Change log for THINKST_CANARY
| Date | Changes |
|---|---|
| 2026-07-10 |
Enhancement: - event.idm.read_only_udm.target.port: Newly mapped DstPort raw log field with event.idm.read_only_udm.target.port UDM field.- event.idm.read_only_udm.principal.port: Newly mapped SrcPort raw log field with event.idm.read_only_udm.principal.port UDM field.- event.idm.read_only_udm.network.dns.questions: Newly mapped Hostname raw log field with event.idm.read_only_udm.network.dns.questions UDM field.- event.idm.read_only_udm.principal.hostname, event.idm.read_only_udm.principal.asset.hostname: Newly mapped Hostname, Host raw log fields with event.idm.read_only_udm.principal.hostname and event.idm.read_only_udm.principal.asset.hostname UDM fields.- event.idm.read_only_udm.security_result.detection_fields: Newly mapped Flock, Reminder, EventName, Merchant, TransactionAmount, TransactionCurrency, MerchantIdentifier raw log fields with event.idm.read_only_udm.security_result.detection_fields UDM field.- event.idm.read_only_udm.principal.asset.platform_software.platform: Newly mapped Sec-Ch-Ua-Platform, Os raw log fields with event.idm.read_only_udm.principal.asset.platform_software.platform UDM field.- event.idm.read_only_udm.principal.location.city: Newly mapped City raw log field with event.idm.read_only_udm.principal.location.city UDM field.- event.idm.read_only_udm.principal.location.country_or_region: Newly mapped Country raw log field with event.idm.read_only_udm.principal.location.country_or_region UDM field.- event.idm.read_only_udm.principal.ip, event.idm.read_only_udm.principal.asset.ip: Newly mapped Ip, X-Forwarded-For raw log fields with event.idm.read_only_udm.principal.ip and event.idm.read_only_udm.principal.asset.ip UDM fields.- event.idm.read_only_udm.principal.location.region_coordinates.latitude: Newly mapped Latitude raw log field with event.idm.read_only_udm.principal.location.region_coordinates.latitude UDM field.- event.idm.read_only_udm.principal.location.region_coordinates.longitude: Newly mapped Longitude raw log field with event.idm.read_only_udm.principal.location.region_coordinates.longitude UDM field.- event.idm.read_only_udm.principal.location.state: Newly mapped Region raw log field with event.idm.read_only_udm.principal.location.state UDM field.- event.idm.read_only_udm.target.resource.product_object_id: Newly mapped DocumentId raw log field with event.idm.read_only_udm.target.resource.product_object_id UDM field.- event.idm.read_only_udm.principal.user.email_addresses: Newly mapped TheirEmail raw log field with event.idm.read_only_udm.principal.user.email_addresses UDM field.- event.idm.read_only_udm.about.user.email_addresses: Newly mapped OurEmail raw log field with event.idm.read_only_udm.about.user.email_addresses UDM field.- event.idm.read_only_udm.principal.file.mime_type: Newly mapped Mimetypes raw log field with event.idm.read_only_udm.principal.file.mime_type UDM field.- event.idm.read_only_udm.principal.process.pid: Newly mapped Pid raw log field with event.idm.read_only_udm.principal.process.pid UDM field.- event.idm.read_only_udm.target.asset.attribute.labels: Newly mapped MaskedCardNumber raw log field with event.idm.read_only_udm.target.asset.attribute.labels UDM field.- event.idm.read_only_udm.principal.asset.attribute.labels: Newly mapped ConsoleCanarytokenDomain, ClientName, ClientVersion, Sec-Ch-Ua, Sec-Ch-Ua-Mobile, Sec-Ch-Ua-Platform, Browser, Os, Version, Platform, Language, Installed, Vendor, Name raw log fields with event.idm.read_only_udm.principal.asset.attribute.labels UDM field.- event.idm.read_only_udm.additional.fields: Newly mapped Content-Length, Content-Type, Enabled, ClientRole, MaxPacketSize, ProgramName, SequenceId, Token, Accept-Language, Accept-Encoding, Accept, Sec-Fetch-Dest, Sec-Fetch-Mode, Sec-Fetch-Site, Sec-Fetch-User, Upgrade-Insecure-Requests, Connection, Abbr, CountryCode, CountryCode3, CurrencyCode, HostDomain, Id, IsBogon, IsProxy, IsTor, IsV4Mapped, IsV6, IsVpn, LanguageCode, TimezoneName, Offset, RegionCode, Time, Valid, ContinentCode, Locale, PacketLength, ClientFlags, ClientAuthPlugin, CharacterSet, AcquirerIdentifier raw log fields with event.idm.read_only_udm.additional.fields UDM field.- event.idm.read_only_udm.metadata.event_type: Set event_type to USER_UNCATEGORIZED and STATUS_UPDATE when user or principal machine data is present else set event_type to GENERIC_EVENT.- event.idm.read_only_udm.network.application_protocol: Set the event.idm.read_only_udm.network.application_protocol UDM field to DNS for DNS log.
|
| 2026-06-26 |
Enhancement: - event.idm.read_only_udm.additional.fields: Newly mapped description.matched_annotations.tripwire_trigger, description.events.password, description.events.MESSAGE and description.events.sectors raw log fields with event.idm.read_only_udm.additional.fields UDM field.- event.idm.read_only_udm.principal.user.userid: Newly mapped description.events.user raw log field with event.idm.read_only_udm.principal.user.userid UDM field.- event.idm.read_only_udm.principal.resource.attribute.labels: Newly mapped description.events.cmd and description.events.db raw log fields with event.idm.read_only_udm.principal.resource.attribute.labels UDM field.- event.idm.read_only_udm.security_result.detection_fields: Newly mapped description.events.OLD_LOGTYPE raw log field with event.idm.read_only_udm.security_result.detection_fields UDM field.
|
| 2026-06-02 |
Enhancement: - event.idm.read_only_udm.additional.fields: Newly mapped description.events.transaction_date,description.acknowledged, description.local_time, elem.acquirer_identifier, elem.masked_card_number, elem.transaction_currency, elem.transaction_type, elem.ip_blocklist.is_proxy,elem.ip_blocklist.is_tor, elem.ip_blocklist.is_vpn, elem.timestamp, elem.timestamp_std raw log fields with event.idm.read_only_udm.additional.fields UDM field.- event.idm.read_only_udm.principal.resource.attribute.labels: Newly mapped elem.client_public_key, elem.client_session_index, elem.geoip.city, elem.geoip.country, elem.geoip.country_code, elem.geoip.country_code3, elem.geoip.currency_code, elem.geoip.ip, elem.geoip.is_bogon, elem.geoip.is_v4_mapped, elem.geoip.is_v6, elem.geoip.language_code, elem.geoip.latitude, elem.geoip.longitude, elem.geoip.region, elem.geoip.region_code, elem.geoip.valid, elem.geoip.timezone.abbr, elem.geoip.timezone.date, elem.geoip.timezone.id, elem.geoip.timezone.name, elem.geoip.timezone.offset, elem.geoip.timezone.time, elem.src_host, elem.src_port raw log field with event.idm.read_only_udm.principal.resource.attribute.labels UDM field.- event.idm.read_only_udm.target.resource.attribute.labels: Newly mapped elem.merchant raw log field with event.idm.read_only_udm.target.resource.attribute.labels UDM field.- event.idm.read_only_udm.target.location.city: Newly mapped elem.merchant_details.city raw log field with event.idm.read_only_udm.target.location.city UDM field.- event.idm.read_only_udm.target.location.country_or_region: Newly mapped elem.merchant_details.country raw log field with event.idm.read_only_udm.target.location.country_or_region UDM field.- event.idm.read_only_udm.target.resource.product_object_id: Newly mapped elem.merchant_details.merchant_identifier raw log field with event.idm.read_only_udm.target.resource.product_object_id UDM field.- event.idm.read_only_udm.target.resource.name: Newly mapped elem.merchant_details.name raw log field with event.idm.read_only_udm.target.resource.name UDM field.- event.idm.read_only_udm.security_result.detection_fields: Newly mapped elem.status, elem.transaction_amount raw log field with event.idm.read_only_udm.security_result.detection_fields UDM field.
|
| 2026-04-07 |
Enhancement: - event.idm.read_only_udm.target.application: Newly mapped elem.INSTANCE_NAME raw log field with event.idm.read_only_udm.target.application UDM field.- event.idm.read_only_udm.security_result.about.resource.attribute.labels: Newly mapped elem.HEADERS.upgrade-insecure-requests, elem.HEADERS.cookie and elem.SKIN raw log fields with event.idm.read_only_udm.security_result.about.resource.attribute.labels` UDM field.- event.idm.read_only_udm.metadata.event_type: Mapped event.idm.read_only_udm.metadata.event_type to NETWORK_HTTP when _md_product_event_type is HTTP Page Load.- Added support for HTTP Page Load logs.
|
| 2025-11-21 |
Enhancement: - event.idm.read_only_udm.additional.fields: Newly mapped updated, updated_std, description.created_std, description.events_list, description.events.FUNC_CODE, description.events.FUNC_NAME, description.events.SFUNC_CODE, description.events.SFUNC_NAME, description.events.UNIT_ID, description.events.timestamp_std, elem.URL, description.local_time, elem.event_descrip, elem.lt, elem.offline_text, elem.uptime raw log field with event.idm.read_only_udm.additional.fields UDM field.- event.idm.read_only_udm.security_result.detection_fields: Newly mapped elem.why, elem.online, description.acknowledged, updated_time raw log field with event.idm.read_only_udm.security_result.detection_fields UDM field.- Added conditional check for _md_product_event_type to include HTTP Proxy Request, Offline Events Dropped, ModBus Request, New Canaries added, `MySQL Login Attempt".- Added conditional check for _md_event_type to default to GENERIC_EVENT if empty.- Added conditional check for _md_product_event_type to include Honeypot Scanner Detected.- event.idm.read_only_udm.metadata.event_type: If _md_product_event_type is HTTP Proxy Request, updated to NETWORK_HTTP.- event.idm.read_only_udm.metadata.event_type: If _md_product_event_type is MySQL Login Attempt, updated to USER_LOGIN.- event.idm.read_only_udm.metadata.event_type: If _md_product_event_type is ModBus Request, updated to NETWORK_CONNECTION.- event.idm.read_only_udm.metadata.event_type: If _md_product_event_type is New Canaries added and other conditions are not met, updated to GENERIC_EVENT.- event.idm.read_only_udm.metadata.event_type: If [_md_event_type] is " , updated to GENERIC_EVENT".- Added a fallback mechanism for JSON parsing: If the initial parse fails, the an on error flag _not_json is set. A new field message1 is created by prepending { to the original message, and JSON parsing is re-attempted on message1.
|
| 2025-06-26 |
Enhancement: - Added Grok patterns to parse the unparsed logs. - Replaced thinkst_canary_udm_host_port_scan_event.include, thinkst_canary_udm_canary_disconnected_reconnected_event.include, thinkst_canary_udm_custom_tcp_service_request_event.include, thinkst_canary_udm_ssh_login_attempt_event.include, thinkst_canary_udm_ftp_telnet_login_attempt_event.include, thinkst_canary_udm_canary_settings_changed_event.include, thinkst_canary_udm_http_page_load_event.include with the actual code.- event.idm.read_only_udm.security_result.detection_fields: Newly mapped Request, Command, PasswordHash, NTPCommand, Key, Salt, Password, ClientHash, connection, accept, FunctionName, FunctionData, TCPBannerID, IncidentHash, accept-encoding, VNCServerChallenge, VNCClientResponse, VNCPassword, Settings, LoginType raw log field with event.idm.read_only_udm.principal.ip UDM field.- event.idm.read_only_udm.target.resource.name: Newly mapped Database' raw log field with event.idm.read_only_udm.target.resource.name` UDM field.- event.idm.read_only_udm.network.ftp.command: Newly mapped Action' raw log field with event.idm.read_only_udm.network.ftp.command` UDM field.- event.idm.read_only_udm.principal.user.group_identifiers: Newly mapped DistinguishedName' raw log field with event.idm.read_only_udm.principal.user.group_identifiers` UDM field.- event.idm.read_only_udm.network.http.referral_url: Newly mapped Pathevent.idm.read_only_udm.network.http.referral_url` UDM field.- event.idm.read_only_udm.target.resource.attribute.labels: Newly mapped ShareNameevent.idm.read_only_udm.target.resource.attribute.labels` UDM field.- Added KV block to extract values from the Headers field. - event.idm.read_only_udm.principal.hostname and event.idm.read_only_udm.principal.asset.hostname: Newly mapped ReverseDNS' raw log field with event.idm.read_only_udm.principal.hostname and event.idm.read_only_udm.principal.asset.hostname` UDM field.- event.idm.read_only_udm.target.ip and event.idm.read_only_udm.target.asset.ip: Newly mapped CanaryPublicIP' raw log field with event.idm.read_only_udm.target.ip and event.idm.read_only_udm.target.asset.ip` UDM field.- event.idm.read_only_udm.principal.user.user_display_name: Newly mapped User' raw log field with event.idm.read_only_udm.principal.user.user_display_name` UDM field.- event.idm.read_only_udm.target.resource.product_object_id: Newly mapped EC2InstanceID' raw log field with event.idm.read_only_udm.target.resource.product_object_id` UDM field.- event.idm.read_only_udm.target.location.country_or_region: Newly mapped EC2Region' raw log field with event.idm.read_only_udm.target.location.country_or_region` UDM field.- event.idm.read_only_udm.principal.administrative_domain: Newly mapped Domain' raw log field with event.idm.read_only_udm.principal.administrative_domain` UDM field.- event.idm.read_only_udm.target.files.names: Newly mapped RemoteSMBName' raw log field with event.idm.read_only_udm.target.files.names` UDM field.- event.idm.read_only_udm.security_result.action: Newly mapped Success is true and BLOCK when Success' is false with event.idm.read_only_udm.security_result.action` UDM field.- event.idm.read_only_udm.target.location.name: Newly mapped CanaryLocation' raw log field with event.idm.read_only_udm.target.location.name` UDM field.- event.idm.read_only_udm.principal.user.userid: Newly mapped Username' raw log field with event.idm.read_only_udm.principal.user.userid` UDM field.- event.idm.read_only_udm.security_result.description: Newly mapped BackgroundContext' raw log field with event.idm.read_only_udm.security_result.description` UDM field.- Added null condition check for all the fields. - Added on_error to all the mutate replace blocks. - event.idm.read_only_udm.network.http.user_agent: Newly mapped User-Agent' raw log field with event.idm.read_only_udm.network.http.user_agent` UDM field.- event.idm.read_only_udm.target.file.full_path: Newly mapped Filename' raw log field with event.idm.read_only_udm.target.file.full_path` UDM field.- event.idm.read_only_udm.principal.hostname and event.idm.read_only_udm.principal.asset.hostname: Newly mapped ThinkstCanary_Hostname' raw log field with event.idm.read_only_udm.principal.hostname and event.idm.read_only_udm.principal.asset.hostname` UDM field.- event.idm.read_only_udm.principal.application: Newly mapped ThinkstCanary_Process' raw log field with event.idm.read_only_udm.principal.application` UDM field.- Removed redundant code for _dst_hostname, CanaryIP, _src_host_reverse, _dst_host and User-Agent.
|
| 2025-02-26 |
Enhancement: - When _md_product_event_type is Host port scan, description.logtype is mapped to security_result.detection_fields.
|
| 2025-02-04 |
Enhancement: - When _md_product_event_type is Host port scan or Custom TCP Service Request, description.logtype is mapped to security_result.detection_fields.
|
| 2024-07-17 |
Enhancement: - Added support for the following events: Remote registry connection, Canarytoken triggered, File share connection, RDP connection made, and Canary settings changed.
|
| 2024-07-03 |
Enhancement: - Added support for dns logs.
|
| 2024-05-10 |
Enhancement: - Added support for Flock Settings Changed events.- If value of _md_product_event_type is Flock Settings Changed, added a Grok pattern to extract user_id from the field elem.SETTINGS.- Mapped user_id to principal.user.userid.
|
| 2024-03-05 |
Enhancement: - Added support for SIP Request events.- Added support for TFTP Request events.- Mapped hash_id to principal.file.sha1.- Mapped HEADERS.user-agent to network.http.user_agent.- Mapped description.node_id to principal.resource.attribute.labels.- Mapped description.flock_id to principal.resource.attribute.labels.- Mapped description.flock_name to principal.resource.attribute.labels.- Mapped description.logtype to security_result.detection_fields.- Mapped description.events_count to security_result.detection_fields.- Mapped HEADERS.allow to security_result.detection_fields.- Mapped HEADERS.call-id to security_result.detection_fields.- Mapped HEADERS.contact to security_result.detection_fields.- Mapped HEADERS.sip to security_result.detection_fields.- Mapped HEADERS.cseq to security_result.detection_fields.- Mapped HEADERS.expires to security_result.detection_fields.- Mapped HEADERS.from to security_result.detection_fields.- Mapped HEADERS.to to security_result.detection_fields.- Mapped HEADERS.max-forwards to security_result.detection_fields.
|
| 2023-12-08 |
Enhancement: - Since all THINKST_CANARY alerts are critical by default, set is_alert to true for all events.- Since all THINKST_CANARY alerts are critical by default, set is_significant to true for all events.- Since all THINKST_CANARY alerts are critical by default, set security_result.severity to CRITICAL for all events.- Added support for NMAP OS Scan Detected events.
|
| 2023-12-07 |
Enhancement: - Added support for WinRM Login Attempt, Telnet Login Attempt, NMAP OS Scan Detected, Redis Command events.- Added support to parse new pattern of _metadata_event_timestamp,_event_time.
|
| 2023-09-15 |
Enhancement: - Added support for VNC Login Attempt events.
|
| 2023-08-04 |
Bug Fix: Following changes have been made for Canarytoken triggered events: - Mapped to more specific event_type, for example NETWORK_CONNECTION.- As resource.id is deprecated, mapped canarytoken to principal.resource.product_object_id.- Also event.idm.is_alert is set to true for the given event.- Set security_result.category to 'NETWORK_SUSPICIOUS.
|
| 2023-05-12 |
Bug Fix - Added support for logs having description.summary=MSSQL Login Attempt and mapped event_type to USER_LOGIN;
|
| 2022-12-04 |
Bug Fix - - Added support for HTTP Login Attempt, FTP Login Attempt, Website Scan, Console Settings Changed, RDP Login Attempt.
|