First Release
- Add FOCS firewall and application lookup commands
- Add FOCS malicious IP lookup, add, and delete commands
Adds VNet flow logs(v4) support and new query commands
Bug fix
- Fix missing login name mapping in sonar-sync-employees command
- Add user_guid to output fields in sonar-employees command
First Release
- Provides a parser, File/SFTP logger model, log schema and dashboard for TmaxSoft JEUS Access logs.
First Release
- Provides a parser, logger model, log schema and dashboard for SNIPER APTX logs
- Supported log type : System Status Information(5), File Analysis Logs(7), Network Detection Events(9), Ransomware Detection(10), File Detection(11)
Improved log schema rules in logger model
- Added `type` condition to `IPSEC` and `SSL VPN` rules
- Refined stream query to `Unknown` rule
First Release
- Provides a parser, logger model, log schema and dashboard for TACHYON Total Security 4.0 logs
- Supported category(Server, Agent, DeviceControl, SelfProtection)
Fix parser logic
- Implemented 31 fields from the RAW log
First Release
- Provides a parser, logger model and log schema for CTILab DTI Anomaly, Auto Profiling syslog messages.
Bug fixes and improvements for employee, department, and boss sync commands
- Common: Expanded required permission to company admin level and above; improved input error handling
- `sonar-sync-employees`: Fixed an issue where the query would not terminate when there are no employees to deactivate
- `sonar-sync-departments`: Departments with no changes are now included in the output (action=skip)
- `sonar-sync-bosses`: Department leads with no changes are now included in dry run output (action=skip)
First Release
- Supported parsers and collection models for 37 AhnLab XTG log types
- Added 35 log schemas
Enhancements
- Added `fortigate-virus` log schema
- Added `fortigate-webfilter` log schema
Bug Fixes
- Improved `action` field normalization in traffic logs: map `accept` to `PERMIT`
- Added wildcard support to dataset query table names
Feature Improvements
- Fix error in converting last_report
- Fix missing usage_type field error
- Enhance handling of empty hostname values
- Improve error message display for query results
First release
- Provides a dedicated logger model, schema and dashboard for CHAEWOOL UTMP logs.
Feature Modifications
- Dynamic Address Group Updates: * Renamed query commands.
- paloalto-ngfw-register-ip -> paloalto-ngfw-add-dynamic-address
- paloalto-ngfw-unregister-ip -> paloalto-ngfw-remove-dynamic-address
- paloalto-ngfw-registered-ips -> paloalto-ngfw-dynamic-addresses
- paloalto-ngfw-register-ip-batch -> paloalto-ngfw-add-dynamic-address-batch
- paloalto-ngfw-unregister-ip-batch -> paloalto-ngfw-remove-dynamic-address-batch
- Added validation for single tag registration.
- External SSH Connection Detection: * Updated the rule query.
First Release
- provides a dedicated log parser, logger model, and dashboard for KORNIC GLORY TESS TMS logs.
Add parsing support for new message codes
- Severity6 (Info): 111009
- Severity7 (Debug): 302015, 302016, 302020, 302021
Add new fields to `Cisco Firepower Session` schema
First Release
- Provides a parser, logger model, and log schema for Trellix Malware Analysis sandbox-based alerts.
Rename `HIPS_FW` log schema code
- CPP Host Firewall(`cpp-hips-fw`) -> CPP Session(`cpp-session`)