Change log for WORKSPACE_ALERTS
| Date | Changes |
|---|---|
| 2026-01-27 |
- security_result.action: Extended support for data.ruleViolationInfo.triggeredActionTypes raw log field with security_result.action UDM field.
|
| 2025-10-29 |
- APNS certificate is expiring soon: Added support for the alert type APNS certificate is expiring soon and relevant corresponding raw log fields.- APNS certificate has expired: Added support for the alert type APNS certificate has expired and relevant corresponding raw log fields.
|
| 2024-10-08 |
- Mapped all fields in message raw log field to security_result.detection_fields with separate security_result block for each message.
|
| 2024-07-26 |
- Updated the field name from emailaddress to emailAddress
|
| 2023-11-29 |
- Updated mapping to map the first occurrence of domain values in the recipients array to target.domain.name and other occurrences to additional UDM field.- Added additional mappings for deprecated labels. |
| 2023-11-01 |
Enhancement to use base64 hex decode function to parse IP addresses.
|
| 2023-10-04 |
Added support for new Alert Types for source Reporting Rule.
|
| 2023-09-06 |
Added support for new Alert Types for source UserChanges and AppSettingsChanged.
|
| 2023-04-12 |
Promoted WORKSPACE_ALERTS parser to default.For the field mapping reference, see https://cloud.google.com/chronicle/docs/ingestion/default-parsers/collect-workspace-logs#field-mapping>Collect Google Workspace logs. |