Change log for EXTREME_SWITCH
Date | Changes |
---|---|
2023-12-19 | Enhancement:
- Added a new Grok pattern to support new type of SYSLOG logs. - Added new Grok patterns to parse "description". - Mapped "protocol", "VrId", "SlppRxVlan", "SlppIncomingVlanId", "Type", "Cause" to "additional.fields". - Mapped "session_id" to "network.session_id" - Mapped "SlppSrcMacAddress" to "principal.mac". - Mapped "intermediary_ip" to "intermediary.ip. - Mapped "ver" to "metadata.version". - Mapped "rcPortVLacpAdminEnable", "rcSyslogHostMapFatalSeverity", "rcSyslogHostMapWarningSeverity", "rcSyslogHostRowStatus", "rcSyslogHostFacility", "rcSyslogHostAddressType", "rcSyslogHostMapErrorSeverity", "rcSyslogHostMapInfoSeverity", "rcSyslogHostSeverity", "rcSyslogHostEnable" to "security_result.detection_fields". - Mapped "port" to "principal.port". - Mapped "rcSyslogHostAddress" to "principal.hostname". |
2023-12-11 | - Newly created parser.
|