We've reorganized our documentation navigation structure to align directly with your operational workflows. See the release notes and the walkthrough video for more information.
Stay organized with collections
Save and categorize content based on your preferences.
Change log for ABSOLUTE
Date
Changes
2024-12-03
Enhancement: - Added a KV block to map objectProperties. - Mapped objectProperties to target.resource.attribute.labels.
2023-07-07
Enhancement: - Modified Grok pattern to support new log formats. - Mapped actorType to principal.user.attribute.roles.name. - Mapped actorID to principal.user.product_object_id. - Mapped objectType to principal.resource.resource_type when objectType is Device. - Mapped objectName to principal.hostname. - Mapped objectID to principal.resource.product_object_id. - Mapped dvc_ip to intermediary.ip. - Mapped hostname to intermediary.hostname. - Mapped pid to about.process.pid. - Mapped event_class to metadata.product_event_type. - Mapped device_version to metadata.product_version. - Mapped eventType to metadata.product_event_type. - Mapped verb to security_result.summary.
[[["Easy to understand","easyToUnderstand","thumb-up"],["Solved my problem","solvedMyProblem","thumb-up"],["Other","otherUp","thumb-up"]],[["Hard to understand","hardToUnderstand","thumb-down"],["Incorrect information or sample code","incorrectInformationOrSampleCode","thumb-down"],["Missing the information/samples I need","missingTheInformationSamplesINeed","thumb-down"],["Other","otherDown","thumb-down"]],["Last updated 2026-08-07 UTC."],[],[]]