Support VPC Endpoint for AWS cloudwatch metrics, stats query.
First release
- Support dedicated log parser, log schema, logger model, dashboard, and detection rule.
New features
- Added sonar-indicators query command
- Added syslog query command
Improvements
- Support AWS VPC Endpoint
- Support AWS Network Firewall logs
- Support AWS CloudWatch VPC Flow custom log format
- Support AWS STS authentication
- Added log start/end regex option to AWS S3 Daily Directory watcher
- AWS S3 Daily Directory Watcher can now collect logs when some target paths contain OID and some target paths don't contain OID
- Added Date regex option for AWS S3 Daily Directory Watcher
- Support Playbook execution for AWS app commands
Bugfix
- Fixed C-TAS app not being installed in Sentry, leading to being unable to use C-TAS logger model in Sentry
First release
- Support log parser, log scheams, logger model, and dashboards
Changelog
* Improved parser for following log types: 106001, 313001, 106014, 199013~199019
Added log types and detection rules
- Supports audit and item usage log types
- Supports brute-force attack, item destruction, and item mass deletion detection rules
Support create, enable loggers query commands
- sonar-create-loggers
- sonar-enable-loggers
First release
- includes dedicated log parser, logger model, log schemas, and dashboards
First release
- Support dedicated log parser, log schemas, logger model, and dashboards
Bug fix
- Fixed ClassCastException when "Swap addresses" setting is changed and parse command is executed
- Reverted "Swap addresses" option type back to textbox from checkbox
- Fixed action field value being null on 106007 log type
- Fixed parse failure on 302013 log type
### Dashboard Improvements and API Sequential Execution
- Added asset world map widget
- Improved dashboard query performance using behavior profile
- Supported sequential execution option to minimize concurrent call errors in Criminal IP Free Plan
Support dashboard, widget, and dataset clone query commands
- sonar-dashboards
- sonar-widgets
- sonar-datasets
- sonar-clone-dashboards
- sonar-clone-widgets
- sonar-clone-datasets
Added Log Schemas and Dashboards
- 8 new Log Schemas: QueryPie ACL Change (qp-acl-server), QueryPie Activity (qp-activity), QueryPie Admin Role (qp-admin-role), QueryPie Audit Log Export k(qp-audit-log-export), QueryPie Server Access (qp-server-access), QueryPie Server Audit (qp-server-audit), QueryPie Server Session (qp-server-session), QueryPie DML Snapshot (qp-dml-snapshot)
- Updated Log Schemas: QueryPie ACL Change (qp-acl-change), QueryPie Auth (qp-auth), QueryPie DB Access (qp-db-access), QueryPie SQL Audit (qp-sql-audit)
- Dashboards: Added new Dashboards for new Log Schemas.
Improvements
- Added ticket webhook logger.
- Added SAML2 integration
- Added sonar-verify-query command
First release
- Support traceroute query command in linux and windows environment
First release
- Support dedicated log parser, log schema, logger model, and dashboards for BLUEMAX ADS
First release
- Support TND-WSIS dedicated log parser, log schema, logger model, dashboard, and detection rule.
Support for executing app query commands through forwarders.
- Logpresso Sonar 4.0.2502.0 and later is required