Change log for SECUREAUTH_SSO
| Date | Changes |
|---|---|
| 2026-04-20 |
Enhancement: - Added support for JSON+KV log formats. - event.idm.read_only_udm.metadata.collected_timestamp: Newly mapped _timestamp raw log field with event.idm.read_only_udm.metadata.collected_timestamp UDM field.- event.idm.read_only_udm.intermediary.ip: Newly mapped i_ip raw log field with event.idm.read_only_udm.intermediary.ip UDM field.- event.idm.read_only_udm.intermediary.port: Newly mapped i_port raw log field with event.idm.read_only_udm.intermediary.port UDM field.- event.idm.read_only_udm.metadata.product_event_type: Newly mapped parsed.LogChannel raw log field with event.idm.read_only_udm.metadata.product_event_type UDM field.- event.idm.read_only_udm.metadata.product_version: Newly mapped parsed.FormatVersion raw log field with event.idm.read_only_udm.metadata.product_version UDM field.- event.idm.read_only_udm.metadata.product_log_id: Newly mapped parsed.EventID raw log field with event.idm.read_only_udm.metadata.product_log_id UDM field.- event.idm.read_only_udm.principal.resource.product_object_id: Newly mapped parsed.CompanyID raw log field with event.idm.read_only_udm.principal.resource.product_object_id UDM field.- event.idm.read_only_udm.principal.resource.name: Newly mapped parsed.Realm raw log field with event.idm.read_only_udm.principal.resource.name UDM field.- event.idm.read_only_udm.principal.ip: Newly mapped parsed.UserHostAddress raw log field with event.idm.read_only_udm.principal.ip UDM field.- event.idm.read_only_udm.principal.asset.ip: Newly mapped parsed.UserHostAddress raw log field with event.idm.read_only_udm.principal.asset.ip UDM field.- event.idm.read_only_udm.principal.hostname: Newly mapped host.name raw log field with event.idm.read_only_udm.principal.hostname UDM field.- event.idm.read_only_udm.principal.asset.hostname: Newly mapped host.name raw log field with event.idm.read_only_udm.principal.asset.hostname UDM field.- event.idm.read_only_udm.metadata.id: Newly mapped parsed.RequestID raw log field with event.idm.read_only_udm.metadata.id UDM field.- event.idm.read_only_udm.principal.location.name: Newly mapped meta.cloud.availability_zone raw log field with event.idm.read_only_udm.principal.location.name UDM field.- event.idm.read_only_udm.principal.location.country_or_region: Newly mapped meta.cloud.region raw log field with event.idm.read_only_udm.principal.location.country_or_region UDM field.- event.idm.read_only_udm.principal.resource.id: Newly mapped host.id raw log field with event.idm.read_only_udm.principal.resource.id UDM field.- event.idm.read_only_udm.observer.hostname: Newly mapped LogstashPod raw log field with event.idm.read_only_udm.observer.hostname UDM field.- event.idm.read_only_udm.principal.asset.asset_id: Newly mapped fields.ApplianceID raw log field with event.idm.read_only_udm.principal.asset.asset_id UDM field.- event.idm.read_only_udm.additional.fields: Newly mapped LogChannel, FormatVersion, EventID, Version, parsed.UserAgent, parsed.ApplianceID, beat.name, beat.hostname, beat.version, fields.CompanyID, derived.CompanyIndex, _version, derived.EventType, prospector.type, input.type, parsed_Message raw log fields with event.idm.read_only_udm.additional.fields UDM field.- event.idm.read_only_udm.principal.resource.attribute.labels: Newly mapped meta.cloud.machine_type, ApplianceType, parsed.Version, host.architecture, host.os.platform, host.os.version, host.os.build, host.os.family, host.os.name, meta.cloud.provider, derived.LogChannelIndex, document_id, meta.cloud.instance_id, tags raw log fields with event.idm.read_only_udm.principal.resource.attribute.labels UDM field.
|
| 2025-07-24 |
- Added a gsub to parse proper value. - event.idm.read_only_udm.target.resource.name: Newly mapped Realm raw log field with event.idm.read_only_udm.target.resource.name UDM field.- event.idm.read_only_udm.additional.fields: Newly mapped CompanyID, PEN, ApplianceID, ApplianceMachineName, RequestID, UseJava raw log fields with event.idm.read_only_udm.additional.fields UDM field.
|
| 2023-07-09 |
- Added support for a new log format: SYSLOG + KV. - Added a Grok pattern to parse the new logs. |
| 2022-04-25 | New: Updated and converted customer-specific version to default. |