Support 22 query commands and automated response model - Tested on V5.0.2_2h build 4753
* aiwaf-system-status
* aiwaf-users
* aiwaf-commit-changes
* aiwaf-revert-changes
* aiwaf-user-defined-rules
* aiwaf-ip-blacklist-rules
* aiwaf-ip-whitelist-rules
* aiwaf-ip-block-pages
* aiwaf-add-ip-blacklist-rule
* aiwaf-remove-ip-blacklist-rule
* aiwaf-add-ip-whitelist-rule
* aiwaf-remove-ip-whitelist-rule
* aiwaf-add-ip-blacklist-item
* aiwaf-remove-ip-blacklist-item
* aiwaf-add-ip-whitelist-item
* aiwaf-remove-ip-whitelist-item
* aiwaf-add-ip-blacklist-item-batch
* aiwaf-remove-ip-blacklist-item-batch
* aiwaf-add-ip-whitelist-item-batch
* aiwaf-remove-ip-whitelist-item-batch
* aiwaf-add-user-defined-rule
* aiwaf-remove-user-defined-rule
First release
- Support fraud account search command
- Support fraud phone search command
First release
- Support Juniper SSG dedicated log parser, log schemas, logger models, and dashboards
First release
- Support Juniper SRX dedicated log parser, log schemas, logger models, and dashboards
Changelog
- Added support for CloudFront-scope response targets via AWS WAF. Select Cloudfront in region dropbox in AWS WAF target response screen. (Empty value cannot be applied)
- Added support for CloudFront in AWS WAF related commands by using region=cloudfront option.
Support VPC Endpoint for AWS cloudwatch metrics, stats query.
First release
- Support dedicated log parser, log schema, logger model, dashboard, and detection rule.
New features
- Added sonar-indicators query command
- Added syslog query command
Improvements
- Support AWS VPC Endpoint
- Support AWS Network Firewall logs
- Support AWS CloudWatch VPC Flow custom log format
- Support AWS STS authentication
- Added log start/end regex option to AWS S3 Daily Directory watcher
- AWS S3 Daily Directory Watcher can now collect logs when some target paths contain OID and some target paths don't contain OID
- Added Date regex option for AWS S3 Daily Directory Watcher
- Support Playbook execution for AWS app commands
Bugfix
- Fixed C-TAS app not being installed in Sentry, leading to being unable to use C-TAS logger model in Sentry
First release
- Support log parser, log scheams, logger model, and dashboards
Changelog
* Improved parser for following log types: 106001, 313001, 106014, 199013~199019
Added log types and detection rules
- Supports audit and item usage log types
- Supports brute-force attack, item destruction, and item mass deletion detection rules
Support create, enable loggers query commands
- sonar-create-loggers
- sonar-enable-loggers
First release
- includes dedicated log parser, logger model, log schemas, and dashboards
First release
- Support dedicated log parser, log schemas, logger model, and dashboards
Bug fix
- Fixed ClassCastException when "Swap addresses" setting is changed and parse command is executed
- Reverted "Swap addresses" option type back to textbox from checkbox
- Fixed action field value being null on 106007 log type
- Fixed parse failure on 302013 log type
### Dashboard Improvements and API Sequential Execution
- Added asset world map widget
- Improved dashboard query performance using behavior profile
- Supported sequential execution option to minimize concurrent call errors in Criminal IP Free Plan
Support dashboard, widget, and dataset clone query commands
- sonar-dashboards
- sonar-widgets
- sonar-datasets
- sonar-clone-dashboards
- sonar-clone-widgets
- sonar-clone-datasets
Added Log Schemas and Dashboards
- 8 new Log Schemas: QueryPie ACL Change (qp-acl-server), QueryPie Activity (qp-activity), QueryPie Admin Role (qp-admin-role), QueryPie Audit Log Export k(qp-audit-log-export), QueryPie Server Access (qp-server-access), QueryPie Server Audit (qp-server-audit), QueryPie Server Session (qp-server-session), QueryPie DML Snapshot (qp-dml-snapshot)
- Updated Log Schemas: QueryPie ACL Change (qp-acl-change), QueryPie Auth (qp-auth), QueryPie DB Access (qp-db-access), QueryPie SQL Audit (qp-sql-audit)
- Dashboards: Added new Dashboards for new Log Schemas.