Change log for WINDOWS_SYSMON
Date | Changes |
---|---|
2024-12-03 | - Added "gsub" for message, "protocol" , "sourceIp" and "destinationIp".
|
2024-11-28 | - Added support for the "OriginalFileName" field and mapped it to "src.process.file.full_path" for "EventID" = 7 and "EventID" = 8.
- Added support for "udm_event_type" for "EventID" = 27. |
2024-11-28 | - Added support for the "OriginalFileName" field and mapped it to "src.process.file.full_path" for "EventID" = 7 and "EventID" = 8.
- Added support for "udm_event_type" for "EventID" = 27. |
2024-10-04 | - Added support for the OriginalFileName field and map it to src.process.file.full_path for EventID = 1.
|
2024-09-03 | Enhancement:
Added a Grok pattern to map the "SourceUser" field value to "principal.user.userid" and "principal.administrative_domain", and the "TargetUser" field value to "target.user.userid" and "target.administrative_domain". |
2024-09-03 | Enhancement:
Added a Grok pattern to map the "SourceUser" field value to "principal.user.userid" and "principal.administrative_domain", and the "TargetUser" field value to "target.user.userid" and "target.administrative_domain". |
2024-08-02 | Enhancement:
- Mapped "SourceUser" to "principal.user.userid" and "TargetUser" to "target.user.userid". |
2024-05-01 | Updated logic for ConfigurationFileHash. |
2024-04-24 | Updated mapping of "Company", "Description", "Product" and "FileVersion" fields to "target.asset.software". |
2024-03-15 | Added new attributes and supported for new log formats. |
2024-01-17 | Added mapping of "SourceProcessGUID", "TargetProcessGUID" XML log field for "EventID 10". |
2023-11-29 | Aligned 'principal/target.hostname' and 'principal/target.asset.hostname' mapping. |
2023-10-27 | Added mapping for "ProviderGuid", "IntegrityLevel", "LogonId", "ThreadID" and "Channel" raw log fields. Enhancements: - Mapped "ProcessID" to "observer.process.pid" - Mapped "ProcessId" to "principal/target.process.pid" - Mapped "CurrentDirectory" to "additional.field.key/value" |
2023-09-06 | Added support for Microsoft Windows Sysmon "Event ID 29 |
2023-01-26 | Enhancement:
- Mapped "FileVersion" to "principal.asset.software.version". - Mapped "Description" to "principal.asset.software.description". - Mapped "Product" to "principal.asset.software.name". - Mapped "Company" to "principal.asset.software.vendor_name". |
2022-08-12 | Added mapping of 'CurrentDirectory' field for 'PROCESS_LAUNCH' events.
|
2022-04-09 | Added support for logs coming with ExecutionProcessID field. |
2022-04-08 | Added support to XML format logs. |