Change log for BROADCOM_SUPPORT_PORTAL
| Date | Changes |
|---|---|
| 2025-03-23 |
Enhancement: - event.idm.read_only_udm.additional.fields: Newly mapped module, socket_details, fd, family, type, level, log_data, timestamp_details, session_duration, correlationId, className raw log field with event.idm.read_only_udm.additional.fields UDM field.- event.idm.read_only_udm.network.ip_protocol: Newly mapped proto raw log field with event.idm.read_only_udm.network.ip_protocol UDM field.- event.idm.read_only_udm.network.http.referral_url: Newly mapped request_url_details raw log field with event.idm.read_only_udm.network.http.referral_url UDM field.- event.idm.read_only_udm.security_result.severity: Newly mapped log_level raw log field with event.idm.read_only_udm.security_result.severity UDM field.- event.idm.read_only_udm.security_result.severity_details: Newly mapped log_level raw log field with event.idm.read_only_udm.security_result.severity_details UDM field.- event.idm.read_only_udm.principal.user.userid: Newly mapped principal_userId_details raw log field with event.idm.read_only_udm.principal.user.userid` UDM field.- event.idm.read_only_udm.target.url: Newly mapped target_url_details, url_details raw log field with event.idm.read_only_udm.target.url UDM field.- event.idm.read_only_udm.metadata.description: Newly mapped desc raw log field with event.idm.read_only_udm.metadata.description UDM field.- event.idm.read_only_udm.principal.user.email_addresses: Newly mapped user_email raw log field with event.idm.read_only_udm.principal.user.email_addresses UDM field.- event.idm.read_only_udm.principal.application: Newly mapped principal_application raw log field with event.idm.read_only_udm.principal.application UDM field.- event.idm.read_only_udm.principal.ip,event.idm.read_only_udm.principal.asset.ip: Newly mapped principal_ip raw log field with event.idm.read_only_udm.principal.ip and event.idm.read_only_udm.principal.asset.ip UDM field.- event.idm.read_only_udm.network.http.method: Newly mapped method_details raw log field with event.idm.read_only_udm.network.http.method UDM field.- event.idm.read_only_udm.network.application_protocol_version: Newly mapped application_protocol_details raw log field with event.idm.read_only_udm.network.application_protocol_version UDM field.- event.idm.read_only_udm.network.application_protocol: Newly mapped application_protocol_data raw log field with event.idm.read_only_udm.network.application_protocol UDM field.- event.idm.read_only_udm.network.http.response_code: Newly mapped response_code_details raw log field with event.idm.read_only_udm.network.http.response_code UDM field.- event.idm.read_only_udm.network.received_bytes: Newly mapped received_bytes_details raw log field with event.idm.read_only_udm.network.received_bytes UDM field.- event.idm.read_only_udm.network.sent_bytes: Newly mapped sent_byte_details raw log field with event.idm.read_only_udm.network.sent_bytes UDM field.- event.idm.read_only_udm.network.http.user_agent: Newly mapped user_agent_details raw log field with event.idm.read_only_udm.network.http.user_agent UDM field.- event.idm.read_only_udm.network.http.parsed_user_agent: Newly mapped user_agent_details raw log field with event.idm.read_only_udm.network.http.parsed_user_agent UDM field.- event.idm.read_only_udm.target.ip,event.idm.read_only_udm.target.asset.ip: Newly mapped target_ip raw log field with event.idm.read_only_udm.target.ip and event.idm.read_only_udm.target.asset.ip UDM field.- event.idm.read_only_udm.target.port: Newly mapped target_port raw log field with event.idm.read_only_udm.target.port UDM field.- event.idm.read_only_udm.principal.port: Newly mapped principal_port raw log field with event.idm.read_only_udm.principal.port UDM field.- event.idm.read_only_udm.metadata.product_log_id: Newly mapped product_log_id_details raw log field with event.idm.read_only_udm.metadata.product_log_id UDM field.- event.idm.read_only_udm.target.application: Newly mapped application_details raw log field with event.idm.read_only_udm.target.application UDM field.- event.idm.read_only_udm.metadata.event_type: If principal machine data fields are present and target machine data fields are present then event_type is updated to NETWORK_CONNECTION.- event.idm.read_only_udm.metadata.event_type: If `principal user details are present then event_type is updated to USER_UNCATEGORIZED.- Added a gsub to remove \r\n, \n, and \\u001b from message.- event.idm.read_only_udm.principal.resource.attribute.labels: Updated mapping for event.idm.read_only_udm.principal.resource.attribute.labels from event1.idm.read_only_udm.principal.resource.attribute.labels to principal.resource.attribute.labels UDM field.- Added grok patterns to parse the log data. |
| 2025-01-29 |
Enhancement: - Newly created parser. |