Stay organized with collections
Save and categorize content based on your preferences.
Change log for MCAFEE_IPS
Date
Changes
2025-07.02
- Added Grok patterns to parse the unparsed logs.
- Added split operation and for loop to convert Ip's into an array of principal_ip.
- 'event.idm.read_only_udm.principal.asset.ip' and 'event.idm.read_only_udm.principal.ip': Newly mapped 'principal_ip' raw log field with 'event.idm.read_only_udm.principal.ip' and 'event.idm.read_only_udm.principal.asset.ip' UDM fields.
- Added has_principal and has_target to identify the event type.
- Added on_error and if conditional statements wherever required.
[[["Easy to understand","easyToUnderstand","thumb-up"],["Solved my problem","solvedMyProblem","thumb-up"],["Other","otherUp","thumb-up"]],[["Hard to understand","hardToUnderstand","thumb-down"],["Incorrect information or sample code","incorrectInformationOrSampleCode","thumb-down"],["Missing the information/samples I need","missingTheInformationSamplesINeed","thumb-down"],["Other","otherDown","thumb-down"]],["Last updated 2025-08-18 UTC."],[],[]]