Change log for LASTPASS
| Date | Changes |
|---|---|
| 2026-05-11 |
Enhancement: - Added a Grok pattern to parse the raw log fields. - event.idm.read_only_udm.principal.ip and event.idm.read_only_udm.principal.asset.ip: Newly mapped lastpass_raw.IP_Address raw log field with event.idm.read_only_udm.principal.ip and event.idm.read_only_udm.principal.asset.ip UDM field.- event.idm.read_only_udm.principal.user.userid: Newly mapped principal.user.userid raw log field with event.idm.read_only_udm.principal.user.userid UDM field.- event.idm.read_only_udm.target.user.userid: Newly mapped lastpass_raw.Username raw log field with event.idm.read_only_udm.target.user.userid UDM field.- event.idm.read_only_udm.target.resource.name: Newly mapped target.resource.name raw log field with event.idm.read_only_udm.target.resource.name UDM field.- event.idm.read_only_udm.metadata.event_timestamp: Newly mapped lastpass_raw.Time raw log field with event.idm.read_only_udm.metadata.event_timestamp UDM field.- event.idm.read_only_udm.metadata.product_event_type: Newly mapped lastpass_raw.Action raw log field with event.idm.read_only_udm.metadata.product_event_type UDM field.- event.idm.read_only_udm.security_result.description: Newly mapped lastpass_raw.Data raw log field with event.idm.read_only_udm.security_result.description UDM field.- event.idm.read_only_udm.additional.fields: Newly mapped additional.fields, metadata.product_event_type raw log fields with event.idm.read_only_udm.additional.fields UDM field.- event.idm.read_only_udm.security_result.detection_fields: Newly mapped security_result.detection_fields raw log field with event.idm.read_only_udm.security_result.detection_fields UDM field.- Updated the naming convention to avoid conflict with raw log fields: - Changed the naming convention from security_result to event_security_result.- Changed the naming convention from additional to event_additional.- Changed the naming convention from target to event_target.- Changed the naming convention from principal to event_principal.- Changed the naming convention from metadata to event_metadata.
|
| 2025-05-29 |
Enhancement: - event.idm.read_only_udm.metadata.event_timestamp: Newly Mapped Datetime raw log field with event.idm.read_only_udm.metadata.event_timestamp UDM Field.- event.idm.read_only_udm.target.user.userid: Newly Mapped UserId raw log field with event.idm.read_only_udm.target.user.userid UDM Field.- event.idm.read_only_udm.target.user.email_addresses: Newly Mapped UserId raw log field with event.idm.read_only_udm.target.user.email_addresses UDM Field.- event.idm.read_only_udm.metadata.product_event_type: Newly Mapped ActionText raw log field with event.idm.read_only_udm.metadata.product_event_type UDM Field.- event.idm.read_only_udm.security_result.description: Newly Mapped Event raw log field with event.idm.read_only_udm.security_result.description UDM Field.- event.idm.read_only_udm.network.session_id: Newly Mapped VID raw log field with event.idm.read_only_udm.network.session_id UDM Field.- event.idm.read_only_udm.principal.ip: Newly Mapped Ip raw log field with event.idm.read_only_udm.principal.ip UDM Field.- event.idm.read_only_udm.principal.asset.ip: Newly Mapped Ip raw log field with event.idm.read_only_udm.principal.asset.ip UDM Field.- event.idm.read_only_udm.additional.fields.key: Newly Mapped EventType raw log field with event.idm.read_only_udm.additional.fields.key UDM Field.
|
| 2024-03-22 | Newly created parser. |