Stay organized with collections
Save and categorize content based on your preferences.
Change log for CISCO_IRONPORT
Date
Changes
2025-03-18
Enhancement:
- Modified Grok patterns to parse "hostname" to "principal.hostname" field.
- Mapped the "hostname" to "principal.hostname" properly ,previously processName was getting mapped to "principal.hostname" field.
- Mapped "processName" to "principal.process.file.full_path".
- Added a grok checker to extract the Ip address properly.
2025-02-26
Enhancement:
- Added support for syslog logs.
2025-01-31
Enhancement:
- Added support for SYSLOG logs.
2024-10-16
Enhancement:
- Mapped "res" to "security_result.action_details".
- Mapped "dkim" to "security_result.summary".
- Mapped "email" to "principal.user.email_addresses".
2024-09-19
Enhancement:
- Mapped "subject" to "additional.fields".
- Mapped "antivirus" to "security_result.detection_fields".
- Mapped "threat_level" to "security_result.detection_fields".
- Mapped "threat_category" to "security_result.detection_fields".
- Mapped "suspected_domain" to "security_result.detection_fields".
2024-06-11
Enhancement:
- Added Grok patterns to parse new format unparsed logs.
[[["Easy to understand","easyToUnderstand","thumb-up"],["Solved my problem","solvedMyProblem","thumb-up"],["Other","otherUp","thumb-up"]],[["Hard to understand","hardToUnderstand","thumb-down"],["Incorrect information or sample code","incorrectInformationOrSampleCode","thumb-down"],["Missing the information/samples I need","missingTheInformationSamplesINeed","thumb-down"],["Other","otherDown","thumb-down"]],["Last updated 2025-04-29 UTC."],[[["This document provides a change log for CISCO\\_IRONPORT, detailing updates and enhancements to the system."],["Recent enhancements include the addition of support for SYSLOG logs, introduced on January 31st, 2025."],["Multiple mapping updates have been made, including mapping fields such as \"res\", \"dkim\", and \"email\" to their respective target locations."],["Grok patterns have been added to parse newly formatted, previously unparsed logs, improving the system's ability to handle various log formats."],["A parser for CISCO\\_IRONPORT was newly created, as indicated by the change log entry on February 7th, 2024."]]],[]]