Changes
- Add support for setting timeout for Rest API (use connection profile option)
Changes
- Resolve parsing errors due to unspecified Syslog PRI part range
First release
- Log parser, log schemas, logger model, and dashboard
- Normalized message codes
* ivanti-vpn-login: AUT24414, AUT31985, AUT22673
* ivanti-vpn-auth: AUT32033, AUT31829, AUT22886, AUT24326, AUT32051, AUT24327, AUT22927
* ivanti-vpn-tunnel: NWC30477, NWC23464, NWC23465, NWC30993, NWC23508, NWC32164, NWC32185, NWC32001, NWC24328, ERR24670, ERR31271
* ivanti-vpn-host-checker: AUT24803, AUT31984
Improvements
- Support for event logs in firmware 2.1.21 log format with headers removed (mds-event)
First release
- v3.0.8 or above
- Darktrace log parser, log schema, logger model, and dashboard
Changes
- Improved parser to correct CEF format inconsistencies (missing escapes) in EDR_POWER_SHELL logs to be parsed
Improvements
- Supports log formats with yyyyMMddHHmmss prefixed to the <PRI> part
- Collect and parse DDoS logs.
Changelog
- Fixed parsing errors in Giga units for byte, packet related fields
- Normalized action field's value.
- Added wildcard to table namespace of dataset.
Changelog
- Added 382 new website category and subcategory codes.
- Removed sc_bytes, added msg_len from OfficeGuard log schema.
First release
- Support log parser, 4 log schemas, logger model, and dashboard for DBSAFER DB.
First release
- Support AIRTMS log parser, log schemas, logger model, and dashboard.
Changelog
- Changed parsing timestamps by epoch instead of date string
Changelog
- Added blocking direction option to response configuration.
- Added wildcard namespace to dataset configurations.
Support TrusGuard 3.1.0 version.
- (NEW) module_flag 1018: tg-iface-traffic
- Parsing by module_flag regardless of type value for version 3 logs.
Changelog
- Added MARS SLF log parser, log schemas, logger model, and dashboards
Support alert log formats
* Added support for parsing alert logs and added log schema
Changelog
- Separately extracted the malware, tool, campaign, and vulnerability fields from the relation field in the Quaxar threat intelligence feed to facilitate data processing. Renamed the existing malware field to malware_family.
- Fixed a bug that resulted in duplicate records of the same IoC when downloading Quaxar threat intelligence feeds.
- Fixed NPE when running quaxar-attack-surface-reports, quaxar-exposed-services commands (service response changed)
- Fixed JSON parsing error when running quaxar-exposure-service-stats and quaxar-exposure-trends commands (service response changed)
Added 37 WAPPLES query commands:
* wapples-acl-rules
* wapples-add-acl-rule
* wapples-add-acl-rule-batch
* wapples-add-snmp-trap-server
* wapples-add-syslog-server
* wapples-alerts
* wapples-audit-snmp-trap-categories
* wapples-audit-syslog-categories
* wapples-cpu-info
* wapples-disk-partitions
* wapples-ha-info
* wapples-intrusion-snmp-trap-categories
* wapples-intrusion-syslog-categories
* wapples-intrusion-syslog-fields
* wapples-license
* wapples-remove-acl-rule
* wapples-remove-acl-rule-batch
* wapples-remove-snmp-trap-server
* wapples-remove-syslog-server
* wapples-set-audit-snmp-trap-categories
* wapples-set-audit-syslog-categories
* wapples-set-intrusion-snmp-trap-categories
* wapples-set-intrusion-syslog-categories
* wapples-set-intrusion-syslog-fields
* wapples-set-snmp-trap-config
* wapples-set-syslog-ca-certificate
* wapples-set-syslog-chain-certificate
* wapples-set-syslog-client-certificate
* wapples-set-syslog-config
* wapples-snmp-trap-config
* wapples-snmp-trap-servers
* wapples-syslog-config
* wapples-syslog-servers
* wapples-syslog-tls-certificates
* wapples-sysmon-stats
* wapples-users
* wapples-version
Improvement
* Modified slack-send-batch query command to be available in stream queries.
Changes
- Support cancel the withflow-rules command while it is running