Added Sonar app manifest.
Added Sonar app manifest.
First Release
- MFI CSV, TSV, WELF Parser
- MFI raw, packet log schemas
- MFI intrusion detection dashboard
Sonar App Support
- Web Insights TCP, UDP Logger Model
- Web Insights v5.0 early log format support
- Web Insights dashboard
First release. Support up to v2.7.5.
- Dedicated log parser
- Logger model
- Traffic and Detection dashboards
First release
- MF2 v2, v3, v4 log parser
- MF2 logger model
- MF2 traffic dashboard
Support Logpresso Sonat platform
- Added sonar dashboards, log schemas, loggers.
First release
- 1Password Sign-in logger and log schema
- 1Password Sign-in dashboard
- 1password-signin-attempts query command
First Release
* Trellix IPS default log format parser
* Trellix IPS Logger Model
* Trellix IPS Intrusion Detection Dashboard
First Release
- MFD v1 log parser
- MFD logger model
- MFD dashboards (6 types)
First Release
* WAPPLES v6, v4 log parser
* WAPPLES logger model
* WAPPLES intrusion detection, performance dashboards
First release
* Dedicated parser (supports log format config)
* Logger model
* Access log dashboard
Bug patch
* Fixed feed sync issue due to time range filtering when querying MISP attributes.
Added parsers, log schemas, dashboards.
* High performance log parser
* Log Schemas
* BLUEMAX NGF HA Status
* BLUEMAX NGF HA Traffic Statistics
* BLUEMAX NGF Interface Statistics
* BLUEMAX NGF NAT Rule Statistics
* BLUEMAX NGF NAT Traffic Statistics
* BLUEMAX NGF Performance
* BLUEMAX NGF Rule Statistics
* BLUEMAX NGF Traffic Statistics
* Traffic, Performance, HA dashboards
First release
* Provides a parser, logger model, and dashboard
Added IP request dashboard and query command.
* genian-nac-ip-requests
First Release
Support parser for 23 log formats
- Supported message codes: 106015, 106021, 106023, 106100, 302013, 302014, 302015, 302016, 302020, 302021, 305006, 305011, 305012, 313005, 410001, 500004, 605005, 710002, 710003, 710005, 710006, 725002, 725016
First release
- Support for a proprietary collector to receive Web Insight TCP syslogs.
- Support v3, v4.1, v5.0 log formats.
First release. Provides the Pub/Sub logger and the following commands:
* gcp-pubsub-messages
* gcp-pubsub-publish
Added commands for [NGFCTI TAXII API](https://ngfcti.kfisac.or.kr/assets/API/index.html).
* ngfcti-advisories - Get security advisories from NGFCTI service.
* ngfcti-alerts - Get alerts from NGFCTI service.
* ngfcti-crisis-alerts - Get crisis alerts from NGFCTI service.
* ngfcti-emergencies - Get emergency alerts from NGFCTI service.
* ngfcti-fsc-notices - Get financial service commission notices from NGFCTI service.
* ngfcti-ip-watchlist - Get IP watchlist from NGFCTI service.
* ngfcti-malware-urls - Get malware deployment URLs from NGFCTI service.
* ngfcti-news - Get security news from NGFCTI service.
* ngfcti-phishing-urls - Get phishing URLs from NGFCTI service.
* ngfcti-threat-reports - Get threat reports from NGFCTI service.