First release
Bug Fixes
- Fixed an issue where the logger did not operate correctly in a forward-server configuration environment.
Upgrade Instructions
- Before installing the app, back up the index name from the existing Elasticsearch logger settings.
- Upgrade the app.
- After the upgrade, the index name of the existing logger will be reset, so restore it using the backed-up value.
Notes
- For proper incremental collection, follow this sequence:
Disable the existing logger → Apply the app patch → Restore the index name in the logger settings → Enable the logger.
Add an option to include the decoded original log field (decoded_raw) in the logger and the akamai-security-events extended command.
Added 6 MITRE ATT&CK TTP detection rules.
First Release
- Supports sending message to Microsoft Teams channels via query commands.
First release
Changelog
- Added support for HTTP proxy options
- Changed the "Chat ID" field in the Telegram connection profile from mandatory to optional
- Added "chat-ids" option to the telegram-send extended command, allowing simultaneous message delivery to multiple chat rooms (takes precedence over the “Chat ID” in the connection profile)
- In the telegram-send-batch extended command, each row’s text and chat_id fields are now read to send messages individually to each chat room
Bug fix
- Fixed NPE that occurred when running command in remote mode
First release
- Support V3 alert and agent audit logger model for AhnLab Policy Center.
- Support 13 TTP detection rules.
Added tab-delimited parsing support for the sys_event log type.
Added error handling logic at logger startup
First release
- mat-instances
- mat-attributes
- mat-path2gc
- mat-class2gc
- mat-histogram
- mat-dominators
- mat-build
Fixed a parsing error in the extended_properties field during SharePoint data collection
Fixed compatibility issues in the sonar-users command
Changelog
* Fixed Parsing Logic for Double-Spaced Date Formats in the Parser
First release
- Support rule based pushdown optimization
Changed ordinal of log command rewriting planner.
Bug fix
- Fixed memory leak when failing to download feed consecutively
Support for dashboard image posting and http proxy configuration
- Requires files:write, channels:read, groups:read scope
Fixed an issue where data collection was interrupted due to an HTTP 416 error occurring when the offset value expired during logger operation.
First release
- KEV catalog query command and dashboard.