Added 13 extended commands for Flow collaboration tool integration
- flow-bots: Retrieve a list of notification bots
- flow-departments: Retrieve a list of departments
- flow-employees: Retrieve a list of members
- flow-send-notification: Send a single notification
- flow-send-notification-batch: Send notifications in batch
- flow-activate-employee: Activate a member
- flow-activate-employee-batch: Activate members in batch
- flow-deactivate-employee: Deactivate a member
- flow-deactivate-employee-batch: Deactivate members in batch
- flow-create-post: Create a post
- flow-create-post-batch: Create posts in batch
- flow-create-task: Create a task
- flow-create-task-batch: Create tasks in batch
Bug fix
- Fixed an issue where copies created by sonar-clone-dashboards, sonar-clone-datasets, and sonar-clone-widgets were deleted during app reinstallation.
Added Endpoint Filters for SentinelOne Application Risk
- Endpoint Name, Endpoint UUID
Support for SentinelOne Cloud Funnel log collector and a dedicated UI
- New log schemas: sentinelone-application-endpoint, sentinelone-application-risk, sentinelone-cross-process-event, sentinelone-dns-event, sentinelone-file-event, sentinelone-group-event, sentinelone-indicator-event, sentinelone-login-event, sentinelone-process-event, sentinelone-registry-event, sentinelone-scheduled-task-event, sentinelone-session, sentinelone-threat, sentinelone-threat-notes, sentinelone-threat-timeline, sentinelone-vuln-event, sentinelone-webfilter
- New query commands: sentinelone-add-threat-note, sentinelone-app-cves, sentinelone-app-endpoints, sentinelone-app-risks, sentinelone-delete-threat-note, sentinelone-events, sentinelone-query, sentinelone-star-custom-rules, sentinelone-threat-notes, sentinelone-threat-timeline, sentinelone-threats, sentinelone-update-threat-note
Fixed WAF Log Parser:
- Resolved errors handling the **responseCodeSent** field.
Feature Improvements
- New Event Support: Added support for the system_monitor event type.
- Audit Log Expansion: Extended the fields for system_event audit logs.
- Resource Monitoring: Implemented per-core CPU usage parsing for system_resource.
- Schema Update: Added new fields for Event Log v1.1.7.
- Stability Enhancements: Improved logger model structure and parser stability.
- Data Integrity: Enhanced field type accuracy and standardized (normalized) field names.
- UI/UX: Updated the dashboard.
Support for commands to search for employees and departments
First Release
- Provides parser, logger model, log schema, and dashboard for AXGATE SSLVPN logs
- Supports parsing of USERAUTH, AUDIT, and SESSION logs
Add S3 DNS, audit log collector, and dashboards
Bugfix
- Implement multi-profile guard for batch commands
Feature Enhancements
- Expanded Command Support: Added 13 new extended commands and integrated blocking synchronization.
- CEF Log Support: Now supports a CEF (Common Event Format) log parser.
- Needs Logpresso Sonar version 4.0.2502.0 or above.
Feature Improvements
- Block Integration & 13 New Extended Commands: Added integration for blocking features and introduced 13 additional extended commands.
- Needs Logpresso Sonar version 4.0.2502.0 or above.
New Log Field Parsing Support
- INTEL Log Type: Added support for parsing risk(level) and threat category(assessment) fields.
- ALERT Log Type: Added support for parsing risk(level) and nested event data by log type.
Feature Improvements
- Improved logic for handling whitespace in dates.
- Added parsing failure handling for unsupported log types.
Fixed parsing failure caused by mismatched log type names.
Support 21 query commands
- umbrella-activity-logs
- umbrella-domain-whois
- umbrella-domain-risk-score
- umbrella-domain-security
- umbrella-domain-category
- umbrella-domain-whois-batch
- umbrella-domain-risk-score-batch
- umbrella-domain-security-batch
- umbrella-domain-category-batch
- umbrella-top-destinations
- umbrella-top-identities
- umbrella-top-threats
- umbrella-apps
- umbrella-summary
- umbrella-networks
- umbrella-categories
- umbrella-destination-lists
- umbrella-destinations
- umbrella-category-stats
- umbrella-destination-stats
- umbrella-api-usage-summary
First release
- Attack Graph, Knowledge Graph, Network Topology
Add logger model
- Provide **Chakra Max DAC (SFTP)** logger model.
Bug Fix: Extended Command Visibility
- Fixed an issue where certain extended commands were not being displayed.
- The azure-activity-logs command is now visible.
- Note: Azure Monitoring Reader permissions must be granted to use this feature.
Bug Fix: Connection Profile Timeout Unit
- Fixed the timeout unit to be applied in seconds (previously applied in milliseconds).
- For sites using version 1.4.2512.0, please re-enter the timeout options.