[[["Easy to understand","easyToUnderstand","thumb-up"],["Solved my problem","solvedMyProblem","thumb-up"],["Other","otherUp","thumb-up"]],[["Hard to understand","hardToUnderstand","thumb-down"],["Incorrect information or sample code","incorrectInformationOrSampleCode","thumb-down"],["Missing the information/samples I need","missingTheInformationSamplesINeed","thumb-down"],["Other","otherDown","thumb-down"]],["Last updated 2025-03-13 UTC."],[[["The CORELIGHT change log shows frequent updates, including the addition of support for new fields in various log types, such as those for v27.12 and updated suricata_corelight schemas."],["Several updates focus on mapping specific fields to enhance data extraction and organization, as seen with '_write_ts', 'extracted', 'network.dns.response', 'assigned_addr', and various TLS certificate fields."],["CORELIGHT has been enhanced to handle base64 decoded values, extract key-value pairs based on delimiters, and modify severity based on raw rules."],["Alignment of 'principal/target.hostname' and 'principal/target.asset.hostname' mappings was added to ensure consistency, alongside adding normalization for Suricata Eve alerts."],["The system now includes support for updated suricata, corelight_metrics_*, and intel log types, along with validation for the \"entity_type\" field."]]],[]]