Stay organized with collections
Save and categorize content based on your preferences.
Change log for EXTREME_SWITCH
Date
Changes
2023-12-19
Enhancement:
- Added a new Grok pattern to support new type of SYSLOG logs.
- Added new Grok patterns to parse "description".
- Mapped "protocol", "VrId", "SlppRxVlan", "SlppIncomingVlanId", "Type", "Cause" to "additional.fields".
- Mapped "session_id" to "network.session_id"
- Mapped "SlppSrcMacAddress" to "principal.mac".
- Mapped "intermediary_ip" to "intermediary.ip.
- Mapped "ver" to "metadata.version".
- Mapped "rcPortVLacpAdminEnable", "rcSyslogHostMapFatalSeverity", "rcSyslogHostMapWarningSeverity", "rcSyslogHostRowStatus", "rcSyslogHostFacility", "rcSyslogHostAddressType", "rcSyslogHostMapErrorSeverity", "rcSyslogHostMapInfoSeverity", "rcSyslogHostSeverity", "rcSyslogHostEnable" to "security_result.detection_fields".
- Mapped "port" to "principal.port".
- Mapped "rcSyslogHostAddress" to "principal.hostname".
[[["Easy to understand","easyToUnderstand","thumb-up"],["Solved my problem","solvedMyProblem","thumb-up"],["Other","otherUp","thumb-up"]],[["Hard to understand","hardToUnderstand","thumb-down"],["Incorrect information or sample code","incorrectInformationOrSampleCode","thumb-down"],["Missing the information/samples I need","missingTheInformationSamplesINeed","thumb-down"],["Other","otherDown","thumb-down"]],["Last updated 2025-08-29 UTC."],[[["\u003cp\u003eThe EXTREME_SWITCH parser was newly created as of December 11, 2023.\u003c/p\u003e\n"],["\u003cp\u003eOn December 19, 2023, enhancements were made, including adding new Grok patterns for SYSLOG logs and parsing descriptions.\u003c/p\u003e\n"],["\u003cp\u003eMultiple fields were mapped to new or existing fields, such as "session_id" to "network.session_id" and "SlppSrcMacAddress" to "principal.mac".\u003c/p\u003e\n"],["\u003cp\u003eSeveral "rcSyslogHost" fields were mapped to "security_result.detection_fields", and "port" was mapped to "principal.port".\u003c/p\u003e\n"]]],[],null,["# Change log for EXTREME_SWITCH\n============================="]]