Change log for ENDPOINT_PROTECTOR_DLP
| Date | Changes |
|---|---|
| 2025-09-26 |
- event.idm.read_only_udm.additional.fields: Newly mapped Date/Time(Server), Date/Time(Client), Date/Time(Server UTC), Date/Time(Client UTC) raw log fields to event.idm.read_only_udm.additional.fields UDM field.- event.idm.read_only_udm.principal.port: Newly mapped epp_port raw log field to event.idm.read_only_udm.principal.port UDM field.- event.idm.read_only_udm.observer.hostname: Newly mapped hostname raw log field to event.idm.read_only_udm.observer.hostname UDM field.- Added Grok patterns and json filter in order to parse new format logs. |
| 2025-09-21 |
Enhancement: - Added Grok pattern to support new pattern of logs. - event.idm.read_only_udm.metadata.ingestion_labels: Removed Destination, and Matched Item raw log fields from event.idm.read_only_udm.metadata.ingestion_labels UDM field.- event.idm.read_only_udm.target.application: Newly mapped Destination raw log field with event.idm.read_only_udm.target.application UDM field.- event.idm.read_only_udm.target.file.mime_type: Newly mapped Matched Item raw log field with event.idm.read_only_udm.target.file.mime_type UDM field.- event.idm.read_only_udm.intermediary.ip: Newly mapped intermediary_ip raw log field with event.idm.read_only_udm.intermediary.ip UDM field.- event.idm.read_only_udm.additional.fields: Newly mapped server_date, client_date, server_date_utc, client_date_utc raw log fields with event.idm.read_only_udm.additional.fields UDM field.- event.idm.read_only_udm.principal.process.pid: Newly mapped pid raw log field with event.idm.read_only_udm.principal.process.pid UDM field.- event.idm.read_only_udm.principal.platform_version: Newly mapped OS raw log field with event.idm.read_only_udm.principal.platform_version UDM field.- event.idm.read_only_udm.metadata.event_type: Setting event.idm.read_only_udm.metadata.event_type to SCAN_UNCATEGORIZED if has_principal is true else set to GENERIC_EVENT.
|
| 2023-04-17 | Newly created parser. |