Stay organized with collections
Save and categorize content based on your preferences.
Change log for GUARDIUM
Date
Changes
2025-01-28
Enhancement:
- Added support to handle unparsed SYSLOG logs.
2024-12-26
Enhancement:
- Added support to handle unparsed SYSLOG logs.
2024-08-05
Enhancement:
- Added support to handle unparsed LEEF format logs.
2024-06-07
Enhancement:
- Mapped "query" to "additional.fields".
2024-04-01
Enhancement:
- Added mapping for "severity" with value "Very-High" to "security_result.severity"
- Added gsub function to manage "space" in the "spt" parameter before mapping to "principal.port".
2023-12-15
Enhancement:
- Added support for LEEF format logs.
2022-10-06
Added Grok pattern to parse syslog logs. - Changed 'observer.hostname' mapping to 'intermediary.hostname'.
- Changed 'observer.ip' mapping to 'intermediary.hostname'.
2022-09-06
Enhancement:
- Migrated customer-specific parser to default and also removed customer-specific parser.
2022-07-08
Enhancement:
- Modified mapping for "user_role" from "target.user.role_name" to "target.user.attribute.roles".
2022-06-30
Enhancement: Added mappings for the following fields:
- Mapped "timestamp" to "metadata.collected_timestamp"
- Mapped SQL to "security_result.summary"
2022-05-17
Enhancement: Modified the parser to support logs that are in "CEF" format.
2022-03-24
Enhancement: Added mappings for the following new fields:
"Full SQL ID" field mapped to "event.idm.read_only_udm.target.process.pid".
"Session ID" field mapped to "event.idm.read_only_udm.network.session_id".
[[["Easy to understand","easyToUnderstand","thumb-up"],["Solved my problem","solvedMyProblem","thumb-up"],["Other","otherUp","thumb-up"]],[["Hard to understand","hardToUnderstand","thumb-down"],["Incorrect information or sample code","incorrectInformationOrSampleCode","thumb-down"],["Missing the information/samples I need","missingTheInformationSamplesINeed","thumb-down"],["Other","otherDown","thumb-down"]],["Last updated 2025-08-29 UTC."],[[["\u003cp\u003eGUARDIUM has enhanced its log handling capabilities by adding support for unparsed SYSLOG and LEEF format logs.\u003c/p\u003e\n"],["\u003cp\u003eSeveral mappings have been added or modified for fields such as "query," "severity," "timestamp," and SQL, improving data organization and retrieval.\u003c/p\u003e\n"],["\u003cp\u003eThe system now supports logs in CEF format and includes Grok patterns for parsing syslog logs.\u003c/p\u003e\n"],["\u003cp\u003eCustomer-specific parsers have been migrated to the default parser, simplifying configuration.\u003c/p\u003e\n"],["\u003cp\u003eMappings for fields like 'observer.hostname' and 'observer.ip' have been updated to use 'intermediary.hostname'.\u003c/p\u003e\n"]]],[],null,["# Change log for GUARDIUM\n======================="]]