Change log for SERVICENOW_CMDB

Date Changes
2026-08-07 Enhancement:
- event.idm.relations.entity.asset.attribute.labels: Removed mapping of sys_domain, asset_display_value, model_id.link, device_type, discovery_proto_id, discovery_proto_type, can_switch, can_route, can_hub, can_partitionvlans, ports, u_internet_internal, u_type_physical_virtual, u_bau_project, u_end_security_vulnerability_eol, u_exclude_from_sam, comments, sys_domain.link, cpu_count, environment, virtual, subcategory from event.idm.relations.entity.asset.attribute.labels UDM fields since the asset details represent the primary entity for IP Switch logs rather than a relational entity.
- event.idm.entity.entity.asset.attribute.labels: Mapped sys_domain, asset_display_value, model_id.link, device_type, discovery_proto_id, discovery_proto_type, can_switch, can_route, can_hub, can_partitionvlans, ports, u_internet_internal, u_type_physical_virtual, u_bau_project, u_end_security_vulnerability_eol, u_exclude_from_sam, comments, sys_domain.link, cpu_count, environment, virtual, subcategory raw log fields with event.idm.entity.entity.asset.attribute.labels UDM fields.
- event.idm.relations.entity.labels: Removed mapping of sys_domain_path, sys_mod_count, location, location.link, attestation_status, monitor, operational_status, skip_sync, install_status from event.idm.relations.entity.labels UDM fields since the asset details represent the primary entity for IP Switch logs rather than a relational entity.
- event.idm.entity.entity.asset.attribute.labels: Mapped sys_domain_path, sys_mod_count, location, location.link, attestation_status, monitor, operational_status, skip_sync, install_status raw log fields with event.idm.entity.entity.asset.attribute.labels UDM fields.
- event.idm.relations.entity.asset.first_discover_time: Removed mapping of first_discovered from event.idm.relations.entity.asset.first_discover_time UDM field since the asset details represent the primary entity for IP Switch logs rather than a relational entity.
- event.idm.entity.entity.asset.first_discover_time: Mapped first_discovered raw log field with event.idm.entity.entity.asset.first_discover_time UDM field.
- event.idm.relations.entity.asset.last_discover_time: Removed mapping of last_discovered from event.idm.relations.entity.asset.last_discover_time UDM field since the asset details represent the primary entity for IP Switch logs rather than a relational entity.
- event.idm.entity.entity.asset.last_discover_time: Mapped last_discovered raw log field with event.idm.entity.entity.asset.last_discover_time UDM field.
- event.idm.relations.entity.asset.system_last_update_time: Removed mapping of sys_updated_on from event.idm.relations.entity.asset.system_last_update_time UDM field since the asset details represent the primary entity for IP Switch logs rather than a relational entity.
- event.idm.entity.entity.asset.system_last_update_time: Mapped sys_updated_on raw log field with event.idm.entity.entity.asset.system_last_update_time UDM field.
- event.idm.relations.entity.asset.category: Removed mapping of category from event.idm.relations.entity.asset.category UDM field since the asset details represent the primary entity for IP Switch logs rather than a relational entity.
- event.idm.entity.entity.asset.category: Mapped category raw log field with event.idm.entity.entity.asset.category UDM field.
- event.idm.relations.entity.asset.product_object_id: Removed mapping of sys_id from event.idm.relations.entity.asset.product_object_id UDM field since the asset details represent the primary entity for IP Switch logs rather than a relational entity.
- event.idm.entity.entity.asset.product_object_id: Mapped sys_id raw log field with event.idm.entity.entity.asset.product_object_id UDM field.
- event.idm.relations.entity.asset.hostname: Removed mapping of name, client_name, host_name from event.idm.relations.entity.asset.hostname UDM fields since the asset details represent the primary entity for IP Switch logs rather than a relational entity.
- event.idm.entity.entity.asset.hostname: Mapped name, client_name, host_name raw log fields with event.idm.entity.entity.asset.hostname UDM fields.
- event.idm.relations.entity.asset.ip: Removed mapping of ip_address from event.idm.relations.entity.asset.ip UDM field since the asset details represent the primary entity for IP Switch logs rather than a relational entity.
- event.idm.entity.entity.asset.ip: Mapped ip_address raw log field with event.idm.entity.entity.asset.ip UDM field.
- event.idm.relations.entity.asset.hardware: Removed mapping of hardware from event.idm.relations.entity.asset.hardware UDM field since the asset details represent the primary entity for IP Switch logs rather than a relational entity.
- event.idm.entity.entity.asset.hardware: Mapped hardware raw log field with event.idm.entity.entity.asset.hardware UDM field.
- event.idm.relations.entity.asset.platform_software.platform_version: Removed mapping of firmware_version from event.idm.relations.entity.asset.platform_software.platform_version UDM field since the asset details represent the primary entity for IP Switch logs rather than a relational entity.
- event.idm.entity.entity.asset.platform_software.platform_version: Mapped firmware_version raw log field with event.idm.entity.entity.asset.platform_software.platform_version UDM field.
- event.idm.relations.entity.asset.asset_id: Removed mapping of asset_tag from event.idm.relations.entity.asset.asset_id UDM field since the asset details represent the primary entity for IP Switch logs rather than a relational entity.
- event.idm.entity.entity.asset.asset_id: Mapped asset_tag raw log field with event.idm.entity.entity.asset.asset_id UDM field.
- event.idm.relations.entity.asset.software: Removed mapping of discovery_source from event.idm.relations.entity.asset.software UDM field since the asset details represent the primary entity for IP Switch logs rather than a relational entity.
- event.idm.entity.entity.asset.software: Mapped discovery_source raw log field with event.idm.entity.entity.asset.software UDM field.
- event.idm.entity.entity.user.userid: Removed mapping of sys_updated_by from event.idm.entity.entity.user.userid UDM field since the user details represent a relational entity for IP Switch logs rather than the primary entity.
- event.idm.relations.entity.user.userid: Mapped sys_updated_by raw log field with event.idm.relations.entity.user.userid UDM field.
- event.idm.entity.entity.user.product_object_id: Removed mapping of sys_id from event.idm.entity.entity.user.product_object_id UDM field since the user details represent a relational entity for IP Switch logs rather than the primary entity.
- event.idm.relations.entity.user.product_object_id: Mapped sys_id raw log field with event.idm.relations.entity.user.product_object_id UDM field.
- event.idm.entity.entity.asset_id: Mapped asset raw log field with event.idm.entity.entity.asset_id UDM field.
- event.idm.entity.metadata.entity_type: Set the value of event.idm.entity.metadata.entity_type to ASSET when sys_class_name is IP Switch.
2026-07-23 Enhancement:
- event.idm.entity.relations.entity.user.username: Removed mapping of host_name from event.idm.entity.relations.entity.user.username UDM field since host_name represents ASSET entity and not USER entity.
- event.idm.entity.relations.entity.asset.hostname: Mapped host_name raw log field with event.idm.entity.relations.entity.asset.hostname UDM field.
- event.idm.entity.relations.entity.user.user_display_name: Newly mapped owned_by.display_value raw log field with event.idm.entity.relations.entity.user.user_display_name UDM field.
- event.idm.entity.relations.entity.asset.hardware.model: Newly mapped model_id.display_value raw log field with event.idm.entity.relations.entity.asset.hardware.model UDM field.
- event.idm.entity.relations.entity.asset.platform_software.platform_version: Newly mapped firmware_version raw log field with event.idm.entity.relations.entity.asset.platform_software.platform_version UDM field.
- event.idm.entity.relations.entity.asset.attribute.labels: Newly mapped support_group.display_value, support_group.link, asset.display_value, model_id.link, device_type, discovery_proto_id, discovery_proto_type, can_switch, can_route, can_hub, can_partitionvlans, ports, u_internet_internal, u_type_physical_virtual, u_bau_project, u_end_security_vulnerability_eol, u_exclude_from_sam, comments, subcategory, firmware_version raw log fields with event.idm.entity.relations.entity.asset.attribute.labels UDM field.
- event.idm.entity.relations.entity_type: When host_name is not empty, updated the value of event.idm.entity.relations.entity_type to ASSET.
- Added support for new date format to the date match pattern for first_discovered, last_discovered, sys_updated_on, and sys_created_on raw log fields.
2026-06-24 Enhancement:
- event.idm.entity.entity.asset.attribute.labels: Newly mapped dr_backup_name ,dv_u_device_role ,u_decomissioned ,warranty_expiration raw log fields with event.idm.entity.entity.asset.attribute.labels UDM field.
- event.idm.entity.metadata.entity_type: Added support for event.idm.entity.metadata.entity_type to be mapped to ASSET when both hostname and entity details are present for additional sys_class_name raw log field values.
2026-06-05 Enhancement:
- event.idm.entity.metadata.creation_timestamp: Newly mapped sys_created_on raw log field with event.idm.entity.metadata.creation_timestamp UDM field.
- event.idm.entity.relations.entity.asset.asset_id: Newly mapped asset raw log field with event.idm.entity.relations.entity.asset.asset_id UDM field.
- event.idm.entity.relations.entity.asset.first_seen_time: Newly mapped install_date raw log field with event.idm.entity.relations.entity.asset.first_seen_time UDM field.
- event.idm.entity.entity.asset.attribute.labels: Newly mapped chassis_type, vendor.value, vendor.link, os_address_width, invoice_number, assigned, os_domain, can_print, cd_rom, unverified, asset.value, owned_by.link, assigned_to.link, managed_by.link, asset.link, hardware_substatus, hardware_status, sys_domain.value, processor_name.value, processor_name.link, cpu_core_thread, cpu_manufacturer.value, cpu_manufacturer.link, department.value, default_gateway, po_number, internet_facing, sys_class_path, u_technical_hold, cost_cc, order_date, attested, fault_count, sys_created_by raw log fields with event.idm.entity.entity.asset.attribute.labels UDM field.
- event.idm.entity.relations.entity.asset.attribute.labels: Newly mapped dv_operational_status, u_glp, u_gmp, manufacturer_company_name, u_other_gxp, u_gcp, managed_by_group_name, managed_by_User_Name, cpu_count, environment, owned_by_User_Name, region, site, support_group_name, u_backup_method, u_backup_required, virtual raw log fields with event.idm.entity.relations.entity.asset.attribute.labels` UDM field.
- event.idm.entity.relations.entity.asset.hostname: Removed mapping of host_name, name, client_name from event.idm.entity.relations.entity.asset.hostname UDM field to change the entity type from USER to ASSET.
- event.idm.entity.entity.asset.hostname: Mapped host_name, name, client_name raw log field to event.idm.entity.entity.asset.hostname UDM field.
- event.idm.entity.relations.entity.asset.ip: Removed mapping of ip_address from event.idm.entity.relations.entity.asset.ip UDM field to change the entity type from USER to ASSET.
- event.idm.entity.entity.asset.ip: Mapped ip_address raw log field to event.idm.entity.entity.asset.ip UDM field.
- event.idm.entity.relations.entity.asset.hostname: Removed mapping of host_name from event.idm.entity.relations.entity.asset.hostname UDM field to change the entity type from USER to ASSET.
- event.idm.entity.relations.entity.user.username: Mapped host_name raw log field to event.idm.entity.relations.entity.user.username UDM field.
- event.idm.entity.relations.entity.asset.hardware.model: Changed mapping for event.idm.entity.relations.entity.asset.hardware.model from model_id.value to dv_model_id UDM field.
- Updated subcategory check to include Computer for mapping to LAPTOP.
- event.idm.read_only_udm.entity.user.userid: Newly mapped sys_id raw log field with event.idm.read_only_udm.entity.user.userid UDM field when userid field is not present.
2025-03-27 Enhancement:
- event.idm.entity.entity.user.userid: Newly mapped owned_by.value raw log field with entity.user.userid UDM field.
- event.idm.entity.entity.user.product_object_id: Newly mapped owned_by.value raw log field with entity.user.product_object_id UDM field.
- event.idm.entity.entity.user.userid: Newly mapped assigned_to.value raw log field with entity.user.product_object_id UDM field.
- event.idm.entity.entity.user.product_object_id: Newly mapped assigned_to.value raw log field with entity.user.product_object_id UDM field.
- When owned_by.value or assigned_to.value is available, then mapped event.idm.entity.entity.metadata.entity_type to USER.
- When category is End User Asset, Hardware, Physical Server, Printer, Workstation or Storage then mapped event.idm.entity.relation.entity_type as ASSET.
- When manufacturer data is available then mapped event.idm.entity.relation.entity_type as ASSET.
- Dropped the events when event.idm.entity.metadata.entity_type and event.idm.read_only_udm.metadata.event_type are not present.
2025-03-10 Enhancement:
- Changed mappings of fields from event.idm.entity.entity to event.idm.entity.relations.
- Changed mappings of fields from event.idm.entity.relations to event.idm.entity.entity.
- Changed metadata.entity_type from ASSET to USER.
2025-01-30 Enhancement:
- Mapped calendar_integration, u_ldap_source, u_show_popup, source, building, web_service_access_only, notification, enable_multifactor_authn, sso_source, sys_domain.display_value, sys_domain.link, u_itil_license_type, and u_assets_validated to entity.entity.asset.attribute.labels
- Mapped last_login_time to entity.relation.entity.user.last_login_time.
- Mapped x_bmgr_support_ent_bomgar_username, vip, zip, time_format, active, gender, failed_attempts, federated_id, internal_integration_user, u_business_line, department.link, introduction, preferred_language, manager.link, photo, avatar, time_zone, schedule, and correlation_id to entity.relation.entity.user.attribute.labels.
- Mapped street to entity.relation.entity.user.personal_address.name.
- Mapped department.display_value to entity.relation.entity.user.department.
- Mapped u_office to entity.relation.entity.user.company_name.
- Mapped title to entity.relation.entity.user.title.
- Mapped first_name to entity.relation.entity.user.first_name.
- Mapped last_name to entity.relation.entity.user.last_name.
- Mapped middle_name to entity.relation.entity.user.middle_name.
- Mapped manager.display_value to entity.relation.entity.user.managers.user_display_name.
- Mapped sys_domain_path, transaction_log, cost_center, sys_mod_count, and sys_tags to entity.entity.labels.
- Mapped employee_number, phone, home_phone, and mobile_phone to entity.relation.entity.user.phone_numbers.
- Mapped city to entity.relation.entity.user.personal_address.city.
- Mapped state to entity.relation.entity.user.personal_address.state.
2025-01-16 Enhancement:
- Mapped country to entity.location.country_or_region.
- Mapped u_site_code to entity.location.city.
- Mapped u_region to entity_labels.
- Mapped location.display_value to entity.labels.
- Mapped location.link to entity.labels.
- Mapped email to _relation.entity.user.email_addresses.
2024-10-16 Enhancement:
- Mapped sys_id to entity.asset.product_object_id.
2024-07-02 Enhancement:
- Mapped u_sima_bs_activation_date, attestation_status, u_oracle_asm_lun_size, u_app_resource_jndi_name, is_encrypted, monitor, operational_status, u_updated_ci, u_cluster_node, firewall_status, skip_sync, u_excluded, u_data_classification, u_sla_report, u_restriction, u_rack_slot, u_account_aztech_oe.link, u_account_aztech_oedisplay_value, u_organisational_entity.link, u_organisational_entity.display_value, assignment_group.link, assignment_group.display_value, cost_center.link, cost_center.display_value, u_service_instance, u_local_oe_cost_center, managed_by, u_mode_of_operation, install_status, and u_provider_tag to entity.labels.
- Mapped u_build_user to entity.user.email_addresses.
2024-01-23 Bug-Fix-
- Changed the entire mapping for logs which are of ASSET type.
- Mapped metadata.entity_type to ASSET and relations.entity_type to USER.
- Changed mapping of label_ci_link from entity.entity.user.attribute.labels to relation.entity.user.attribute.labels.
- Changed mapping of label_value from entity.entity.user.attribute.labels to relation.entity.user.attribute.labels.
- Changed mapping of label_sys_class_name from entity.entity.user.attribute.labels to relation.entity.user.attribute.labels.
- Changed mapping of first_discovered from asset_entity.asset.last_discover_time to entity.entity.asset.last_discover_time.
- Changed mapping of last_discovered from asset_entity.asset.first_discover_time to entity.entity.asset.first_discover_time.
- Changed mapping of sys_updated_on from asset_entity.asset.system_last_update_time to entity.entity.asset.system_last_update_time".
- Changed mapping of category from asset_entity.asset.category to entity.entity.asset.category.
- Changed mapping of u_sub_status from asset_entity.asset.deployment_status to "entity.entity.asset.deployment_status.
- Changed mapping of subcategory from asset_entity.asset.type to entity.entity.asset.type.
- Changed mapping of name from asset_entity.asset.hostname to entity.entity.asset.hostname.
- Changed mapping of _lan1 and _lan2 and _ip from asset_entity.asset.ip to entity.entity.asset.ip.
- Changed mapping of _mac from asset_entity.asset.mac to entity.entity.asset.mac.
- Changed mapping of dns_domain from asset_entity.asset.network_domain to entity.entity.asset.network_domain.
- Changed mapping of os from asset_entity.asset.platform_software.platform to entity.entity.asset.platform_software.platform.
- Changed mapping of os_version and os_service_pack from asset_entity.asset.platform_software.platform_patch_level to entity.entity.asset.platform_software.platform_patch_level.
- Changed mapping of asset_tag from asset_entity.asset.asset_id to entity.entity.asset.asset_id.
- Changed mapping of WMI_Asset_ID from asset_entity.asset.asset_id to entity.entity.asset.asset_id.
- Changed mapping of _asset_software and software from asset_entity.asset.software to entity.entity.asset.software.
- Changed mapping of client_name from asset_entity.asset.hostname to entity.entity.asset.hostname.
- Changed mapping of client_id from entity.entity.user.userid to relation.entity.user.userid.
- Changed mapping of ips from asset_entity.asset.ip to entity.entity.asset.ip.
- Changed mapping of hardware from asset_entity.asset.hardware to entity.entity.asset.hardware.
- Changed mapping of DNS_Name from asset_entity.asset.network_domain to entity.entity.asset.network_domain.
- Changed mapping of sys_id from entity.entity.user.product_object_id to relation.entity.user.product_object_id.
- Changed mapping of WMI_Service_Tag from entity.entity.user.product_object_id to relation.entity.user.product_object_id.
- Changed mapping of u_owner_name_computer from entity.entity.user.user_display_name to relation.entity.user.user_display_name.
- Changed mapping of roles from entity.entity.user.attribute.roles to relation.entity.user.attribute.roles.
2023-05-31 Enhancement-
- Removed unwanted declarations.
- Wrote merge blocks separately to avoid conflict.
2023-05-22 Enhancement-Added mappings for the following fields-
- Mapped number to security_result.detection_fields.
- Mapped cmdb_ci to event.idm.entity.entity.user.attribute.labels.
- Mapped host_name to event.idm.entity.entity.asset.hostname.
- Mapped short_description to security_result.description.
- Mapped description to security_result.action_details.
- Mapped sys_class_name to event.idm.entity.entity.user.attribute.labels.
- Mapped u_aam_category to security_result.category_details.
- Mapped u_aam_subcategory to security_result.detection_fields.
2022-07-08 Enhancement:
- Modified mapping for user_role from entity.user.role_name to entity.user.attribute.roles.
2022-06-10 Enhancement- The newly ingested logs have been parsed and mapped to the following fields:
- WMI_Service_Tag mapped to entity.user.product_object_id.
- User_Name mapped to entity.user.user_display_name.
- user_role mapped to entity.user.role_name.
- OperatingSystemRole mapped to entity.asset.type.
- MAC_Addresses mapped to entity.asset.mac.
- OS mapped to entity.asset.platform_software.platform.
- WMI_Asset_ID mapped to entity.asset.asset_id.
- WindowsOperatingSystem mapped to entity.asset.software.
- SerialNumber mapped to entity.asset.product_object_id.
- client_name mapped to entity.asset.hostnam.
- client_id mapped to entity.user.userid.
- CIDR_Subnet_String mapped to entity.asset.ip.
- Computer_Serial_Number mapped to entity.asset.hardware.serial_number.
- Computer_Serial_Number mapped to entity.asset.hardware.manufacturer.
- Computer_Serial_Number mapped to entity.asset.hardware.model.
- DNS_Name mapped to entity.asset.network_domain.
2022-04-13 Enhancement-Parsed the CEF format logs having different message format.
Mapped the following additional fields: event, event_ts, instance, userid, source_ip.