Change log for WORKSPACE_ALERTS

Date Changes
2026-01-27 - security_result.action: Extended support for data.ruleViolationInfo.triggeredActionTypes raw log field with security_result.action UDM field.
2025-10-29 - APNS certificate is expiring soon: Added support for the alert type APNS certificate is expiring soon and relevant corresponding raw log fields.
- APNS certificate has expired: Added support for the alert type APNS certificate has expired and relevant corresponding raw log fields.
2024-10-08 - Mapped all fields in message raw log field to security_result.detection_fields with separate security_result block for each message.
2024-07-26 - Updated the field name from emailaddress to emailAddress
2023-11-29 - Updated mapping to map the first occurrence of domain values in the recipients array to target.domain.name and other occurrences to additional UDM field.
- Added additional mappings for deprecated labels.
2023-11-01 Enhancement to use base64 hex decode function to parse IP addresses.
2023-10-04 Added support for new Alert Types for source Reporting Rule.
2023-09-06 Added support for new Alert Types for source UserChanges and AppSettingsChanged.
2023-04-12 Promoted WORKSPACE_ALERTS parser to default.
For the field mapping reference, see https://cloud.google.com/chronicle/docs/ingestion/default-parsers/collect-workspace-logs#field-mapping>Collect Google Workspace logs.