Change log for CISCO_WIRELESS
| Date | Changes |
|---|---|
| 2026-06-17 |
Enhancement: - Added new grok pattern to parse logs with event_type SEC_LOGIN-5-LOGIN_SUCCESS.- event.idm.read_only_udm.principal.asset.attribute.labels: Newly mapped srcip raw log field with event.idm.read_only_udm.principal.asset.attribute.labels UDM field when srcip is not a valid IP.- event.idm.read_only_udm.principal.port: Newly mapped srcport raw log field with event.idm.read_only_udm.principal.port UDM field.- event.idm.read_only_udm.target.user.userid: Newly mapped target_user raw log field with event.idm.read_only_udm.target.user.userid UDM field.- event.idm.read_only_udm.target.user.last_login_time: Newly mapped last_login_time raw log field with event.idm.read_only_udm.target.user.last_login_time UDM field.
|
| 2026-05-27 |
Enhancement: - Modified event.idm.read_only_udm.metadata.event_type from NETWORK_CONNECTION to STATUS_UPDATE as previously it was wrongly flagged has_target == for event.idm.read_only_udm.target.mac mapping.- event.idm.read_only_udm.security_result.detection_fields: Newly mapped line and taskName raw log field with event.idm.read_only_udm.security_result.detection_fields UDM field.- event.idm.read_only_udm.principal.process.file.full_path: Newly mapped cFile raw log field with event.idm.read_only_udm.principal.process.file.full_path UDM field.- event.idm.read_only_udm.intermediary.ip: Newly mapped wlc_ip raw log field with event.idm.read_only_udm.intermediary.ip UDM field.
|
| 2026-04-20 |
Enhancement: - event.idm.read_only_udm.additional.fields: Newly mapped target_port_1 log field with event.idm.read_only_udm.additional.fields UDM field.- Added new grok pattern to parse new pattern of SYSLOG logs. |
| 2026-04-03 |
Enhancement: - event.idm.read_only_udm.metadata.product_event_type: Newly mapped mnemonic raw log field with event.idm.read_only_udm.metadata.product_event_type UDM field.- event.idm.read_only_udm.target.url: Newly mapped urlHolder raw log field with event.idm.read_only_udm.target.url UDM field.- Added support for new date format for event_ts log field.- Added a grok pattern to parse new format SYSLOG logs. |
| 2026-04-01 |
Enhancement: - Added support for syslog format. - event.idm.read_only_udm.observer.hostname: Newly mapped ap_name raw log field to event.idm.read_only_udm.observer.hostname.- event.idm.read_only_udm.observer.mac: Newly mapped bssid raw log field to event.idm.read_only_udm.observer.mac.- event.idm.read_only_udm.principal.mac: Newly mapped principal_mac_cisco raw log field to event.idm.read_only_udm.principal.mac.- event.idm.read_only_udm.principal.process.file.names: Newly mapped program raw log field to event.idm.read_only_udm.principal.process.file.names.- event.idm.read_only_udm.principal.process.pid: Newly mapped pid raw log field to event.idm.read_only_udm.principal.process.pid.- event.idm.read_only_udm.target.user.product_object_id: Newly mapped uid raw log field to event.idm.read_only_udm.target.user.product_object_id.- event.idm.read_only_udm.principal.user.userid: Newly mapped by_username raw log field to event.idm.read_only_udm.principal.user.userid.- event.idm.read_only_udm.security_result.detection_fields: Newly mapped module_details and reason_1 raw log field to event.idm.read_only_udm.security_result.detection_fields.- event.idm.read_only_udm.security_result.rule_name: Newly mapped module raw log field to event.idm.read_only_udm.security_result.rule_name.- event.idm.read_only_udm.principal.user.attribute.labels: Newly mapped by_uid raw log field to event.idm.read_only_udm.principal.user.attribute.labels.- event.idm.read_only_udm.target.user.userid: Newly mapped username raw log field to event.idm.read_only_udm.target.user.userid.- event.idm.read_only_udm.additional.fields: Newly mapped module_id and facility raw log field to event.idm.read_only_udm.additional.fields.- event.idm.read_only_udm.target.resource.resource_subtype: Newly mapped device_type raw log field to event.idm.read_only_udm.target.resource.resource_subtype.- event.idm.read_only_udm.principal.process.file.full_path: Newly mapped process_name raw log field to event.idm.read_only_udm.principal.process.file.full_path.- event.idm.read_only_udm.principal.resource.product_object_id: Newly mapped chassis_id raw log field to event.idm.read_only_udm.principal.resource.product_object_id.
|
| 2026-01-23 |
Enhancement: - Added support for a new syslog header. - Added support for the event SISF-4-EXCESS_ARP_ACTIVITY and relevant corresponding raw log fields.- For SISF-4-EXCESS_ARP_ACTIVITY events, added a grok pattern to extract obs_host, obs_desc, target_mac, summary, and description from the message. The extracted target_mac is transformed into a standard MAC address format.- event.idm.read_only_udm.security_result.summary: Newly mapped summary raw log field to event.idm.read_only_udm.security_result.summary.- event.idm.read_only_udm.security_result.description: Newly mapped description raw log field to event.idm.read_only_udm.security_result.description.
|
| 2025-12-22 |
Enhancement: - event.idm.read_only_udm.additional.fields: Newly mapped syslog_sequence raw log field with event.idm.read_only_udm.additional.fields UDM field.- event.idm.read_only_udm.principal.hostname: Removed mapping of syslog_sequence from event.idm.read_only_udm.principal.hostname UDM field,as it was not the appropriate UDM for this field.- event.idm.read_only_udm.principal.asset.hostname: Removed mapping of syslog_sequence from event.idm.read_only_udm.principal.asset.hostname UDM field,as it was not the appropriate UDM for this field.- A new grok pattern has been introduced to accommodate an additional log format. |
| 2025-12-05 |
Enhancement: - Handled timestamps with the IST timezone by converting them to a UTC offset - event.idm.read_only_udm.principal.user.userid: Newly mapped userid raw log field with event.idm.read_only_udm.principal.user.userid UDM field.- event.idm.read_only_udm.principal.mac: Newly mapped principal_mac raw log field with event.idm.read_only_udm.principal.mac UDM field.- event.idm.read_only_udm.observer.hostname: Newly mapped obs_host raw log field with event.idm.read_only_udm.observer.hostname UDM field.- event.idm.read_only_udm.observer.labels: Newly mapped obs_desc raw log field with event.idm.read_only_udm.observer.labels UDM field.
|
| 2025-11-27 |
Enhancement: - Added grok patterns to parse new pattern of syslog logs. - event.idm.read_only_udm.additional.fields: Newly mapped syslog_sequence raw log field with event.idm.read_only_udm.additional.fields UDM field.- event.idm.read_only_udm.additional.fields: Newly mapped addr, component_status, ecc, multipleErrorsDetected, rep[0], rep[1], rep[2], suppressed_times, valid, interface raw log fields with event.idm.read_only_udm.additional.fields UDM field.- event.idm.read_only_udm.metadata.product_log_id: Newly mapped event_id raw log field with event.idm.read_only_udm.metadata.product_log_id UDM field.- Added KV filter to parse the kv_data field.
|
| 2025-07-08 |
Enhancement: - Added grok pattern to parse unparsed fields. - Updated event.idm.read_only_udm.metadata.event_type from STATUS_UPDATE to NETWORK_CONNECTION.- Updated event.idm.read_only_udm.metadata.event_type from USER_RESOURCE_ACCESS to STATUS_UPDATE.- Updated the mapping of event.idm.read_only_udm.security_result.detection_fields to utilize a generalized map for fields certificate, expiry_date, interface, auth_failure_reason, failure_reason, ssid, xid, slot, current_version, latest_version.- Removed redundant mapping of event.idm.is_significant, event.idm.is_alert, security_result.category, security_result.action, security_result.summary, event.idm.read_only_udm.network.ip_protocol, event.idm.read_only_udm.metadata.event_type.- Removed redundant mapping of event.idm.read_only_udm.target.mac and used common field target_mac and mapped it to event.idm.read_only_udm.target.mac.- Removed redundant mapping of event.idm.read_only_udm.target.port and used common field target_port and mapped it to event.idm.read_only_udm.target.port.- Removed redundant mapping of event.idm.read_only_udm.target.ip and used common field target_ip and mapped it to event.idm.read_only_udm.target.ip.- Removed redundant mapping of event.idm.read_only_udm.principal.mac and used common field principal_mac and mapped it to event.idm.read_only_udm.principal.mac.- Removed redundant mapping of event.idm.read_only_udm.principal.port and used common field principal_port and mapped it to event.idm.read_only_udm.principal.port.- Removed redundant mapping of event.idm.read_only_udm.principal.ip and used common field principal_ip and mapped it to event.idm.read_only_udm.principal.ip.- Removed redundant mapping of event.idm.read_only_udm.principal.hostname and used common field principal_hostname and mapped it to event.idm.read_only_udm.principal.hostname.- Removed redundant code for field wlc_controller.
|
| 2025-04-15 |
Enhancement: - Added Gsub to replace \\n with on message to parse the logs.- Added GROK patterns to parse new pattern of syslog logs. - event.idm.read_only_udm.principal.hostname,event.idm.read_only_udm.principal.asset.hostname: Newly mapped principal_hostname raw log field with event.idm.read_only_udm.principal.hostname and event.idm.read_only_udm.principal.asset.hostname UDM field.- event.idm.read_only_udm.target.hostname,event.idm.read_only_udm.target.asset.hostname: Removed mapping of wlc_controller from event.idm.read_only_udm.target.hostname and event.idm.read_only_udm.target.asset.hostname UDM field when mnemonicis USER_NAME_CREATED in include file cisco_wireless.include.- event.idm.read_only_udm.principal.hostname,event.idm.read_only_udm.principal.asset.hostname: Mapped wlc_controller raw log field with event.idm.read_only_udm.principal.hostname and event.idm.read_only_udm.principal.asset.hostname UDM field when mnemonic is USER_NAME_CREATED in include file cisco_wireless.include.- Added GROK patterns to parse dropped logs when mnemonic is RADIUS_IN_GLOBAL_LIST in include file cisco_wireless.include.- Added else if conditional check when mnemonic is CLIENT_MOVED_TO_RUN_STATE in include file cisco_wireless.include.- event.idm.read_only_udm.principal.hostname,event.idm.read_only_udm.principal.asset.hostname: Newly mapped principal_hostname raw log field with event.idm.read_only_udm.principal.hostname and event.idm.read_only_udm.principal.asset.hostname UDM field.- event.idm.read_only_udm.principal.ip: Newly mapped src_ip_1 raw log field with event.idm.read_only_udm.principal.ip UDM field when mnemonic is CLIENT_MOVED_TO_RUN_STATE in include file cisco_wireless.include.- event.idm.read_only_udm.principal.ip: Newly mapped src_ip_2 raw log field with event.idm.read_only_udm.principal.ip UDM field when mnemonic is CLIENT_MOVED_TO_RUN_STATE in include file cisco_wireless.include.- Added else if conditional check when mnemonic is AUTHENTICATION_TRAP in include file cisco_wireless.include.- event.idm.read_only_udm.principal.mac: Newly mapped mac1 raw log field with event.idm.read_only_udm.principal.mac UDM field when mnemonic is AUTHENTICATION_TRAP in include file cisco_wireless.include.- event.idm.read_only_udm.principal.mac: Newly mapped mac2 raw log field with event.idm.read_only_udm.principal.mac UDM field when mnemonic is AUTHENTICATION_TRAP in include file cisco_wireless.include.- event.idm.read_only_udm.security_result.detection_fields: Newly mapped slot raw log field with event.idm.read_only_udm.security_result.detection_fields UDM field when mnemonic is AUTHENTICATION_TRAP in include file cisco_wireless.include.- event.idm.read_only_udm.principal.user.userid: Newly mapped username raw log field with event.idm.read_only_udm.principal.user.userid UDM field when mnemonic is AUTHENTICATION_TRAP in include file cisco_wireless.include.- event.idm.read_only_udm.principal.ip,event.idm.read_only_udm.principal.asset.ip: Newly mapped src_ip raw log field with event.idm.read_only_udm.principal.ip and event.idm.read_only_udm.principal.asset.ip UDM field when mnemonic is AUTHENTICATION_TRAP in include file cisco_wireless.include.- event.idm.read_only_udm.security_result.detection_fields: Newly mapped ssid raw log field with event.idm.read_only_udm.security_result.detection_fields UDM field when mnemonic is AUTHENTICATION_TRAP in include file cisco_wireless.include.- event.idm.read_only_udm.principal.hostname,event.idm.read_only_udm.principal.asset.hostname: Newly mapped principal_hostname raw log field with event.idm.read_only_udm.principal.hostname and event.idm.read_only_udm.principal.asset.hostname UDM field when mnemonic is AUTHENTICATION_TRAP in include file cisco_wireless.include.- event.idm.read_only_udm.metadata.event_type: if has_principal_user is true set event.idm.read_only_udm.metadata.event_type to USER_UNCATEGORIZED, else if has_principal is true set it to STATUS_UPDATE otherwise set it to GENERIC_EVENT when mnemonic is AUTHENTICATION_TRAP in include file cisco_wireless.include.- Added on_error when mapping ap_mac to event.idm.read_only_udm.target.mac in include file cisco_wireless.include.
|
| 2024-09-25 |
Enhancement: - Added support for new pattern of syslog logs. |
| 2024-05-28 |
Enhancement - - Mapped MessageSourceAddress to principal.ip and principal.asset.ip.- Mapped SourceModuleName and SourceModuleType to principal.resource.attribute.labels.- Mapped intermediary_hostname to intermediary.hostname.
|
| 2024-03-18 |
Enhancement - - Added new Grok patterns to support new pattern of syslog logs. - Mapped version to metadata.product_version.- Mapped client_host, and hostname to principal.hostname.- Mapped client_ip to principal.ip.- Mapped client_mac to principal.mac.- Mapped ap_ip to target.ip.- Mapped ap_mac to target.mac.- Mapped messageToProcess and description to metadata.description.- Mapped inter_url to intermediary.url.- Mapped inter_ip to intermediary.ip.- Mapped sec_desc to security_result.description.- Mapped latest_version, current_version, certificate, expiry_date, clostest_sensor, ssid, client, xid, failure_reason, auth_failure_reason, and interface to security_result.detection_fields.- Aligned mappings for principal.hostname and principal.asset.hostname.- Aligned mappings for target.hostname and target.asset.hostname.- Aligned mappings for principal.ip and principal.asset.ip.- Aligned mappings for target.ip and target.asset.ip.- Mapped action_data to security_result.acion_details.- Mapped username to principal.user.userid.- Mapped vendor, and RSSI to principal.resource.attribute.labels.- Mapped vendor, security_setting, channel, protocol, and RSSI to target.resource.attribute.labels.
|
| 2024-01-10 |
Enhancement - - Added Grok patterns to parse newly ingested unparsed logs. - Handled logs when the value of mnemonic is not null and the value is SEC_LOGIN-5-LOGIN_SUCCESS and CRL_LDAP_QUERY.- Mapped msg1 to metadata.description.- Mapped messageToProcess to metadata.description.
|
| 2023-02-09 |
Enhancement - - Supported new logs which has field PARSE_ERROR.- Added grok pattern to support new logs. |
| 2022-09-08 |
Fix - - Corrected a typo error: On line 1239 in include file added comment marker # proceeding to the word security.
|
| 2022-08-22 |
Enhancement - Moved customer specific parser changes to default parser - Added grok patterns to parse the drop logs - Removed drop tags to enhance the parser - Changed the field mapping of event.idm.read_only_udm.metadata.event_type from GENERIC_EVENT to STATUS_UNCATEGORIZED and STATUS_UPDATE- Mapped messageToProcess field to event.idm.read_only_udm.metadata.description- Mapped src_ip field to event.idm.read_only_udm.principal.ip- Mapped wlc_controller to event.idm.read_only_udm.principal.hostname- Mapped event.idm.read_only_udm.metadata.event_type to USER_RESOURCE_ACCESS
|