Change log for LACEWORK

Date Changes
2025-02-24 Enhancement:
- Mapped "ACCOUNT", "EVENT_CATEGORY", "subject.srcEvent.recipientAccountAlias", "DERIVED_FIELDS.SOURCE", "subject.srcEvent.event.userIdentity.accessKeyId", "subject.srcEvent.event.userIdentity.arn", "subject.srcEvent.event.errorCode", "subject.srcEvent.event.errorMessage", "subject.srcEvent.event.eventID", "subject.srcEvent.event.eventSource", "subject.srcEvent.event.userIdentity.sessionContext.attributes.mfaAuthenticated", "subject.srcEvent.username", "subject.startTime", "subject.srcEvent.eventName", "DERIVED_FIELDS.CATEGORY", "DERIVED_FIELDS.SUBCATEGORY", "subject.dstEvent.gbm_version", "subject.dstEvent.is_visible", "subject.dstEvent.severity", "subject.dstEvent.recipientAccountAlias", "subject.srcEvent.api", "subject.srcEvent.calltype", "subject.srcEvent.gbm_version", "subject.srcEvent.is_visible", and "subject.srcEvent.severity" to "additional.fields".
- Mapped "SUMMARY" to "metadata.description".
- Mapped "EVENT_TYPE" to "metadata.product_event_type".
- Mapped "EVENT_ID" to "metadata.product_log_id".
- Mapped "LINK" to "metadata.url_back_to_product".
- Mapped "subject.srcEvent.event.userAgent", "subject.srcEvent.source" to "network.http.user_agent".
- Mapped "subject.srcEvent.recipientAccountId" to "principal.user.groupid".
- Mapped "subject.srcEvent.principalId" to "principal.user.userid".
- Mapped "subject.srcEvent.event.awsRegion" to "security_result.about.asset.attribute.cloud.availability_zone".
- Mapped "subject.srcEvent.event.eventCategory" to "security_result.about.asset.category".
- Mapped "EVENT_NAME" to "security_result.category".
- Mapped "EVENT_NAME" to "security_result.summary".
- Mapped "subject.srcType" to "src.resource.resource_subtype".
- Mapped "subject.srcEvent.event.userIdentity.sessionContext.attributes.creationDate" to "metadata.event_timestamp".
- Mapped "subject.srcEvent.accountcaller" to "principal.resource.product_object_id".
- Mapped "subject.dstEvent.region" to "target.asset.location.name".
- Mapped "subject.dstEvent.accountcaller" to "target.resource.product_object_id".
- Mapped "subject.dstType" to "target.resource.resource_subtype".
- Mapped "subject.dstEvent.service" to "target.url".
- Mapped "subject.dstEvent.username" to "target.user.userid".
2024-11-15 Enhancement:
- Added support to handle JSON logs.
- Reduced the GENERIC_EVENT percentage.
2024-09-25 Enhancement:
- Added support to handle JSON logs.
2023-11-09 - Newly created parser.