Change log for CISCO_ROUTER
| Date | Changes |
|---|---|
| 2026-07-08 |
Enhancement: - Added Grok patterns to parse the raw log fields. - event.idm.read_only_udm.security_result.rule_id: Newly mapped sec_result_rule_id raw log field with event.idm.read_only_udm.security_result.rule_id UDM field.- Added support for the HKT timezone.
|
| 2026-06-08 |
Enhancement: - Replaced hardcoded timezone conversions with an include file timezone.include for dynamic timezone handling.- Modified a grok pattern to parse the raw log fields. - event.idm.read_only_udm.metadata.product_log_id: Newly mapped numeric_intermediary_host raw log field with event.idm.read_only_udm.metadata.product_log_id UDM field.- event.idm.read_only_udm.network.application_protocol: Newly mapped app_protocol raw log field with event.idm.read_only_udm.network.application_protocol UDM field.- event.idm.read_only_udm.principal.ip and event.idm.read_only_udm.principal.asset.ip: Mapped src_ip raw log field with event.idm.read_only_udm.principal.ip and event.idm.read_only_udm.principal.asset.ip UDM fields.- event.idm.read_only_udm.principal.mac: The value from src_msg_mac is now formatted before being mapped to event.idm.read_only_udm.principal.mac.- event.idm.read_only_udm.additional.fields: Newly mapped tty_session field with event.idm.read_only_udm.additional.fields UDM field.
|
| 2026-02-03 |
Enhancement: - Added new grok patterns to support additional log formats. - Added support for the AEDT timezone by mapping it to the +1100 UTC offset. - event.idm.read_only_udm.additional.fields: Newly mapped SN, P and C raw log fields with event.idm.read_only_udm.additional.fields UDM field.- event.idm.read_only_udm.target.ip: Newly mapped target_ip raw log field with event.idm.read_only_udm.target.ip UDM field.- event.idm.read_only_udm.target.asset.ip: Newly mapped target_ip raw log field with event.idm.read_only_udm.target.asset.ip UDM field.- event.idm.read_only_udm.target.port: Newly mapped target_port raw log field with event.idm.read_only_udm.target.port UDM field.- |
| 2026-01-20 |
Enhancement: - Added new grok patterns to support additional log formats. - event.idm.read_only_udm.principal.ip: Newly mapped src_ip raw log field with event.idm.read_only_udm.principal.ip UDM field.- event.idm.read_only_udm.principal.asset.ip: Newly mapped src_ip raw log field with event.idm.read_only_udm.principal.asset.ip UDM field.- event.idm.read_only_udm.target.user.userid: Newly mapped dst_user raw log field with event.idm.read_only_udm.target.user.userid UDM field.- event.idm.read_only_udm.additional: Newly mapped packet_count raw log field with event.idm.read_only_udm.additional UDM field.- event.idm.read_only_udm.security_result.action: Newly mapped status raw log field with event.idm.read_only_udm.security_result.action UDM field.
|
| 2025-11-20 |
Enhancement: - Added support for the IST timezone by mapping it to the +0530 UTC offset. |
| 2025-11-14 |
Enhancement: - event.idm.read_only_udm.target.user.userid: Newly mapped username raw log field to event.idm.read_only_udm.target.user.userid UDM field.- Added grok pattern to parse new format of syslog logs. - Added a grok pattern in order to fetch tar_user from the message_data field.- Set the event_type to USER_LOGIN when the log has login related events.
|
| 2025-10-23 |
Enhancement: - Added support for the event FMANFP-6-IPACCESSLOGP and relevant corresponding raw log fields.- event.idm.read_only_udm.additional.fields: Newly mapped interface and packet_count raw log fields to event.idm.read_only_udm.additional.fields UDM field.- event.idm.read_only_udm.security_result.detection_fields: Newly mapped src_identifier raw log field to event.idm.read_only_udm.security_result.detection_fields UDM field.- event.idm.read_only_udm.target.resource.name: Newly mapped process raw log field to event.idm.read_only_udm.target.resource.name UDM field.- event.idm.read_only_udm.intermediary.application: Newly mapped acl_name raw log field to event.idm.read_only_udm.intermediary.application UDM field.- event.idm.read_only_udm.security_result.action: Newly mapped status raw log field to event.idm.read_only_udm.security_result.action UDM field.- event.idm.read_only_udm.metadata.id: Newly mapped seq_no raw log field to event.idm.read_only_udm.metadata.id UDM field.
|
| 2025-08-25 |
Enhancement: - event.idm.read_only_udm.principal.user.userid: Newly mapped failed_user_id raw log field to event.idm.read_only_udm.principal.user.userid UDM field.- event.idm.read_only_udm.principal.ip: Newly mapped failed_client_ip raw log field to event.idm.read_only_udm.principal.ip UDM field.- event.idm.read_only_udm.principal.asset.ip: Newly mapped failed_client_ip raw log field to event.idm.read_only_udm.principal.asset.ip.- event.idm.read_only_udm.additional.fields: Newly mapped auth_method and service_name raw log field to event.idm.read_only_udm.additional.fields UDM field.- event.idm.read_only_udm.principal.hostname and event.idm.read_only_udm.principal.asset.hostname: Newly mapped intermediary_host raw log field to event.idm.read_only_udm.principal.hostname and event.idm.read_only_udm.principal.asset.hostname when mnemonics is LOGIN_FAILED or AUTHN_FALLBACK.- event.idm.read_only_udm.principal.ip and event.idm.read_only_udm.principal.asset.ip: Mapped inter_hostname raw log field to event.idm.read_only_udm.principal.ip and event.idm.read_only_udm.principal.asset.ip UDM fields when mnemonics is LOGIN_FAILED or AUTHN_FALLBACK.- event.idm.read_only_udm.principal.hostname and event.idm.read_only_udm.principal.asset.hostname: Mapped inter_hostname raw log field to event.idm.read_only_udm.principal.hostname and event.idm.read_only_udm.principal.asset.hostname when mnemonics is LOGIN_FAILED or AUTHN_FALLBACK.
|
| 2025-07-17 |
Enhancement: - Added a grok pattern to parse intermediary.hostname.- Added grok pattern to parse sum_data.- Added gsub to replace \\r with "".
|
| 2025-06-05 |
Enhancement: - Added Grok patterns to parse inter_host,src_ip,src_port,dst_ip,dst_port,user_name_,sc_description and packets. - event.idm.read_only_udm.principal.port : Newly mapped src_port raw log field with event.idm.read_only_udm.principal.port UDM field if message_type is equals to DMI-5-AUTH_PASSED.- event.idm.read_only_udm.principal.ip, event.idm.read_only_udm.principal.asset.ip : Newly mapped src_ip raw log field with event.idm.read_only_udm.principal.ip and event.idm.read_only_udm.principal.asset.ip UDM field if message_type is equals to DMI-5-AUTH_PASSED.- event.idm.read_only_udm.principal.user.userid : Newly mapped user_name_ raw log field with event.idm.read_only_udm.principal.user.userid UDM field if message_type is equals to DMI-5-AUTH_PASSED.- event.idm.read_only_udm.security_result.description : Newly mapped sc_description raw log field with event.idm.read_only_udm.security_result.description UDM field.- event.idm.read_only_udm.network.received_bytes : Newly mapped packets raw log field with event.idm.read_only_udm.network.received_bytes UDM field.
|
| 2025-05-26 |
Enhancement: - Added a Grok pattern to parse intermediary hostname. - event.idm.read_only_udm.target.port : Newly mapped tar_port raw log field with event.idm.read_only_udm.target.port UDM field.- event.idm.read_only_udm.target.ip : Newly mapped tar_ip raw log field with event.idm.read_only_udm.target.ip UDM field.- event.idm.read_only_udm.target.asset.ip : Newly mapped tar_ip raw log field with event.idm.read_only_udm.target.asset.ip UDM field.- event.idm.read_only_udm.network.ip_protocol : Newly mapped proto raw log field with event.idm.read_only_udm.network.ip_protocol UDM field.- event.idm.read_only_udm.principal.port : Newly mapped src_ip_port raw log field with event.idm.read_only_udm.principal.port UDM field.
|
| 2025-04-21 |
Enhancement: - `event.idm.read_only_udm.metadata.event_timestamp : Handled new pattern of timestamps for event.idm.read_only_udm.metadata.event_timestamp UDM field. - event.idm.read_only_udm.principal.ip, event.idm.read_only_udm.principal.asset.ip : Newly mapped src_ip_msg raw log field with event.idm.read_only_udm.principal.ip and event.idm.read_only_udm.principal.asset.ip UDM field.- Newly added multiple grok patterns in order to parse the logs with syslog format. - event.idm.read_only_udm.metadata.event_type: Newly mapped event.idm.read_only_udm.metadata.event_type UDM field as NETWORK_CONNECTION when owner has_principal and has_target are not null.- event.idm.read_only_udm.metadata.event_type: Newly mapped event.idm.read_only_udm.metadata.event_type UDM field as STATUS_UPDATE when owner has_principal is not null.- event.idm.read_only_udm.metadata.event_type: Newly mapped event.idm.read_only_udm.metadata.event_type UDM field as GENERIC_EVENT when has_principal and has_target are null.- event.idm.read_only_udm.principal.ip, event.idm.read_only_udm.principal.asset.ip : Newly mapped src_ip_msg_data raw log field with event.idm.read_only_udm.principal.ip and event.idm.read_only_udm.principal.asset.ip UDM field.
|
| 2025-03-06 |
Enhancement: - Added support for SYSLOG logs. |
| 2025-02-26 |
Enhancement: - Removed intermediary.hostname mapping if the value is numeric.
|
| 2024-12-12 |
Enhancement: - Mapped intermediary_host to intermediary.hostname.
|
| 2024-12-05 |
Enhancement: - Added a Grok pattern to support new pattern of syslog logs. - Mapped srcip to principal.ip.
|
| 2024-10-30 |
Enhancement: - Added support for metadata.event_timestamp in BST timezone.
|
| 2024-10-15 |
Enhancement: - Mapped inter_hostname to intermediary.ip and intermediary_host to intermediary.hostname.
|
| 2024-09-12 |
Enhancement: - Added a Grok pattern to map int_ip to intermediary.hostname.
|
| 2024-06-26 |
Enhancement: - Added a new Grok pattern to parse a new format of SYSLOG logs. |
| 2024-06-09 |
Enhancement: - Mapped hostname from syslog header to intermediary.hostname.
|
| 2024-05-20 |
Enhancement: - Added a new Grok pattern to parse a new format of SYSLOG logs. - Mapped MessageSourceAddress to principal.ip and principal.asset.ip.- Mapped SourceModuleName and SourceModuleType to principal.resource.attribute.labels.
|
| 2023-11-10 |
Enhancement: - Added new Grok patterns to parse failing SYSLOG logs. - Added Unable, exceeded, and No space left on device conditions for AUTH_VIOLATION.
|
| 2023-10-30 |
Enhancement: - Added new Grok patterns to parse failing syslog logs. - Mapped resourcename to principal.resource.name.- Mapped app_protocol to network.application.protocol.- Mapped app to target.application.- Mapped source_port to principal.port.- Mapped source_ip to principal.ip.- Mapped device_ip to target.ip.- Mapped username to target.user.userid.- Mapped intermediary_ip to intermediary.ip.- Mapped mnemonics to metadata.event_type.- Mapped sec_action to security_result.action.- Mapped sec_category security_result.category.- Mapped sec_summary to security_result.summary.- For authentication type logs, set metadata.event_type to USER_LOGIN.
|
| 2023-05-09 |
Enhancement- - Logs with value FMANFP-6-IPACCESSLOGP are parsed as NETWORK_CONNECTION events.
|
| 2022-12-02 |
Enhancement- - Added grok to support unparsed Syslog logs. - If principal.hostname changed event_type mapping from GENERIC_EVENT to STATUS_UPDATE.
|
| 2022-11-10 |
Enhancement- - Added support for SYS-5-CONFIG_I event logs. - Modified grok to support logs having timezone. |
| 2022-10-27 |
Enhancement- Parse following syslog fields of log type IOSXE-6-PLATFORM -Mapped ip to intermediary.ip-Mapped src_ip to principal.ip-Mapped src_port to principal.port-Mapped dst_ip to target.ip-Mapped dst_port to target.port-Mapped protocol to network.ip_protocol-Mapped facility to principal.resource.type-Mapped mnemonics to metadata.product_event_type-Mapped sc_summary to metadata.description-Mapped sr_action to security_result.action-Mapped summary to security_result.summary
|
| 2022-08-23 |
Enhancement- -Corrected mapping of principal and target ip -Mapped target_ip to event.idm.read_only_udm.target.ip-Mapped src_ip to event.idm.read_only_udm.principal.asset.ip
|
| 2022-07-01 |
Enhancement- Fixed an error to parse logs containing product_event_type as SYS-3-LOGGINGHOST_FAIL,SEC_LOGIN-5-LOGIN_SUCCESS,SYS-6-LOGGINGHOST_STARTSTOP,SYS-6-LOGOUT and timestamp is not present. Changed metadata.event_type of SYS-3-LOGGINGHOST_FAIL logs to STATUS_UPDATE from GENERIC_EVENT |