Change log for CYNET_360_AUTOXDR

Date Changes
2026-06-18 - Added a Grok pattern to validate that the src, dst, RequesterIp, and StringIP raw log fields contain valid IP addresses.
- Added timestamp support for the rt raw log field.
- event.idm.read_only_udm.target.hostname, event.idm.read_only_udm.target.asset.hostname: Newly mapped dst raw log field with event.idm.read_only_udm.target.hostname and event.idm.read_only_udm.target.asset.hostname UDM fields when it is not a valid IP address.
- event.idm.read_only_udm.principal.hostname, event.idm.read_only_udm.principal.asset.hostname: Newly mapped src raw log field with event.idm.read_only_udm.principal.hostname and event.idm.read_only_udm.principal.asset.hostname UDM fields when it is not a valid IP address.
- event.idm.read_only_udm.metadata.product_version: Newly mapped cef_device_version raw log field with event.idm.read_only_udm.metadata.product_version UDM field.
- event.idm.read_only_udm.metadata.product_event_type: Newly mapped cef_signature_id raw log field with event.idm.read_only_udm.metadata.product_event_type UDM field.
- event.idm.read_only_udm.security_result.severity_details: Newly mapped cef_severity raw log field with event.idm.read_only_udm.security_result.severity_details UDM field.
- event.idm.read_only_udm.target.url: Newly mapped requestUrl raw log field with event.idm.read_only_udm.target.url UDM field.
- event.idm.read_only_udm.metadata.description: Newly mapped msg raw log field with event.idm.read_only_udm.metadata.description UDM field.
- event.idm.read_only_udm.principal.user.product_object_id: Newly mapped suid raw log field with event.idm.read_only_udm.principal.user.product_object_id UDM field.
- event.idm.read_only_udm.principal.user.email_addresses: Newly mapped suser raw log field with event.idm.read_only_udm.principal.user.email_addresses UDM field.
- event.idm.read_only_udm.additional.fields: Newly mapped dtz, event_time and msg_type raw log fields with event.idm.read_only_udm.additional.fields UDM field.
- event.idm.read_only_udm.security_result.action_details: Newly mapped act raw log field with event.idm.read_only_udm.security_result.action_details UDM field.
- event.idm.read_only_udm.observer.hostname: Newly mapped syslog_host raw log field with event.idm.read_only_udm.observer.hostname UDM field.
- event.idm.read_only_udm.observer.application: Newly mapped syslog_app raw log field with event.idm.read_only_udm.observer.application UDM field.
- event.idm.read_only_udm.observer.process.pid: Newly mapped process_id raw log field with event.idm.read_only_udm.observer.process.pid UDM field.
2025-10-01 - event.idm.read_only_udm.additional.fields: Newly mapped externalId, fname, sev, gpParams, gpprUser, gpSign, hostLS, epsVer, confVer, scanGroupId, sign, pssdeep, pSign, pct, gpssdeep, clientId, etwAlertId, pParams raw log field with event.idm.read_only_udm.additional.fields UDM field.
- event.idm.read_only_udm.security_result.severity: Newly mapped sev raw log field with event.idm.read_only_udm.security_result.severity UDM field.
- event.idm.read_only_udm.security_result.summary: Newly mapped remedStat raw log field with event.idm.read_only_udm.security_result.summary UDM field.
- event.idm.read_only_udm.security_result.action_details: Newly mapped actRem raw log field with event.idm.read_only_udm.security_result.action_details UDM field.
- event.idm.read_only_udm.security_result.category_details: Newly mapped cat raw log field with event.idm.read_only_udm.security_result.category_details UDM field.
- event.idm.read_only_udm.principal.ip: Newly mapped src raw log field with event.idm.read_only_udm.principal.ip UDM field.
- event.idm.read_only_udm.principal.user.userid: Newly mapped prUser raw log field with event.idm.read_only_udm.principal.user.userid UDM field.
- event.idm.read_only_udm.principal.asset.ip: Newly mapped src raw log field with event.idm.read_only_udm.principal.asset.ip UDM field.
- event.idm.read_only_udm.principal.hostname: Newly mapped dhost raw log field with event.idm.read_only_udm.principal.hostname UDM field.
- event.idm.read_only_udm.principal.asset.hostname: Newly mapped dhost raw log field with event.idm.read_only_udm.principal.asset.hostname UDM field.
- event.idm.read_only_udm.principal.platform_version: Newly mapped osVer raw log field with event.idm.read_only_udm.principal.platform_version UDM field.
- event.idm.read_only_udm.principal.file.sha256: Newly mapped pFileHash raw log field with event.idm.read_only_udm.principal.file.sha256 UDM field.
- event.idm.read_only_udm.principal.administrative_domain: Newly mapped pprUser raw log field with event.idm.read_only_udm.principal.administrative_domain UDM field.
- event.idm.read_only_udm.principal.process.file.full_path: Newly mapped ppParams raw log field with event.idm.read_only_udm.principal.process.file.full_path UDM field.
- event.idm.read_only_udm.principal.process.parent_process.file.sha256: Newly mapped gpFileHash raw log field with event.idm.read_only_udm.principal.process.parent_process.file.sha256 UDM field.
- event.idm.read_only_udm.target.ip: Newly mapped dst raw log field with event.idm.read_only_udm.target.ip UDM field.
- event.idm.read_only_udm.target.asset.ip: Newly mapped dst raw log field with event.idm.read_only_udm.target.asset.ip UDM field.
- event.idm.read_only_udm.target.file.full_path: Newly mapped filePath raw log field with event.idm.read_only_udm.target.file.full_path UDM field.
- event.idm.read_only_udm.target.user.userid: Newly mapped duser raw log field with event.idm.read_only_udm.target.user.userid UDM field.
- event.idm.read_only_udm.security_result.summary: Newly mapped cef_header raw log field with event.idm.read_only_udm.security_result.summary UDM field.
- event.idm.read_only_udm.target.administrative_domain: Newly mapped duser raw log field with event.idm.read_only_udm.target.administrative_domain UDM field.
- event.idm.read_only_udm.target.group.group_display_name: Newly mapped scanGroupName raw log field with event.idm.read_only_udm.target.group.group_display_name UDM field.
- event.idm.read_only_udm.metadata.event_timestamp: Newly mapped dtUtc, rt raw log field with event.idm.read_only_udm.metadata.event_timestamp UDM field.
- event.idm.read_only_udm.metadata.collected_timestamp: Newly mapped rtUtc raw log field with event.idm.read_only_udm.metadata.collected_timestamp UDM field.
- event.idm.read_only_udm.metadata.event_type: The condition to set the event type to USER_UNCATEGORIZED was updated to include a check on the has_target_user field.
- Added conditional check for json_failed to parse CEF formatted logs as a fallback.
- Added conditional check for duser to parse domain and user.
- Added conditional check for dtUtc and rt for event timestamp mapping.
- Added conditional check for sev to map severity values.
2024-07-09 - Newly created parser.