Change log for ONAPSIS

Date Changes
2026-07-07 Enhancement:
- event.idm.read_only_udm.additional.fields: Newly mapped metadata_data.capacity, event_id, incident_detail, appliancesStates, task, related_to.tag.list, related_to.tag.operator, conditions raw log field with event.idm.read_only_udm.additional.fields UDM field.
- event.idm.read_only_udm.target.resource.name: Newly mapped metadata_data.name, data.name raw log field with event.idm.read_only_udm.target.resource.name UDM field.
- event.idm.read_only_udm.target.resource.product_object_id: Newly mapped id raw log field with event.idm.read_only_udm.target.resource.product_object_id UDM field.
- event.idm.read_only_udm.target.resource.attribute.labels: Newly mapped data.vendors, data.fields_to_keep, data.filters.names_regex, data_cadence, enabled raw log field with event.idm.read_only_udm.target.resource.attribute.labels UDM field.
- event.idm.read_only_udm.principal.resource.attribute.labels: Newly mapped leef_version raw log field with event.idm.read_only_udm.principal.resource.attribute.labels UDM field.
- event.idm.read_only_udm.security_result.detection_fields: Newly mapped metadata_data.type raw log field with event.idm.read_only_udm.security_result.detection_fields UDM field.
- event.idm.read_only_udm.security_result.description: Newly mapped metadata_data.description, reason raw log field with event.idm.read_only_udm.security_result.description UDM field.
- event.idm.read_only_udm.security_result.risk_score: Newly mapped anomaly_score raw log field with event.idm.read_only_udm.security_result.risk_score UDM field.
- event.idm.read_only_udm.metadata.event_timestamp: Newly mapped devTime, time raw log field with event.idm.read_only_udm.metadata.event_timestamp UDM field.
- event.idm.read_only_udm.metadata.product_event_type: Newly mapped event_name raw log field with event.idm.read_only_udm.metadata.product_event_type UDM field.
- event.idm.read_only_udm.metadata.product_version: Newly mapped product_version raw log field with event.idm.read_only_udm.metadata.product_version UDM field.
- event.idm.read_only_udm.metadata.description: Newly mapped logline raw log field with event.idm.read_only_udm.metadata.description UDM field.
- event.idm.read_only_udm.metadata.product_log_id: Newly mapped msgid raw log field with event.idm.read_only_udm.metadata.product_log_id UDM field.
- event.idm.read_only_udm.security_result.severity_details: Newly mapped metadata_data.severity raw log field with event.idm.read_only_udm.security_result.severity_details UDM field.
- event.idm.read_only_udm.principal.user.userid: Newly Mapped username raw log field to event.idm.read_only_udm.principal.user.userid UDM field when username consists of numeric values.
- event.idm.read_only_udm.principal.asset.ip: Newly mapped erp_host raw log field with event.idm.read_only_udm.principal.asset.ip UDM field.
2025-11-25 Enhancement:
- Added support for a new log format.
- event.idm.read_only_udm.additional.fields: Newly mapped conditions.condition_id, conditions.eval_value.success, conditions.matched, erp_event_source, erp_time, protocol raw log fields with event.idm.read_only_udm.additional.fields UDM field.
- event.idm.read_only_udm.security_result.confidence_details: Newly mapped confidence raw log field with event.idm.read_only_udm.security_result.confidence_details UDM field.
- event.idm.read_only_udm.security_result.severity_details: Newly mapped severity raw log field with event.idm.read_only_udm.security_result.severity_details UDM field.
- event.idm.read_only_udm.security_result.action: Newly mapped success raw log field with event.idm.read_only_udm.security_result.action UDM field.
- event.idm.read_only_udm.intermediary.ip: Newly mapped inter_ip raw log field with event.idm.read_only_udm.intermediary.ip and event.idm.read_only_udm.intermediary.asset.ip UDM fields.
- event.idm.read_only_udm.metadata.event_type: If event_type is UserLogin and has_target is true, updated to USER_LOGIN.
- The created_at field now supports RFC 3339 and ISO8601 date formats.
- The logic for populating principal.ip, principal.asset.ip, principal.hostname, and principal.asset.hostname has been updated to check if the source fields (host, src, terminal_source) are valid IP addresses.
2023-12-08 - Newly created parser.