Change log for CISCO_VPN
Date | Changes |
---|---|
2024-12-05 | Enhancement:
- Added support to parse new format of unparsed SYSLOG logs. |
2024-11-07 | Enhancement:
- Added support to parse new format of unparsed SYSLOG logs. |
2024-07-02 | Enhancement:
- Added support to parse new format of unparsed logs. - Changed "src_ip" mapping from "target.ip" to "principal.ip". - Changed "dst_ip" mapping from "principal.ip" to "target.ip". |
2024-05-27 | Enhancement:
- Added support to parse dropped logs that wer dropped due to UDM validation and a missing target field. |
2024-03-25 | Enhancement:
- Added support to parse new format unparsed logs. |
2024-02-23 | Enhancement:
- Parsed the logs with event IDs "733100","725011","737034","737006","106023". - Added "on_error" check for Grok patterns. |
2024-01-15 | Enhancement:
- Added new Grok patterns for the support of new patterns of syslog logs. - If "observer.ip" is a valid IP value, mapped "observer" to "observer.ip". |
2022-08-19 | Enhancement - Parsed The logs with event_id's :- "113012","113015","722033","722035","716058","716002","716038","722028","722032","722034","716001","716059","305012","106015",
"305011","302015","302016","725016","302020","302014","302013","302021","106006","110002","605005","605004","106001","734003","734001","725002","607001","725001","106012", "725005","611101","611102","402119","737026","313009","725007","725003","109207","500003","500004","444100","444102","602303","602304","315011","602101","302004". - Updated the event_type from "GENERIC_EVENT" to "USER_UNCATEGORIZED" when event_id="113014". - Updated the event_type from "GENERIC_EVENT" to "USER_LOGIN" when event_id="113016". |