Change log for GCP_NGFW_ENTERPRISE

Date Changes
2026-04-28 Enhancement:
- event.idm.read_only_udm.security_result.detection_fields: Newly mapped jsonPayload.interceptVpc.vpc, jsonPayload.interceptVpc.projectId, jsonPayload.threatDetails.repeatCount, jsonPayload.threatDetails.detectionTime raw log fields with event.idm.read_only_udm.security_result.detection_fields UDM field.
- event.idm.read_only_udm.security_result.category_details: Newly mapped jsonPayload.threatDetails.type, jsonPayload.threatDetails.category raw log fields with event.idm.read_only_udm.security_result.category_details UDM field.
- event.idm.read_only_udm.target.application: Newly mapped jsonPayload.threatDetails.application raw log field with event.idm.read_only_udm.target.application UDM field.
- event.idm.read_only_udm.security_result.description: Newly mapped jsonPayload.threatDetails.description raw log field with event.idm.read_only_udm.security_result.description UDM field.
- event.idm.read_only_udm.additional.fields: Newly mapped jsonPayload.threatDetails.cves, jsonPayload.interceptInstance.projectId, jsonPayload.interceptInstance.vm, jsonPayload.securityProfileGroupDetails.organizationId, jsonPayload.@type raw log fields with event.idm.read_only_udm.additional.fields UDM field.
- event.idm.read_only_udm.observer.location.name: Newly mapped resource.labels.location raw log field with event.idm.read_only_udm.observer.location.name UDM field.
- event.idm.read_only_udm.observer.resource.resource_subtype: Newly mapped resource.type raw log field with event.idm.read_only_udm.observer.resource.resource_subtype UDM field.
- event.idm.read_only_udm.observer.resource.name: Newly mapped resource.labels.resource_container raw log field with event.idm.read_only_udm.observer.resource.name UDM field.
- event.idm.read_only_udm.observer.resource.product_object_id: Newly mapped resource.labels.id raw log field with event.idm.read_only_udm.observer.resource.product_object_id UDM field.
- event.idm.read_only_udm.security_result.action: When jsonPayload.action is DROP, set the value of event.idm.read_only_udm.security_result.action to BLOCK.
- Modified the internal variable name from action to action_var for extracting the value mapped to event.idm.read_only_udm.security_result.action.
2024-04-16 Enhancement:
- Changed mapping of alert_severity from jsonPayload.alert_severity to jsonPayload.threatDetails.severity.
- Changed mapping of threat_id from jsonPayload.threat_id to jsonPayload.threatDetails.id.
- Changed mapping of rdspg from jsonPayload.security_profile_group to jsonPayload.securityProfileGroupDetails.securityProfileGroupId.
- Changed mapping of rduri from jsonPayload.uri_or_filename to jsonPayload.threatDetails.uriOrFilename.
- Removed mapping of jsonPayload.rule_details.priority, jsonPayload.rule_details.apply_security_profile_fallback_action, jsonPayload.rule_details.source_range, and jsonPayload.rule_details.target_secure_tag.
2024-03-26 - Newly created parser.