Change log for TRENDMICRO_VISION_ONE
| Date | Changes |
|---|---|
| 2026-01-08 |
Enhancement: - event.idm.read_only_udm.security_result.detection_fields: Removed mapping of indicator.value from event.idm.read_only_udm.security_result.detection_fields UDM field because the indicator.value contains a file's SHA1 hash when the indicator.type is file_sha1.- event.idm.read_only_udm.principal.file.sha1: Mapped indicator.value raw log field to event.idm.read_only_udm.principal.file.sha1 UDM field.- event.idm.read_only_udm.additional.fields: Newly mapped engVer raw log field with event.idm.read_only_udm.additional.fields UDM field.- event.idm.read_only_udm.security_result.attack_details.tactics: Newly mapped tacticId raw log field with event.idm.read_only_udm.security_result.attack_details.tactics UDM field.- When indicator.type is file_sha1, the indicator.value field is now converted to lowercase before being mapped to event.idm.read_only_udm.principal.file.sha1.
|
| 2025-12-17 |
Enhancement: - event.idm.read_only_udm.additional.fields: Newly mapped process_file_size, level, detail.instanceId, detail.channel, detail.objectLaunchTime, detail.engineOperation, detail.processHashId, process_pid, process_file_path, process_cmd, process_file_hash_sha1, process_file_hash_sha256, process_user and process_launch_time raw log fields to event.idm.read_only_udm.additional.fields.- event.idm.read_only_udm.target.file.size: Newly mapped detail.objectFileSize raw log field to event.idm.read_only_udm.target.file.size.- event.idm.read_only_udm.security_result.detection_fields: Newly mapped detail.policyId raw log field to event.idm.read_only_udm.security_result.detection_fields.- event.idm.read_only_udm.security_result.category_details: Newly mapped detail.behaviorCat raw log field to event.idm.read_only_udm.security_result.category_details.- event.idm.read_only_udm.principal.process.pid: Newly mapped process_pid raw log field from detail.processChainInfo to event.idm.read_only_udm.principal.process.pid.- event.idm.read_only_udm.principal.process.file.full_path: Newly mapped process_file_path raw log field from detail.processChainInfo to event.idm.read_only_udm.principal.process.file.full_path.- event.idm.read_only_udm.principal.process.command_line: Newly mapped process_cmd raw log field from detail.processChainInfo to event.idm.read_only_udm.principal.process.command_line.- event.idm.read_only_udm.principal.process.file.sha1: Newly mapped process_file_hash_sha1 raw log field from detail.processChainInfo to event.idm.read_only_udm.principal.process.file.sha1.- event.idm.read_only_udm.principal.process.file.sha256: Newly mapped process_file_hash_sha256 raw log field from detail.processChainInfo to event.idm.read_only_udm.principal.process.file.sha256.- event.idm.read_only_udm.principal.user.userid: Newly mapped process_user raw log field from detail.processChainInfo to event.idm.read_only_udm.principal.user.userid.- Conditionally mapped entity_entityValue: maps to event.idm.read_only_udm.principal.user.user_display_name for the first entity, and to event.idm.read_only_udm.additional.fields for subsequent entities.
|
| 2025-11-27 |
Enhancement: - Implemented a grok pattern to parse the username from the entity.entityValue field when the entityType is account.- Iterating through impactScope.entities with index for more granular field mapping in additional.fields.- event.idm.read_only_udm.metadata.product_log_id: Newly mapped id raw log field to event.idm.read_only_udm.metadata.product_log_id.- event.idm.read_only_udm.additional.fields: Newly mapped matchedRules.matchedFilters.id, matchedRules.matchedFilters.matchedDateTime, schemaVersion, status, modelId, modelType, incidentId, impactScope.desktopCount, impactScope.serverCount, impactScope.accountCount, impactScope.emailAddressCount, impactScope.containerCount, impactScope.cloudIdentityCount, entity.managementScopePartitionKey, entity.managementScopeInstanceId, entity.managementScopeGroupId, entity.entityValue.guid, and entity.provenance raw log fields to event.idm.read_only_udm.additional.fields.- event.idm.read_only_udm.principal.user.user_display_name: Changed mapping for event.idm.read_only_udm.principal.user.user_display_name from entity.entityValue to the part of entity.entityValue after a backslash, extracted via grok.- event.idm.read.only_udm.security_result.detection_fields: Newly mapped matchedRules.matchedFilters.matchedEvents.uuid and matchedRules.matchedFilters.matchedEvents.type to event.idm.read_only_udm.security_result.detection_fields.
|
| 2025-11-06 |
Enhancement: - event.idm.read_only_udm.metadata.event_timestamp: Newly mapped detail.eventTime raw log field with event.idm.read_only_udm.metadata.event_timestamp UDM field.- event.idm.read_only_udm.metadata.collected_timestamp: Newly mapped detectedDateTime raw log field with event.idm.read_only_udm.metadata.collected_timestamp UDM field.- event.idm.read_only_udm.metadata.product_version: Newly mapped detail.mpver raw log field with event.idm.read_only_udm.metadata.product_version UDM field.- event.idm.read_only_udm.observer.ip: Newly mapped detail.senderIp raw log field with event.idm.read_only_udm.observer.ip UDM field.- event.idm.read_only_udm.observer.hostname: Newly mapped detail.dvchost raw log field with event.idm.read_only_udm.observer.hostname UDM field.- event.idm.read_only_udm.observer.asset.asset_id: Newly mapped detail.mDeviceGUID raw log field with event.idm.read_only_udm.observer.asset.asset_id UDM field.- event.idm.read_only_udm.additional.fields: Newly mapped detail.logReceivedTime, detail.logKey, detail.eventSourceType, detail.senderGUID, detail.eventSubName, detail.pname raw log fields with event.idm.read_only_udm.additional.fields UDM field.- event.idm.read_only_udm.principal.process.file.full_path: Newly mapped detail.processName raw log field with event.idm.read_only_udm.principal.process.file.full_path UDM field.- event.idm.read_only_udm.principal.group.product_object_id: Newly mapped detail.groupId raw log field with event.idm.read_only_udm.principal.group.product_object_id UDM field.- event.idm.read_only_udm.target.resource.attribute.labels: Newly mapped detail.dacDeviceType raw log field with event.idm.read_only_udm.target.resource.attribute.labels UDM field.- event.idm.read_only_udm.target.asset.asset_id: Newly mapped detail.deviceGUID raw log field with event.idm.read_only_udm.target.asset.asset_id UDM field.- event.idm.read_only_udm.security_result.action_details: Newly mapped detail.accessPermission raw log field with event.idm.read_only_udm.security_result.action_details UDM field.- event.idm.read_only_udm.security_result.severity_details: Newly mapped filter.riskLevel raw log field with event.idm.read_only_udm.security_result.severity_details UDM field.- event.idm.read_only_udm.security_result.rule_type: Newly mapped filter.type raw log field with event.idm.read_only_udm.security_result.rule_type UDM field.- event.idm.read_only_udm.security_result.detection_fields: Newly mapped tag, object.field, object.type raw log fields with event.idm.read_only_udm.security_result.detection_fields UDM field.- event.idm.read_only_udm.target.file.full_path: Newly mapped value raw log field with event.idm.read_only_udm.target.file.full_path UDM field.- event.idm.read_only_udm.principal.asset.asset_id: Newly mapped endpoint.agentGuid raw log field with event.idm.read_only_udm.principal.asset.asset_id UDM field.- event.idm.read_only_udm.principal.asset.attribute.labels: Newly mapped entityName raw log field with event.idm.read_only_udm.principal.asset.attribute.labels UDM field.- event.idm.read_only_udm.metadata.ingested_timestamp: Newly mapped ingestedDateTime raw log field with event.idm.read_only_udm.metadata.ingested_timestamp UDM field.- event.idm.read_only_udm.metadata.product_event_type: Newly mapped detail.eventName raw log field with event.idm.read_only_udm.metadata.product_event_type UDM field.- event.idm.read_only_udm.principal.mac: Newly mapped detail.endpointMacAddress raw log field with event.idm.read_only_udm.principal.mac UDM field.
|
| 2025-08-05 |
Enhancement: - event.idm.read_only_udm.additional.fields: Newly mapped entityType,deviceFacility, ApexCentralHost raw log fields with event.idm.read_only_udm.additional.fields UDM field.- Added a grok pattern on TMCMdevicePlatform raw log field to extract plat_form and platform_version fields.- event.idm.read_only_udm.principal.platform_version: Newly Mapped platform_version field to event.idm.read_only_udm.principal.platform_version UDM field.- event.idm.read_only_udm.principal.platform: Newly Mapped plat_form raw log field to event.idm.read_only_udm.principal.platform UDM field.- Initialised msg field in statedata to parse the unparsed raw log.- Removed the variable process_present that was set to true for processFilePath field .- Removed the conditional check for process_present where the event.idm.read_only_udm.metadata.event_type is set to PROCESS_UNCATEGORIZED.- event.idm.read_only_udm.target.process.file.full_path: Updated logic to set target_process_present to true when mapping object.value to event.idm.read_only_udm.target.process.file.full_path if object.field is equal to processFilePath.- event.idm.read_only_udm.target.process.file.sha1: Updated logic to set target_process_present to true when mapping object.value to event.idm.read_only_udm.target.process.file.sha1 if object.field is equal to processFileHashSha1.- event.idm.read_only_udm.target.process.command_line: Updated logic to set target_process_present to true when mapping object.value to event.idm.read_only_udm.target.process.command_line if object.field is equal to processCmd.
|
| 2025-06-05 |
Enhancement: - event.idm.read_only_udm.target.ip: Newly mapped filters.highlightedObjects.value raw log field when filters.highlightedObjects.field is dst with event.idm.read_only_udm.target.ip and event.idm.read_only_udm.target.asset.ip UDM field.- event.idm.read_only_udm.principal.ip: Newly mapped filters.highlightedObjects.value raw log field when filters.highlightedObjects.field is src with event.idm.read_only_udm.principal.ip and event.idm.read_only_udm.principal.asset.ip UDM field.
|
| 2025-05-19 |
Enhancement: - event.idm.read_only_udm.additional.fields: Newly mapped Impactscopedetails.EndpointServers.Guid and Impactscopedetails.EndpointDesktops.Guid raw log field with event.idm.read_only_udm.additional.fields UDM field.- Added index for Impactscopedetails.EndpointDesktops and Impactscopedetails.EndpointServers.
|
| 2025-04-30 |
Enhancement: - Added a Gsub to convert Endpoint - Servers to EndpointServers.- Added a flag has_asset_id and has_process.- event.idm.read_only_udm.principal.hostname: Newly mapped Impactscopedetails.EndpointServers.Hostname raw log field with event.idm.read_only_udm.principal.hostname and event.idm.read_only_udm.principal.asset.hostname UDM field.- event.idm.read_only_udm.principal.asset_id: Newly mapped Impactscopedetails.EndpointServers.Guid raw log field with event.idm.read_only_udm.principal.asset_id UDM field.- event.idm.read_only_udm.principal.ip: Newly mapped Impactscopedetails.EndpointServers.Ips raw log field with event.idm.read_only_udm.principal.ip and event.idm.read_only_udm.principal.asset.ip UDM field.- event.idm.read_only_udm.target.process.parent_process.file.sha1: Newly mapped objectfield if equal to objectFileHashSha1 or fileHash raw log field with event.idm.read_only_udm.target.process.parent_process.file.sha1 UDM field.- event.idm.read_only_udm.target.process.parent_process.command_line: Newly mapped objectfield if equal to processCmd raw log field with event.idm.read_only_udm.target.process.parent_process.command_line UDM field.- PROCESS_LAUNCH: Added support for the event PROCESS_LAUNCH when principal_present is true, has_asset_id is true AND has_process is true has_target_hostname is true and set event.idm.read_only_udm.principal.asset_id to "".- event.idm.read_only_udm.metadata.event_type: Removed mapping of EMAIL_TRANSACTION from event.idm.read_only_udm.metadata.event_type UDM field.- Set has_asset_id to true when event.idm.read_only_udm.principal.asset_id and event.idm.read_only_udm.principal.asset.asset_id is populated.- Set has_process to true when event.idm.read_only_udm.target.process.file.full_path is populated.
|
| 2025-04-22 |
Enhancement: - event.idm.read_only.udm.additional.fields: Removed mapping of endpoint.name from event.idm.read_only.udm.additional.fields UDM field.- event.idm.read_only.udm.principal.hostname: Mapped endpoint.name raw log field with event.idm.read_only.udm.principal.hostname UDM field.- event.idm.read_only.udm.principal.asset.hostname: Mapped endpoint.name raw log field with event.idm.read_only.udm.principal.asset.hostname UDM field.- event.idm.read_only.udm.principal.ip: Mapped endpoint.ips raw log field with event.idm.read_only.udm.principal.ip UDM field if valid IP, esle mapped it to event.idm.read_only.udm.additional.fields.- event.idm.read_only.udm.principal.asset.ip: Mapped endpoint.ips raw log field with event.idm.read_only.udm.principal.asset.ip UDM field if valid IP, esle mapped it to event.idm.read_only.udm.additional.fields.- event.idm.read_only.udm.additional.fields: Newly mapped actResult raw log list field with event.idm.read_only.udm.additional.fields UDM field.- event.idm.read_only.udm.security_result.action: Newly mapped event.idm.read_only.udm.security_result.action UDM field as ALLOW if actResult raw log field value is Passed else mapped it to BLOCK.
|
| 2025-03-21 |
Enhancement: - If objecttype is command_line and objectfield is objectCmd and target_commandline_process_set is false then mapped object.CustomValue to target.process.command_line.- If objecttype is command_line and objectfield is parentCmd and target_commandline_parent_process_set is false then mapped object.CustomValue to target.process.parent_process.command_line.- If objecttype is command_line and objectfield is not processCmd and objectCmd then mapped object.CustomValue to target.resource.attribute.labels.- If objecttype is file_sha1 and objectfield is processFileHashSha1 and target_filesha1_set is false then mapped object.CustomValue to target.file.sha1 and target.process.file.sha1.- If objecttype is file_sha1 and objectfield is parentFileHashSha1 and target_parent_filesha1_set is false then mapped object.CustomValue to target.process.parent_process.file.sha1.- If objecttype is file_sha1 and objectfield is not parentFileHashSha1 and processFileHashSha1 then mapped object.CustomValue to target.resource.attribute.labels.- If objecttype is fullpath and objectfield is processFilePath and target_filepath_set is false then mapped object.CustomValue to target.file.full_path and target.process.file.full_path.- If objecttype is fullpath and objectfield is parentFilePath and target_parent_filepath_set is false then mapped object.CustomValue to target.process.parent_process.file.full_path.- If objecttype is fullpath and objectfield is not processFilePath and processFilePath then mapped object.CustomValue to target.resource.attribute.labels.
|
| 2025-03-17 |
Enhancement: - Removed the mapping of uuid from principal.user.userid.- Added the mapping of uuid to principal.resource.product_object_id.
|
| 2025-03-06 |
Enhancement: - Added a for loop to handle multiple Impactscopedetails and Accounts.- Added a for loop to handle multiple Impactscopedetails and EndpointDesktops.- Mapped endpointdesktop.Hostname to principal.hostname.- Mapped guid to principal.asset.asset_id.- Mapped Ips to principal.ip.- If objecttype is text then mapped object.CustomValue to security_result.detection_fields.- If objecttype is command_line then mapped object.CustomValue to target.process.command_line.- If objecttype is file_sha1 then mapped object.CustomValue to target.process.file.sha1.- If objecttype is fullpath then mapped object.CustomValue to target.file.full_path.- Mapped IP_address to principal.ip.- Mapped pliance_IP_address to Appliance_IP_address.
|
| 2025-02-11 |
Enhancement: - When object_field is parentCmd, it is mapped to principal.process.command_line.- When object_field is parentFilePath, it is mapped to principal.process.file.full_path.- Removed principal.process.command_line and principal.process.file.full_path when object_field is processCmd.
|
| 2025-01-31 |
Enhancement: - When object_field is processCmd mapped to principal.process.command_line and principal.process.file.full_path.- When object_field is malName mapped to security_result.threat_name.- When object_field is actResult mapped to security_result.action_details and security_result.action.
|
| 2025-01-24 |
Enhancement: - Removed mappings for target.- Mapped detail.eventSubId should be mapped from metadata.product_event_type- Mapped endpoint.guid and detail.endpointGuid to principal.asset_id and principal.asset.asset_id- Mapped detail.uuid to metadata.product_log_id- Mapped filters.0.unique_id to security_result.rule_id- Mapped filters.0.name to security_result.summary- Mapped filters.0.id to security_result.rule_name
|
| 2025-01-17 |
Enhancement: - Removed mapping of highlightedObjects to additional.fields and mapped them to respective process and file fields.
|
| 2024-12-06 |
Enhancement: - Added date match pattern for firstSeen, createdDateTime, and lastSeen. |
| 2024-11-15 |
Enhancement: - Added support for dropped logs. |
| 2024-11-04 |
Enhancement: - When severity value is info, then mapped security_result.severity to INFORMATIONAL.- Added support for IPv6 logs. |
| 2024-10-10 |
Enhancement: - Mapped detectionTime to metadata.event_timestamp.
|
| 2024-10-03 |
Enhancement: - Added support for new pattern of JSON logs. - Changed mapping of details.ipAddr from principal.ip and principal.asset.ip to target.ip and target.asset.ip.
|
| 2024-08-15 |
Enhancement: - Added support for new pattern of JSON logs. |
| 2024-08-01 |
Enhancement: - Initialized about to null and added a check before merging.
|
| 2024-05-24 |
Enhancement: - Added support for the new pattern of JSON logs. |
| 2024-05-13 |
Enhancement: - Added support for JSON logs. |
| 2023-03-24 | Newly created parser. |