Change log for BLUECAT_DDI

Date Changes
2026-08-12 - Added new grok patterns to support new pattern of SYSLOG logs.
- event.idm.read_only_udm.principal.hostname and event.idm.read_only_udm.principal.asset.hostname: Newly mapped dhcp_server log field with event.idm.read_only_udm.principal.hostname and event.idm.read_only_udm.principal.asset.hostname UDM fields.
- event.idm.read_only_udm.target.hostname and event.idm.read_only_udm.target.asset.hostname: Newly mapped target_host raw log field with event.idm.read_only_udm.target.hostname and event.idm.read_only_udm.target.asset.hostname UDM fields.
- event.idm.read_only_udm.metadata.event_type: When log contains principal and target machine details set event.idm.read_only_udm.metadata.event_type to NETWORK_CONNECTION and when only principal machine data is present set event.idm.read_only_udm.metadata.event_type to STATUS_UPDATE.
- event.idm.read_only_udm.principal.process.pid: Newly mapped principal_pid raw log field with event.idm.read_only_udm.principal.process.pid UDM field.
- event.idm.read_only_udm.additional.fields: Newly mapped pool_id raw log field to event.idm.read_only_udm.additional.fields UDM field.
2022-11-08 - Added grok for newly ingested logs for log_type - agetty, syslog-ng, systemd.
- Added grok pattern for log_type - named, systemd, CRON, agetty, syslog-ng and it's respective mappings for the fields in the log_type mentioned above.
2022-09-01 - Modified event_type from GENERIC_EVENT to USER_UNCATEGORIZED to reduce generic percentage.
2022-08-16 - Added udm mapping
metadata.vendor_name to Bluecat Networks
metadata.product_name to Bluecat DDI
2022-05-05 - Added checks for query_type field.