to event.idm.read_only_udm.target.resource.name when cs13Label is Database.- event.idm.read_only_udm.target.resource.name: Newly mapped dbName raw log field to event.idm.read_only_udm.target.resource.name.- event.idm.read_only_udm.target.resource.resource_type: Newly mapped cs13 raw log field to event.idm.read_only_udm.target.resource.resource_type (set to DATABASE) when cs13Label is Database.- event.idm.read_only_udm.target.resource.resource_type: Newly mapped dbName raw log field to event.idm.read_only_udm.target.resource.resource_type (set to DATABASE).- event.idm.read_only_udm.additional.fields: Newly mapped cs18 (with key from cs18Label), cs19 (with key from cs19Label), cs20 (with key from cs20Label), cs21 (with key from cs21Label) raw log fields to event.idm.read_only_udm.additional.fields. Also mapped cs5 raw log field to event.idm.read_only_udm.additional.fields with key RawDBQuery when cs5Label is RawDBQuery.- event.idm.read_only_udm.principal.ip: Newly mapped shost raw log field to event.idm.read_only_udm.principal.ip.- event.idm.read_only_udm.principal.asset.ip: Newly mapped shost raw log field to event.idm.read_only_udm.principal.asset.ip.- event.idm.read_only_udm.network.sent_bytes: Newly mapped bytesOut raw log field to event.idm.read_only_udm.network.sent_bytes.- event.idm.read_only_udm.target.process.command_line: Newly mapped cs4 raw log field to event.idm.read_only_udm.target.process.command_line when cs4Label is DBQuery.- event.idm.read_only_udm.security_result.action: Newly mapped isAuthenticated raw log field to event.idm.read_only_udm.security_result.action (set to ALLOW) when isAuthenticated is True.- event.idm.read_only_udm.target.resource.attribute.labels: Newly mapped dbSchema raw log field to event.idm.read_only_udm.target.resource.attribute.labels with key dbSchema.- event.idm.read_only_udm.target.resource.attribute.labels: Newly mapped dbBindVariables raw log field to event.idm.read_only_udm.target.resource.attribute.labels with key dbBindVariables.- Updated event.idm.read_only_udm.metadata.event_type to USER_LOGIN for logs where descrip contains SQL protocol and message contains login.
|
| 2025-10-17 |
Enhancement: - event.idm.read_only_udm.security_result.rule_id: Newly mapped ruleid raw log field to event.idm.read_only_udm.security_result.rule_id UDM field.- event.idm.read_only_udm.additional.fields: Newly mapped cs3, deviceCustomDate1, cs8, cs9, cs10, cs11, cs13, cs4 raw log fields to event.idm.read_only_udm.additional.fields UDM field.- event.idm.read_only_udm.principal.ip: Newly mapped src raw log field to event.idm.read_only_udm.principal.ip UDM field.- event.idm.read_only_udm.principal.asset.ip: Newly mapped src raw log field to event.idm.read_only_udm.principal.asset.ip UDM field.- event.idm.read_only_udm.principal.user.userid: Newly mapped cs5 raw log field to event.idm.read_only_udm.principal.user.userid UDM field.- event.idm.read_only_udm.target.application: Newly mapped cs6 raw log field to event.idm.read_only_udm.target.application UDM field.- event.idm.read_only_udm.target.ip: Newly mapped dst raw log field to event.idm.read_only_udm.target.ip UDM field.- event.idm.read_only_udm.target.asset.ip: Newly mapped dst raw log field to event.idm.read_only_udm.target.asset.ip UDM field.- event.idm.read_only_udm.security_result.summary: Newly mapped cs7 raw log field to event.idm.read_only_udm.security_result.summary UDM field.- event.idm.read_only_udm.target.resource.attribute.labels: Newly mapped cs12 raw log field to event.idm.read_only_udm.target.resource.attribute.labels UDM field.- event.idm.read_only_udm.network.sent_bytes: Newly mapped cn1 raw log field to event.idm.read_only_udm.network.sent_bytes UDM field.- event.idm.read_only_udm.principal.port: Newly mapped cn2 raw log field to event.idm.read_only_udm.principal.port UDM field.- event.idm.read_only_udm.target.port: Newly mapped cn3 raw log field to event.idm.read_only_udm.target.port UDM field.- Added logic to set metadata.event_type to NETWORK_CONNECTION, USER_UNCATEGORIZED, STATUS_UPDATE, or GENERIC_EVENT based on the presence of principal, target, and user information for the new log format.- Added grok patterns to parse new pattern of syslog logs. |
| 2025-07-18 |
Enhancement: - Added mappings for cs7 and cs11 raw log fields globally.- Modified the condition to map cs12 raw log field to security_result.description UDM field when cs12Label is not OSUser.- Modified the condition to map cs17 raw log field to event.idm.read_only_udm.target.resource.resource_subtype UDM field when cs17Label is not Error.- event.idm.read_only_udm.target.resource.attribute.labels: Newly mapped cs17 raw log field with event.idm.read_only_udm.target.resource.attribute.labels UDM field when cs17Label is Error.
|
| 2025-07-03 |
Enhancement: - Added Grok patterns to support new pattern of syslog logs. - event.idm.read_only_udm.additional.fields: Newly mapped cs2, cs2Label, and additional_json_data raw log fields with event.idm.read_only_udm.additional.fields UDM field when cs2Label is ServerGroup.- event.idm.read_only_udm.target.application: Newly mapped cs5 raw log field with event.idm.read_only_udm.target.application UDM field when cs5Label is ApplicationName.- event.idm.read_only_udm.target.resource.attribute.labels: Newly mapped cs4 raw log field with event.idm.read_only_udm.target.resource.attribute.labels UDM field when cs4Label is ServiceName.- event.idm.read_only_udm.principal.application: Newly mapped cs6 raw log field with event.idm.read_only_udm.principal.application UDM field when cs11Label is SrcApp.- event.idm.read_only_udm.security_result.description: Newly mapped cs7 raw log field with event.idm.read_only_udm.security_result.description UDM field when cs7Label is AlertDesc.- event.idm.read_only_udm.target.resource.name: Newly mapped cs11 raw log field with event.idm.read_only_udm.target.resource.name UDM field when cs11Label is DatabaseName.- event.idm.read_only_udm.target.resource.resource_type: Newly mapped DATABASE with event.idm.read_only_udm.target.resource.resource_type UDM field when cs11Label is DatabaseName.- event.idm.read_only_udm.metadata.product_log_id: Newly mapped cs10 raw log field with event.idm.read_only_udm.metadata.product_log_id UDM field when cs10Label is EventID.- event.idm.read_only_udm.target.resource.attribute.labels: Newly mapped cs15 raw log field with event.idm.read_only_udm.target.resource.attribute.labels UDM field when cs15Label is not ViolatedItem.- event.idm.read_only_udm.security_result.threat_id: Newly mapped cs9 raw log field with event.idm.read_only_udm.security_result.threat_id UDM field when cs9Label is AlertID.- event.idm.read_only_udm.principal.user.userid: Newly mapped cs12 raw log field with event.idm.read_only_udm.principal.user.userid UDM field when cs12Label is OSUser- event.idm.read_only_udm.intermediary.hostname: Newly mapped inter_host raw log field with event.idm.read_only_udm.intermediary.hostname UDM field.- event.idm.read_only_udm.principal.hostname: Newly mapped cs13 raw log field with event.idm.read_only_udm.principal.hostname UDM field when cs13Label is HostName.- Modified condition such that cs2 raw log field is mapped to event.idm.read_only_udm.principal.group.group_display_name when cs2Label is ServerGroup.- Modified condition such that cs4 raw log field is mapped to event.idm.read_only_udm.target.application UDM field when cs4Label is ApplicationName.- Modified condition such that cs5 raw log field is mapped to event.idm.read_only_udm.metadata.description UDM field when cs5Label is Description.- Modified condition such that cs15 raw log field is mapped to security_result.summary UDM field when cs15Label is ViolatedItem.- Modified condition such that cs9 raw log field is mapped to event.idm.read_only_udm.principal.user.userid UDM field when cs9Label is osUser.- Modified condition such that cs8 raw log field is mapped to event.idm.read_only_udm.target.resource.name UDM field when cs8Label is DatabaseName or ApplicationName.
|
| 2024-04-01 |
Enhancement - - Added support for JSON logs. |
| 2023-04-26 |
Enhancement - - Mapped cs1 to security_result.rule_name.- Mapped cs2 to principal.group.group_display_name.- Mapped cs3 to principal.hostname.- Mapped cs6 to target.resource_ancestors.name.- Mapped cs7 to target.resource_ancestors.resource_subtype.- Mapped cs5 to metadata.description.- Mapped cs12 to security_result.description.- Mapped cs14 to target.resource.attribute.labels.- Mapped cs15 to security_result.summary.- Mapped cs16 to principal.process.command_line.- Mapped cs17 to target.resource.resource_subtype.- Parsed severity field.- Mapped act to security_result.action_details.- Mapped cs13 to metadata.product_log_id.
|
| 2022-07-24 |
Enhancement - - Mapped proto to network.ip_protocol.- Mapped severity to security_result.severity_details.- Mapped cs1Label to security_result.detection_fields.- Mapped cs2Label to security_result.detection_fields.- Mapped cs3Label to security_result.detection_fields.- Mapped cs4 to target.application.- Mapped cs5Label to security_result.detection_fields.- Mapped cs8 to target.resource.name.- Mapped cs9 to principal.user.userid.- Mapped cs10Label to additional.fields.- Mapped cs11 to principal.application.- Mapped cs12Label to additional.fields.- Mapped cs13Label to additional.fields.- Mapped cs14Label to additional.fields.- Mapped cs16Label to additional.fields.- Mapped cs17Label to additional.fields.
|