We've reorganized our navigation structure to align directly with your operational workflows. See the Google SecOps release notes for more information.
Stay organized with collections
Save and categorize content based on your preferences.
Change log for BRO_JSON
Date
Changes
2026-03-26
- `target.url`: Updated the logic to check whether the `host` and 'uri` raw log fields have same value, before concatenating them to set the `target.url` UDM field for http log type.
2024-05-01
Updated the deprecated UDM fields.
2024-01-31
Handled the extra spaces in the `regex` condition while setting the log types.
2023-11-29
Aligned 'principal/target.hostname' and 'principal/target.asset.hostname' mapping.
2023-10-04
Added mapping to "network.tls.certificate.md5", "network.tls.certificate.sha1" and "network.tls.certificate.sha256".
2023-06-14
Updated the parser to include "parse_network_http_user_agent" to use "Parsed User Agent" and "User Agent".
2022-09-28
Promoted BRO_JSON parser to default.
For the field mapping differences, see field mapping changes
[[["Easy to understand","easyToUnderstand","thumb-up"],["Solved my problem","solvedMyProblem","thumb-up"],["Other","otherUp","thumb-up"]],[["Hard to understand","hardToUnderstand","thumb-down"],["Incorrect information or sample code","incorrectInformationOrSampleCode","thumb-down"],["Missing the information/samples I need","missingTheInformationSamplesINeed","thumb-down"],["Other","otherDown","thumb-down"]],["Last updated 2026-06-18 UTC."],[],[]]