Add Notion Database Query Command
First release
SNMP MIB Built-in
- [Based on PAN OS version 12.1](https://docs.paloaltonetworks.com/resources/snmp-mib-files)
* PAN-COMMON-MIB
* PAN-ENTITY-EXT-MIB
* PAN-GLOBAL-REG-MIB
* PAN-GLOBAL-TC-MIB
* PAN-LC-MIB
* PAN-PRODUCT-MIB
* PAN-TRAPS
Query commands
* snmpv2-bulkget, snmpv2-get, snmpv2-getnext, snmpv2-iftables, snmpv2-scalars, snmpv2-status, snmpv2-walk
*snmpv3-bulkget, snmpv3-get, snmpv3-getnext, snmpv3-iftables, snmpv3-scalars, snmpv3-status, snmpv3-walk
Support MIB extension by app resource
Add query commands and functions
- Add top and rare commands
- Add filter function
Changelog
* Supports CEF format for AUDIT, INTRUSION, SYSTEM logs
Changelog
* Fixed issue where data was missing when the signature field was null
* Removed data size limit (2048 bytes)
* Added support for collecting the raw_data field
* Fixed error message "version is not a supported option" when executing the webfront-block-ip command
Query Optimization Bug Fixes
- Support for wildcards during table and full-text conversion
- Ensuring semantic equivalence when converting null comparison using the fulltext command
- Compatibility ensured up to Logpresso Sonar version 4.0.2409.0
Changelog
- Fix to output error code instead of command failure if no virustotal-file-report search results are found or if hash value is invalid
Query Optimization
- Automatically converts table | search commands to a fulltext command
- Automatically converts log | search commands to a single log command
Misc.
- Renames the query_string field in sonar-stream-rules output fields to query field
- Requires **Logpresso Sonar 4.0.2507.0** or higher
Changelog
- Added syslog logger model
- Added query command genian-nac-node-apps, genian-nac-node-apps-batch
- Added ip option to query command genian-nac-remove-tag
- Improved parser - parse rows with log_id 100, with pipe(|) character delimiter, Node Up/Down log types
Changelog
* Time filter can be applied to dashboard
* Relaxed dependency requirements for app bundle compatibility
##### Added Log Schema and Collector Management Commands
* **log**: Search logs based on schema, model, or collector (supports raw search, aliasing, and subqueries)
* **sonar-log-schemas**: Retrieve a list of log schemas
* **sonar-log-schema-fields**: Retrieve log schema fields
* **sonar-loggers**: Retrieve a list of collectors
* **sonar-logger-models**: Retrieve a list of collection models
##### Added SSL Certificate Management Commands
* **sonar-check-cert-batch**: Batch verification of SSL certificates
##### Added Address Group and Blocking Integration Management Commands
* **sonar-address-groups**: Retrieve a list of address groups
* **sonar-address-objects**: Retrieve address objects
* **sonar-remove-address-batch**: Batch deletion of address objects
* **sonar-response-targets**: Retrieve a list of response targets
* **sonar-response-models**: Retrieve a list of response models
##### Added Detection Rule Management Commands
* **sonar-stream-rules**: Enumerate real-time detection rules
* **sonar-batch-rules**: Enumerate batch detection rules
* **sonar-add-stream-rule-command-batch**: Batch addition of real-time rule commands
* **sonar-update-stream-rule-command-batch**: Batch modification of real-time rule commands
* **sonar-delete-stream-rule-command-batch**: Batch deletion of real-time rule commands
* **sonar-update-batch-rule-query-batch**: Batch modification of batch rule queries
##### Added App Management Commands
* **sonar-apps**: Retrieve a list of apps
Bug Fixes
* Modified to parse logs even when the PRI field is missing.
Added support for Apache Kafka TLS integration
SNIPER ONE v3.3 Support
- Updated parsers for Detect, VipsProtocol, VipsService, and tcpCPSTraffic events
- Added 5 new log schemas for the following events
- Malware Detection
- System Information
- System Status
- System Sub Information
- URL Log
Bug Fixes
- Modified to load dashboard data from all nodes when running in a cluster configuration
- Fixed an issue where the time filter in dashboard filters was not applied
First release
- Support login and query log collectors.
- Support query usage and login dashboards.
Support for Basic Authentication in the Splunk HEC Collector
Snowflake JDBC driver 3.14.4 version
First release