Change log for F5_BIGIP_LTM
| Date | Changes |
|---|---|
| 2026-07-16 |
Enhancement: - Added a Grok pattern to parse the new format of logs. - event.idm.read_only_udm.additional.fields: Newly mapped eventId, facility, priority raw log field with event.idm.read_only_udm.additional.fields UDM field.- event.idm.read_only_udm.metadata.collected_timestamp: Newly mapped event_time_str raw log field with event.idm.read_only_udm.metadata.collected_timestamp UDM field when ts is not null.- event.idm.read_only_udm.metadata.event_timestamp: Newly mapped event_time_str raw log field with event.idm.read_only_udm.metadata.event_timestamp UDM field when ts and event_timestamp is null.- event.idm.read_only_udm.metadata.product_event_type: Newly mapped logtype_tag raw log field with event.idm.read_only_udm.metadata.product_event_type UDM field.
|
| 2026-06-12 |
Enhancement: - Added a Grok pattern to parse the raw log fields. - event.idm.read_only_udm.principal.ip and event.idm.read_only_udm.principal.asset.ip: Newly mapped princ_ip raw log field with event.idm.read_only_udm.principal.ip and event.idm.read_only_udm.principal.asset.ip UDM fields.- event.idm.read_only_udm.security_result.first_discovered_time: Newly mapped time_data raw log field with event.idm.read_only_udm.security_result.first_discovered_time UDM field.- event.idm.read_only_udm.target.application: Newly mapped process raw log field with event.idm.read_only_udm.target.application UDM field.
|
| 2026-04-10 |
Enhancement: - Modified grok pattern to extract syslog_priority from the raw log.- Added a grok pattern on log_message to parse new raw log fields.- event.idm.read_only_udm.security_result.priority_details: Newly mapped syslog_priority raw log field with event.idm.read_only_udm.security_result.priority_details UDM field.- event.idm.read_only_udm.target.process.file.full_path: Newly mapped target_path raw log field with event.idm.read_only_udm.target.process.file.full_path UDM field.- event.idm.read_only_udm.principal.ip and event.idm.read_only_udm.principal.asset.ip: Newly mapped client_ip raw log field with event.idm.read_only_udm.principal.ip and event.idm.read_only_udm.principal.asset.ip UDM fields.- event.idm.read_only_udm.principal.port: Newly mapped client_port raw log field with event.idm.read_only_udm.principal.port UDM field.- event.idm.read_only_udm.network.http.response_code: Newly mapped response_code raw log field with event.idm.read_only_udm.network.http.response_code UDM field.- event.idm.read_only_udm.intermediary.ip and event.idm.read_only_udm.intermediary.asset.ip: Newly mapped backend_ip raw log field with event.idm.read_only_udm.intermediary.ip and event.idm.read_only_udm.intermediary.asset.ip UDM fields.- event.idm.read_only_udm.intermediary.port: Newly mapped backend_port raw log field with event.idm.read_only_udm.intermediary.port UDM field.- event.idm.read_only_udm.additional.fields: Newly mapped ssl_data raw log field with event.idm.read_only_udm.additional.fields UDM field.
|
| 2026-04-02 |
Enhancement: - event.idm.read_only_udm.metadata.event_timestamp: Newly mapped event_timestamp raw log field with event.idm.read_only_udm.metadata.event_timestamp UDM field.- event.idm.read_only_udm.intermediary.hostname and event.idm.read_only_udm.intermediary.asset.hostname: Newly mapped hostname raw log field with event.idm.read_only_udm.intermediary.hostname and event.idm.read_only_udm.intermediary.asset.hostname UDM fields.
|
| 2026-02-09 |
Enhancement: - event.idm.read_only_udm.principal.port: Newly mapped client_port raw log field(s) with event.idm.read_only_udm.principal.port UDM field.- event.idm.read_only_udm.target.port: Newly mapped server_port raw log field(s) with event.idm.read_only_udm.target.port UDM field.
|
| 2026-01-23 |
Enhancement: - Added a Key-Value (KV) filter to parse fields from the raw message. - event.idm.read_only_udm.target.ip: Newly mapped server_ip raw log field to event.idm.read_only_udm.target.ip UDM field. - event.idm.read_only_udm.target.asset.ip: Newly mapped server_ip raw log field to event.idm.read_only_udm.target.asset.ip UDM field. - event.idm.read_only_udm.additional.fields: Newly mapped http_uri raw log field to event.idm.read_only_udm.additional.fields UDM field. - event.idm.read_only_udm.security_result.detection_fields: Newly mapped event_source raw log field to event.idm.read_only_udm.security_result.detection_fields UDM field. - event.idm.read_only_udm.target.resource.name: Newly mapped virtual_name raw log field to event.idm.read_only_udm.target.resource.name UDM field. - event.idm.read_only_udm.metadata.event_timestamp: Newly mapped ts raw log field to event.idm.read_only_udm.metadata.event_timestamp UDM field. - Modified grok pattern to better extract the dvc field. - Reorganized the mapping logic for the and http_host raw log fields. |
| 2025-12-03 |
Enhancement: - Added a Grok pattern to provide support for new pattern of logs. - event.idm.read_only_udm.additional.fields: Mapped ssh_server_version,ssh_client_version raw log field with event.idm.read_only_udm.additional.fields UDM field.- event.idm.read_only_udm.principal.port: Mapped prin_port raw log field with event.idm.read_only_udm.principal.port UDM field.- event.idm.read_only_udm.target.application: Mapped process raw log field with event.idm.read_only_udm.target.application UDM field.- event.idm.read_only_udm.metadata.product_log_id: Mapped eventId raw log field with event.idm.read_only_udm.metadata.product_log_id UDM field.
|
| 2025-07-16 |
Enhancement: - Added a Grok pattern to parse principal , intermediary and target ips and ports. - event.idm.read_only_udm.metadata.product_log_id: Newly Mapped eventId raw log field with event.idm.read_only_udm.metadata.product_log_id UDM field.- event.idm.read_only_udm.principal.ip: Newly Mapped p_ip raw log field with event.idm.read_only_udm.principal.ip UDM field.- event.idm.read_only_udm.principal.asset.ip: Newly Mapped p_ip raw log field with event.idm.read_only_udm.principal.asset.ip UDM field.- event.idm.read_only_udm.principal.port: Newly Mapped p_port raw log field with event.idm.read_only_udm.principal.port UDM field.- event.idm.read_only_udm.intermediary.ip: Newly Mapped i_ip raw log field with event.idm.read_only_udm.intermediary.ip UDM field.- event.idm.read_only_udm.intermediary.asset.ip: Newly Mapped i_ip raw log field with event.idm.read_only_udm.intermediary.asset.ip UDM field.- event.idm.read_only_udm.intermediary.port: Newly Mapped i_port raw log field with event.idm.read_only_udm.intermediary.port UDM field.- event.idm.read_only_udm.target.ip: Newly Mapped t_ip raw log field with event.idm.read_only_udm.target.ip UDM field.- event.idm.read_only_udm.target.asset.ip: Newly Mapped t_ip raw log field with event.idm.read_only_udm.target.asset.ip UDM field.- event.idm.read_only_udm.target.port: Newly Mapped t_port raw log field with event.idm.read_only_udm.target.port UDM field.
|
| 2025-05-13 |
Enhancement: - Added a Grok pattern to parse the unparsed logs. - event.idm.read_only_udm.principal.ip: Mapped src_ip raw log field with event.idm.read_only_udm.principal.ip UDM field.- event.idm.read_only_udm.principal.asset.ip: Mapped src_ip raw log field with event.idm.read_only_udm.principal.asset.ip UDM field.- event.idm.read_only_udm.metadata.description: Mapped desc raw log field with event.idm.read_only_udm.metadata.description UDM field.- event.idm.read_only_udm.principal.ip: Mapped client_ip raw log field with event.idm.read_only_udm.principal.ip UDM field.- event.idm.read_only_udm.principal.asset.ip: Mapped client_ip raw log field with event.idm.read_only_udm.principal.asset.ip UDM field.- event.idm.read_only_udm.network.tls.version Mapped tls_version raw log field with event.idm.read_only_udm.network.tls.version UDM field.- event.idm.read_only_udm.network.tls.cipher: Mapped cipher raw log field with event.idm.read_only_udm.network.tls.cipher` UDM field.- event.idm.read_only_udm.target.url: Mapped request_path raw log field with event.idm.read_only_udm.target.url UDM field.- event.idm.read_only_udm.target.user.userid: Mapped user raw log field with event.idm.read_only_udm.target.user.userid UDM field.- event.idm.read_only_udm.target.process.pid: Mapped pid raw log field with event.idm.read_only_udm.target.process.pid UDM field.- event.idm.read_only_udm.target.process.command_line: Mapped cmd_data raw log field with event.idm.read_only_udm.target.process.command_line UDM field.- event.idm.read_only_udm.security_result.detection_fields: Mapped module raw log field with event.idm.read_only_udm.security_result.detection_fields UDM field.
|
| 2024-12-17 |
Enhancement: - Mapped header.X-HackerOne to principal.user.userid.
|
| 2024-12-12 |
Enhancement: - Mapped dvc to intermediary.hostname.
|
| 2024-12-05 |
Enhancement: - Mapped host to principal.ip and principal.asset.ip
|
| 2024-10-24 |
Enhancement: - Removed the mapping from principal.
|
| 2024-10-09 |
Enhancement: - Added support to parse unparsed logs. - Mapped src_ip and src_port from reason to principal.ip and principal.port.
|
| 2024-09-15 |
Enhancement: - Added Grok patterns to parse unparsed logs. |
| 2024-07-02 |
Enhancement: - Added a new Grok pattern to parse the logs containing CN.- Mapped bank, service, operation, and information to principal.resource.attribute.labels.- Mapped src_ip to principal.ip and principal.asset.ip.
|
| 2024-05-06 |
Enhancement: - Added support to handle a new format of KV logs. - Mapped tlsproto to network.tls.version_protocol.- Mapped method_req to network.http.method.- Mapped path to target.url.- Mapped url to principal.url.- Mapped client_ip to principal.ip and principal.asset.ip.- Mapped device to principal.hostname and principal.asset.hostname.- Mapped host to target.hostname and target.asset.hostname.- Mapped vip to target.ip and target.asset.ip.- Mapped client_port to principal.port.- Mapped snat_ip to principal.nat_ip.- Mapped snat_port to principal.nat_port.- Mapped vs_name, path, query, node, pool_member, vs, device, blade, client, and snat to about.resource.attribute.labels.
|
| 2024-03-23 |
Enhancement: - Added gsub to remove unwanted characters to parse the logs. - Mapped support_id, query_string, and request_status to additional.fields.- Mapped uri to target.url.
|
| 2024-03-11 |
Enhancement: - Added a Grok pattern to parse the unparsed logs. |
| 2024-02-23 |
Enhancement - Added a kv block to retrieve key-value format data.- Added support for CSV format logs. - Added a new Grok pattern to extract key-value fields. - Mapped dest_ip to target_ip.- Mapped dest_port to targetPort- Mapped src_port to principalPort- Mapped dest_port to targetPort- Mapped ip_client and manage_ip_addr to principal.ip and principal.asset.ip- Mapped target_ip and Virtual_IP to target.ip and target.asset.ip"- Mapped severity to security_result.severity- Mapped session_id to network.session_id- Mapped network to network.http.method- Mapped violations, policy_name and req_status to security_result.detection_fields..- Mapped protocol to network.application_protocol- Mapped staged_threat_campaign_names,staged_sig_ids,threat_campaign_names,staged_sig_names,captcha_result,sig_set_names,staged_sig_set_names, sig_ids, sig_names,resp_code and false_positive to additional.fields.
|
| 2024-01-24 |
Bug-fix - Changed mapping of uri_pathuri_query and header.Referer.- Changed mapping of uri_pathuri_query to target.url from network.http.referral_url.- Changed mapping of header.Referer to network.http.referral_url from security_result.about.resource.attribute.labels.
|
| 2024-01-09 |
Enhancement: - Mapped principalIp to principal.ip and principal.asset.ip.
|
| 2023-12-14 |
Enhancement - Added support for JSON format logs. |
| 2023-08-28 |
Enhancement - Added a kv block to retrieve key-value format data.- Mapped process to target.application.- Mapped Country to principal.location.country_or_region.- Mapped State to principal.location.state.- Mapped Client_IP to principal.ip.- Mapped Virtual_IP to target.ip.- Mapped Session_ID to network.session_id.- Mapped errdefs_msgno, partition_name, Listener, Access_Profile to additional.fields.
|
| 2023-07-18 |
- Parsed logs where process is apmd and loglevel is notice.
|
| 2023-05-18 |
Enhancement - Added new Grok patterns to parse the logs containing tmm.- Parsed the logs containing anacron, run-parts and syslog-ng.
|
| 2023-05-09 |
Bug-fix - The hostname which is being mapped to intermediary.hostname mapped to principal.hostname for Syslogs. |
| 2023-03-14 |
Enhancement - Mapped intermediary.hostname for event_type USER_LOGIN and NETWORK_CONNECTION.- The logs which are parsing as GENERIC_EVENT if principal.user.userid present then mapped to USER_UNCATEGORIZED.- The logs which are parsing as GENERIC_EVENT if principal.ip present then mapped to STATUS_UPDATE.
|
| 2023-02-23 |
Enhancement - Updated Grok pattern for the process types httpd and tmm.
|
| 2023-02-06 |
Enhancement - Updated grok pattern for the process type tmm.- Removed target.hostname redundant code and made as generic/global.- changed mapping of target.hostname to intermediary.hostname.
|
| 2023-02-02 |
Enhancement - Updated grok pattern for the process type tmm.- Changed mapping of target.hostname to intermediary.hostname.- Modified metadata.event_type from GENERIC_EVENT when principal.ip is present to STATUS_UPDATE.
|
| 2022-06-21 |
Bug-fix - updated grok pattern for the process type tmm
|
| 2022-05-02 |
Bug-fix - Removed duplicate mappings for event.idm.read_only_udm.security_result.- Parsed the logs failing during Validation API testing. |