Change log for CYNET_360_AUTOXDR
| Date | Changes |
|---|---|
| 2026-06-18 | - Added a Grok pattern to validate that the `src`, `dst`, `RequesterIp`, and `StringIP` raw log fields contain valid IP addresses.
- Added timestamp support for the `rt` raw log field. - `event.idm.read_only_udm.target.hostname`, `event.idm.read_only_udm.target.asset.hostname`: Newly mapped `dst` raw log field with `event.idm.read_only_udm.target.hostname` and `event.idm.read_only_udm.target.asset.hostname` UDM fields when it is not a valid IP address. - `event.idm.read_only_udm.principal.hostname`, `event.idm.read_only_udm.principal.asset.hostname`: Newly mapped `src` raw log field with `event.idm.read_only_udm.principal.hostname` and `event.idm.read_only_udm.principal.asset.hostname` UDM fields when it is not a valid IP address. - `event.idm.read_only_udm.metadata.product_version`: Newly mapped `cef_device_version` raw log field with `event.idm.read_only_udm.metadata.product_version` UDM field. - `event.idm.read_only_udm.metadata.product_event_type`: Newly mapped `cef_signature_id` raw log field with `event.idm.read_only_udm.metadata.product_event_type` UDM field. - `event.idm.read_only_udm.security_result.severity_details`: Newly mapped `cef_severity` raw log field with `event.idm.read_only_udm.security_result.severity_details` UDM field. - `event.idm.read_only_udm.target.url`: Newly mapped `requestUrl` raw log field with `event.idm.read_only_udm.target.url` UDM field. - `event.idm.read_only_udm.metadata.description`: Newly mapped `msg` raw log field with `event.idm.read_only_udm.metadata.description` UDM field. - `event.idm.read_only_udm.principal.user.product_object_id`: Newly mapped `suid` raw log field with `event.idm.read_only_udm.principal.user.product_object_id` UDM field. - `event.idm.read_only_udm.principal.user.email_addresses`: Newly mapped `suser` raw log field with `event.idm.read_only_udm.principal.user.email_addresses` UDM field. - `event.idm.read_only_udm.additional.fields`: Newly mapped `dtz`, `event_time` and `msg_type` raw log fields with `event.idm.read_only_udm.additional.fields` UDM field. - `event.idm.read_only_udm.security_result.action_details`: Newly mapped `act` raw log field with `event.idm.read_only_udm.security_result.action_details` UDM field. - `event.idm.read_only_udm.observer.hostname`: Newly mapped `syslog_host` raw log field with `event.idm.read_only_udm.observer.hostname` UDM field. - `event.idm.read_only_udm.observer.application`: Newly mapped `syslog_app` raw log field with `event.idm.read_only_udm.observer.application` UDM field. - `event.idm.read_only_udm.observer.process.pid`: Newly mapped `process_id` raw log field with `event.idm.read_only_udm.observer.process.pid` UDM field. |
| 2025-10-01 | - event.idm.read_only_udm.additional.fields: Newly mapped `externalId`, `fname`, `sev`, `gpParams`, `gpprUser`, `gpSign`, `hostLS`, `epsVer`, `confVer`, `scanGroupId`, `sign`, `pssdeep`, `pSign`, `pct`, `gpssdeep`, `clientId`, `etwAlertId`, `pParams` raw log field with `event.idm.read_only_udm.additional.fields` UDM field.
- event.idm.read_only_udm.security_result.severity: Newly mapped `sev` raw log field with `event.idm.read_only_udm.security_result.severity` UDM field. - event.idm.read_only_udm.security_result.summary: Newly mapped `remedStat` raw log field with `event.idm.read_only_udm.security_result.summary` UDM field. - event.idm.read_only_udm.security_result.action_details: Newly mapped `actRem` raw log field with `event.idm.read_only_udm.security_result.action_details` UDM field. - event.idm.read_only_udm.security_result.category_details: Newly mapped `cat` raw log field with `event.idm.read_only_udm.security_result.category_details` UDM field. - event.idm.read_only_udm.principal.ip: Newly mapped `src` raw log field with `event.idm.read_only_udm.principal.ip` UDM field. - event.idm.read_only_udm.principal.user.userid: Newly mapped `prUser` raw log field with `event.idm.read_only_udm.principal.user.userid` UDM field. - event.idm.read_only_udm.principal.asset.ip: Newly mapped `src` raw log field with `event.idm.read_only_udm.principal.asset.ip` UDM field. - event.idm.read_only_udm.principal.hostname: Newly mapped `dhost` raw log field with `event.idm.read_only_udm.principal.hostname` UDM field. - event.idm.read_only_udm.principal.asset.hostname: Newly mapped `dhost` raw log field with `event.idm.read_only_udm.principal.asset.hostname` UDM field. - event.idm.read_only_udm.principal.platform_version: Newly mapped `osVer` raw log field with `event.idm.read_only_udm.principal.platform_version` UDM field. - event.idm.read_only_udm.principal.file.sha256: Newly mapped `pFileHash` raw log field with `event.idm.read_only_udm.principal.file.sha256` UDM field. - event.idm.read_only_udm.principal.administrative_domain: Newly mapped `pprUser` raw log field with `event.idm.read_only_udm.principal.administrative_domain` UDM field. - event.idm.read_only_udm.principal.process.file.full_path: Newly mapped `ppParams` raw log field with `event.idm.read_only_udm.principal.process.file.full_path` UDM field. - event.idm.read_only_udm.principal.process.parent_process.file.sha256: Newly mapped `gpFileHash` raw log field with `event.idm.read_only_udm.principal.process.parent_process.file.sha256` UDM field. - event.idm.read_only_udm.target.ip: Newly mapped `dst` raw log field with `event.idm.read_only_udm.target.ip` UDM field. - event.idm.read_only_udm.target.asset.ip: Newly mapped `dst` raw log field with `event.idm.read_only_udm.target.asset.ip` UDM field. - event.idm.read_only_udm.target.file.full_path: Newly mapped `filePath` raw log field with `event.idm.read_only_udm.target.file.full_path` UDM field. - event.idm.read_only_udm.target.user.userid: Newly mapped `duser` raw log field with `event.idm.read_only_udm.target.user.userid` UDM field. - event.idm.read_only_udm.security_result.summary: Newly mapped `cef_header` raw log field with `event.idm.read_only_udm.security_result.summary` UDM field. - event.idm.read_only_udm.target.administrative_domain: Newly mapped `duser` raw log field with `event.idm.read_only_udm.target.administrative_domain` UDM field. - event.idm.read_only_udm.target.group.group_display_name: Newly mapped `scanGroupName` raw log field with `event.idm.read_only_udm.target.group.group_display_name` UDM field. - event.idm.read_only_udm.metadata.event_timestamp: Newly mapped `dtUtc`, `rt` raw log field with `event.idm.read_only_udm.metadata.event_timestamp` UDM field. - event.idm.read_only_udm.metadata.collected_timestamp: Newly mapped `rtUtc` raw log field with `event.idm.read_only_udm.metadata.collected_timestamp` UDM field. - event.idm.read_only_udm.metadata.event_type: The condition to set the event type to USER_UNCATEGORIZED was updated to include a check on the `has_target_user` field. - Added conditional check for json_failed to parse CEF formatted logs as a fallback. - Added conditional check for duser to parse domain and user. - Added conditional check for dtUtc and rt for event timestamp mapping. - Added conditional check for sev to map severity values. |
| 2024-07-09 | - Newly created parser.
|