Change log for LOOKOUT_MOBILE_ENDPOINT_SECURITY
| Date | Changes |
|---|---|
| 2026-07-03 |
Enhancement: - event.idm.read_only_udm.principal.user.userid: Newly mapped actor.id raw log field with event.idm.read_only_udm.principal.user.userid UDM field.- event.idm.read_only_udm.security_result.detection_fields: Newly mapped outcome raw log field with event.idm.read_only_udm.security_result.detection_fields UDM field.- event.idm.read_only_udm.metadata.event_type: Updated the value of event.idm.read_only_udm.metadata.event_type to SCAN_UNCATEGORIZED when event_name is THREAT and principal machine data is present.
|
| 2026-03-12 |
Enhancement: - event.idm.read_only_udm.additional.fields: Newly mapped actor.type (key: actor_type), changeType (key: changeType) raw log fields with event.idm.read_only_udm.additional.fields UDM field.- event.idm.read_only_udm.principal.resource.product_object_id: Newly mapped id raw log field with event.idm.read_only_udm.principal.resource.product_object_id UDM field.- event.idm.read_only_udm.target.user.userid: Newly mapped CustomerName raw log field with event.idm.read_only_udm.target.user.userid UDM field.- event.idm.read_only_udm.metadata.event_type: If has_target_user is true, updated the event.idm.read_only_udm.metadata.event_type to USER_UNCATEGORIZED.- Added support for new format of JSON logs, this is allowing the following UDM fields to be mapped correctly: - event.idm.read_only_udm.metadata.event_type- event.idm.read_only_udm.metadata.product_event_type- event.idm.read_only_udm.metadata.log_type- event.idm.read_only_udm.metadata.product_log_id- event.idm.read_only_udm.principal.platform- event.idm.read_only_udm.principal.resource.name- event.idm.read_only_udm.principal.user.userid- event.idm.read_only_udm.metadata.event_timestamp.seconds- event.idm.read_only_udm.principal.application- event.idm.read_only_udm.principal.asset.hardware.manufacturer- event.idm.read_only_udm.principal.asset.hardware.model- event.idm.read_only_udm.principal.file.full_path- event.idm.read_only_udm.principal.platform_version- event.idm.read_only_udm.principal.process.file.full_path- event.idm.read_only_udm.security_result.action_details- event.idm.read_only_udm.security_result.severity
|
| 2024-11-20 |
Enhancement: - Mapped details.type, details.packageSha, details.packageName, details.assessments, details.activationStatus, details.securityStatus, and details.protectionStatus to additional.fields.- Mapped details.applicationName to principal.application.- Mapped details.fileName to principal.process.file.full_path.- Mapped details.path to principal.file.full_path.- Mapped target.manufacturer to principal.asset.hardware.manufacturer.- Mapped target.type to principal.resource.name.
|
| 2024-09-17 |
Enhancement: - Added support for key-value pair log format. |
| 2024-03-07 | Newly created parser. |