Change log for SEP

Date Changes
2026-05-29 Enhancement:
- Added new grok patterns to parse the new format of syslog logs.
- event.idm.read_only_udm.additional.fields: Newly mapped vrCat raw log field with event.idm.read_only_udm.additional.fields UDM field.
- event.idm.read_only_udm.intermediary.hostname: Newly mapped intermediary_host raw log field with event.idm.read_only_udm.intermediary.hostname UDM field.
2026-04-29 Enhancement:
- Added a new grok pattern to parse new format of syslog logs.
- Removed has_target as true when event.idm.read_only_udm.target.asset_id and event.idm.read_only_udm.target.asset.asset_id is not null as these fields don't come under the target machine details criteria.
- Removed has_principal as true when event.idm.read_only_udm.principal.asset_id and event.idm.read_only_udm.principal.asset.asset_id is not null as these fields don't come under the principal machine details criteria.
- event.idm.read_only_udm.additional.fields: Newly mapped COMMAND_ID, ATP_DEVICE_ID, DEVICE_INFO, pattern_idx, vrType, translation, locale raw log fields with event.idm.read_only_udm.additional.fields UDM field.
- event.idm.read_only_udm.metadata.event_timestamp: Newly mapped timestamp raw log field with event.idm.read_only_udm.metadata.event_timestamp UDM field.
- event.idm.read_only_udm.target.group.attribute.labels: Newly mapped group_type raw log field with event.idm.read_only_udm.target.group.attribute.labels UDM field.
- event.idm.read_only_udm.target.group.group_display_name: Newly mapped group_name raw log field with event.idm.read_only_udm.target.group.group_display_name UDM field.
- event.idm.read_only_udm.security_result.detection_fields: Newly mapped deleted, discovered, virusname_idx, stealth, vID, removal, performance, privacy, dependency, detection_type, dynacat, catDes raw log fields with event.idm.read_only_udm.security_result.detection_fields UDM field.
- event.idm.read_only_udm.security_result.threat_name: Newly mapped virusname raw log field with event.idm.read_only_udm.security_result.threat_name UDM field.
- event.idm.read_only_udm.target.port: Newly mapped RemotePort raw log field with event.idm.read_only_udm.target.port UDM field.
2026-02-05 Enhancement:
- Added support to parse security_result.action as BLOCK when security_result_action is TERMINATED.
2025-11-27 Enhancement:
- event.idm.read_only_udm.security_result.about.labels: Removed mapping of custom_politica_infringida raw log field from event.idm.read_only_udm.security_result.about.labels UDM field.
- event.idm.read_only_udm.additional.fields: Newly mapped custom_politica_infringida raw log field with event.idm.read_only_udm.additional.fields UDM field.
- event.idm.read_only_udm.security_result.about.labels: Removed mapping of custom_incidente raw log field from event.idm.read_only_udm.security_result.about.labels UDM field.
- event.idm.read_only_udm.additional.fields: Newly mapped custom_incidente raw log field with event.idm.read_only_udm.additional.fields UDM field.
- event.idm.read_only_udm.security_result.about.labels: Removed mapping of connection.ether_type raw log field from event.idm.read_only_udm.security_result.about.labels UDM field.
- event.idm.read_only_udm.additional.fields: Newly mapped connection.ether_type raw log field with event.idm.read_only_udm.additional.fields UDM field.
- event.idm.read_only_udm.security_result.about.labels: Removed mapping of feature_name raw log field from event.idm.read_only_udm.security_result.about.labels UDM field.
- event.idm.read_only_udm.additional.fields: Newly mapped feature_name raw log field with event.idm.read_only_udm.additional.fields UDM field.
2025-10-29 Enhancement:
- event.idm.read_only_udm.target.hostname and event.idm.read_only_udm.target.asset.hostname: Removed mapping of ServerName from event.idm.read_only_udm.target.hostname and event.idm.read_only_udm.target.asset.hostname UDM field when logType is similar to Virus found inorder to remove duplicate values.
2025-08-21 Enhancement:
- Parser overhaul version to make it more efficient and increase fields coverage. You can see the full list of changes in the parser documentation page https://cloud.google.com/chronicle/docs/ingestion/default-parsers/symantec-endpoint-protection .
2025-08-14 Enhancement:
Added support to parse new format of json logs.
Added Grok pattern to map the fields.
- event.idm.read_only_udm.security_result.detection_fields: Newly mapped facility, cids_signature_id1, cids_signature_subid, url_category, url_risk, intensive_protection_level raw log fields with event.idm.read_only_udm.security_result.detection_fields UDM field.
- event.idm.read_only_udm.principal.ip: Newly mapped local_host_ip raw log field with event.idm.read_only_udm.principal.ip UDM field.
- event.idm.read_only_udm.principal.asset.ip: Newly mapped local_host_ip raw log field with event.idm.read_only_udm.principal.asset.ip UDM field.
- event.idm.read_only_udm.target.hostname: Newly mapped remote_host_name raw log field with event.idm.read_only_udm.target.hostname UDM field.
- event.idm.read_only_udm.target.asset.hostname: Newly mapped remote_host_name raw log field with event.idm.read_only_udm.target.asset.hostname UDM field.
- event.idm.read_only_udm.metadata.description: Newly mapped event_description raw log field with event.idm.read_only_udm.metadata.description UDM field.
- event.idm.read_only_udm.principal.user.userid: Newly mapped user_name raw log field with event.idm.read_only_udm.principal.user.userid UDM field.
- event.idm.read_only_udm.principal.administrative_domain: Newly mapped domain_name raw log field with event.idm.read_only_udm.principal.administrative_domain UDM field.
- event.idm.read_only_udm.principal.location.city: Newly mapped location raw log field with event.idm.read_only_udm.principal.location.city UDM field.
- event.idm.read_only_udm.extensions.vulns.vulnerabilities: Newly mapped vuln raw log field with event.idm.read_only_udm.extensions.vulns.vulnerabilities UDM field.
- event.idm.read_only_udm.principal.hostname: Newly mapped hostname raw log field with event.idm.read_only_udm.principal.hostname UDM field.
- event.idm.read_only_udm.principal.asset.hostname: Newly mapped hostname raw log field with event.idm.read_only_udm.principal.asset.hostname UDM field.
- event.idm.read_only_udm.target.ip: Newly mapped remote_host_ip raw log field with event.idm.read_only_udm.target.ip UDM field.
- event.idm.read_only_udm.target.asset.ip: Newly mapped remote_host_ip raw log field with event.idm.read_only_udm.target.asset.ip UDM field.
- event.idm.read_only_udm.principal.port: Newly mapped local_port raw log field with event.idm.read_only_udm.principal.port UDM field.
- event.idm.read_only_udm.target.port: Newly mapped remote_port raw log field with event.idm.read_only_udm.target.port UDM field.
- event.idm.read_only_udm.additional.fields: Newly mapped occurrences1 raw log field with event.idm.read_only_udm.additional.fields UDM field.
- event.idm.read_only_udm.target.mac: Newly mapped remote_host_mac raw log field with event.idm.read_only_udm.target.mac UDM field.
- event.idm.read_only_udm.target.asset.mac: Newly mapped remote_host_mac raw log field with event.idm.read_only_udm.target.asset.mac UDM field.
- event.idm.read_only_udm.principal.mac: Newly mapped local_host_mac raw log field with event.idm.read_only_udm.principal.mac UDM field.
- event.idm.read_only_udm.principal.asset.mac: Newly mapped local_host_mac raw log field with event.idm.read_only_udm.principal.asset.mac UDM field.
- event.idm.read_only_udm.target.file.sha256: Newly mapped sha256 raw log field with event.idm.read_only_udm.target.file.sha256 UDM field.
- event.idm.read_only_udm.target.process.file.md5: Newly mapped md5 raw log field with event.idm.read_only_udm.target.process.file.md5 UDM field.
- event.idm.read_only_udm.security_result: Newly mapped security_result raw log field with event.idm.read_only_udm.security_result UDM field.
- event.idm.read_only_udm.target.file.full_path: Newly mapped application_path raw log field with event.idm.read_only_udm.target.file.full_path UDM field.
- event.idm.read_only_udm.principal.file.full_path: Newly mapped application_path_2 raw log field with event.idm.read_only_udm.principal.file.full_path UDM field.
- Added a conditional null check for domain_name raw log field in the include file to remove null value for event.idm.read_only_udm.intermediary.administrative_domain UDM field.
- event.idm.read_only_udm.metadata.vendor_name: Newly mapped Symantec with event.idm.read_only_udm.metadata.vendor_name UDM field.
- event.idm.read_only_udm.metadata.product_name: Newly mapped SEP with event.idm.read_only_udm.metadata.product_name UDM field.
2025-03-20 Enhancement:
- If syslogServer is not empty, then mapped syslogServer to intermediary.hostname else mapped computer to intermediary.hostname.
2025-02-26 Enhancement:
- If log_type value is REP, and syslogServer value is not empty, then map syslogServer to intermediary.hostname else map computer to intermediary.hostname.
2025-01-09 Enhancement:
- If Actual action value is Left alone, then changed mapping of security_result.action from BLOCK to UNKNOWN_ACTION.
- Changed mapping of computer from intermediary.hostname to principal.hostname and principal.asset.hostname.
- Changed mapping of syslogServer from principal.hostname to intermediary.hostname.
2024-12-12 Enhancement:
- Added a Grok pattern to parse new format of syslog logs.
- Mapped anvpap-srv1 to intermediary.hostname.
- Mapped SymantecServer to principal.hostname.
- Mapped Remote Host Name to target.hostname.
- Mapped Remote Port to target.port.
- Mapped Remote Host IP to target.ip.
- Mapped Local Port to principal.port.
- Mapped Remote Host MAC to principal.mac.
- Mapped ICMP to network.ip_protocol.
- Mapped Inbound to network.direction.
- Mapped Application to principal.process.file.full_path.
- Mapped Rule to security_result.rule_name.
- Mapped Action to security_result.action.
- Mapped SHA-256 to principal.process.file.sha256.
2024-11-21 Enhancement:
- Added gsub to parse new pattern of logs.
- Added a Grok pattern to event_description to parse the fields.
- Mapped File to principal.process.file.full_path.
- Mapped Size to principal.process.file.size.
2024-11-07 Enhancement:
- Mapped SITE_NAME and SOURCE to additional.fields.
- Mapped SOURCE to security_result.description.
2024-10-25 Enhancement:
- Mapped SCAN_ID, CATEGORY_DESC, CLIENT_TYPE, DETECTION_TYPE, HELP_VIRUS_IDX, HPP_APP_TYPE, IDX, LAST_LOG_SESSION_GUID, SITE_TYPE, UUID, VBIN_ID, and VIRUS_TYPE to additional.fields.
- Mapped USER_DOMAIN_NAME to target.administrative_domain.
- Mapped COMPUTER_DOMAIN_NAME to principal.administrative_domain.
- Mapped IP_ADDR1 to src.ip.
- Mapped SOURCE_COMPUTER_NAME to src.asset.hostname and src.hostname.
- Mapped COMPUTER_NAME to principal.asset.hostname and principal.hostname.
- Mapped OPERATION_SYSTEM to principal.asset.platform_software.platform.
- Mapped SERVICE_PACK to principal.asset.platform_software.platform_version.
- Mapped SOURCE_COMPUTER_IP to principal.ip and principal.asset.ip.
- Mapped ALERT to metadata.product_event_type.
- Mapped USER_NAME to principal.user.userid.
- Mapped BIOS_SERIALNUMBER to principal.asset.hardware.serial_number.
- Mapped ACTUALACTION to security_result.action_details.
- Mapped VIRUSNAME to security_result.threat_name.
- Mapped NOOFVIRUSES to security_result.verdict_info.malicious_count.
- Mapped SOURCE, DESCRIPTION, REQUESTEDACTION to security_result.detection_fields.
- Mapped CLIENT_GROUP to principal.group.group_display_name.
- Mapped downloader to principal.process.file.full_path.
2024-10-24 Enhancement:
- Added support to parse logs with logType as IPS, Network Intrusion Protection System, REP, Memory Exploit Mitigation System, and NTR.
2024-10-08 Enhancement:
- Added support for new format of syslog logs.
2024-09-23 Enhancement:
- Changed mapping of rule_name from principal.resource.name to security_result.rule_name.
- Removed mapping of principal.resource.resource_type as FIREWALL_RULE.
- Changed mapping of security_result.category from ACL_VIOLATION to UNKNOWN_CATEGORY.
2024-09-11 Enhancement:
- Added support for array-type logs.
2024-08-08 - Mapped REQUESTEDACTION to security_result.action_details.
- Mapped SECONDARYACTION, ACTUALACTION, VIRUSNAME, and NOOFVIRUSES to security_result.detection_fields.
- Mapped SOURCE to additional.fields.
- Mapped HPP_APP_HASH to target.file.sha256.
- Mapped HPP_APP_NAME to target.file.names.
- Mapped FILEPATH to target.file.full_path.
- Mapped CLIENT_GROUP to target.user.group_identifiers.
2024-06-07 - Added Support for KV format logs.
2024-05-27 Enhancement:
- Mapped target_file_name from target.file.full_path to target.file.names.
2023-11-28 Bug-Fix:
- When event_time present, mapped the same to datetime.
2023-11-08 Bug-Fix:
- Removed mapping of ServerName to target.asset.hostname and mapped it to intermediary.hostname.
- When Actualaction is Cleaned, then mapped security_result.action to BLOCK and is_significant to false.
- Added Grok pattern to parse the unparsed logs with varying patterns.
- Mapped type, utility-sub-type, lang, service-sandbox-type, mojo-platform-channel-handle, field-trial-handle, disable-features to security_result.detection_fields.
- Mapped target_arguments to read_only_udm.additional.fields.
- Mapped user-data-dir to sec_result.about.file.full_path.
- Mapped security-realm to security_result.summary.
- Mapped startup-url to principal.url.
- Mapped source_ip to target.ip.
- Mapped action_word to security_result.action_details.
2023-10-12 Bug-Fix:
- Added Grok pattern to parse the unparsed logs with varying patterns.
2023-04-21 Bug-Fix:
- Changed intermediate variable names in the include files.
- Mapped security_result.rule_name for File related events.
2023-04-10 Enhancement:
- Handled the dropped logs with the logType File Read, File Write, File Delete, or Registry Write.
- Mapped payload.domain_name to principal.administrative_domain.
- Added null check for payload.device_id and event_description.
2023-01-21 Enhancement:
- Added conditional check for targetComputerName,event_description1.
- Added on_error check for file_full_path,GroupName,ServerName.
- Mapped Applicationtype to principal.resource.attribute.labels.
- Mapped mail to target.user.email_addresses.
- Mapped server_name_1 to principal.hostname.
- For logtype SEC:
- Mapped computer to principal.hostname.
- Mapped syslogServer to intermediary.hostname.
- Mapped event_description to metadata.description.
- Added for loop for the logtype SONAR,CVE,SEC.
2022-11-24 Enhancement:
- Added grok pattern to parse logs containaing SONAR detection now allowed.
2022-11-15 Enhancement:
- Added grok pattern to parse failed logs of type Virus Found and SONAR Scan.
- Added conditional check for Categorytype.
2022-10-25 Enhancement:
- Mapped EventDescription to metadata.description.
- Mapped LocalHostIP,IPAddress,source_ip to principal.ip.
- Mapped LocalHostMAC to principal.mac.
- Mapped computer to principal.hostname
- Mapped guid to principal.asset.asset_id.
- Mapped DeviceID to principal.resource.product_object_id.
- Mapped Filesize to target.file.size.
- Mapped SHA256 to target.file.sha256.
- Mapped User1 to principal.user.userid.
- Mapped file_path to target.file.full_path.
- Mapped GroupName to principal.group.group_display_name.
- Mapped action_word to security_result.action_details.
- Mapped Begin to vulnerabilities.scan_start_time.
- Mapped EndTime to vulnerabilities.scan_end_time.
- Mapped ScanID to principal.process.product_specific_process_id.
- Mapped inter_host to intermediary.hostname.
- Mapped inter_ip to intermediary.ip.
- Mapped ActionType to additional.fields.
- Mapped Rule to security_result.rule_name.
2022-10-10 - Mapped category to security_result.category_details.
- Mapped CIDS Signature ID to target.resource.attribute.labels.
- Mapped CIDS Signature SubID to target.resource.attribute.labels.
- Mapped CIDS Signature string to target.resource.attribute.labels.
- Mapped Intrusion URL to principal.url.
- Mapped User Name to principal.user.userid.
- Mapped Actual action to security_result.action_details.
- Mapped Application hash to target.file.sha256.
- Mapped Application name to target.application.
- Mapped Application type to target.resource.attribute.labels.
- Mapped Certificate issuer to network.tls.server.certificate.issuer.
- Mapped Certificate serial number to network.tls.server.certificate.serial.
- Mapped Certificate signer to network.tls.server.certificate.subject.
- Mapped Certificate thumbprint to network.tls.server.certificate.sha256.
- Mapped Secondary action to target.resource.attribute.labels.
- Mapped First Seen to security_result.detection_fields.
- Mapped Risk Name to security_result.detection_fields.
- Mapped Risk Type to security_result.detection_fields.
- Mapped Permitted application reason to security_result.detection_fields.
- Mapped Company name to target.user.company_name.
- Mapped Computer name to principal.hostname.
- Mapped Server Name to principal.asset.network_domain.
- Mapped Confidence to security_result.description.
- Mapped Detection Type to security_result.summary.
- Mapped Group Name to principal.group.group_display_name.
- Mapped Risk Level to security_result.severity_details.
- Mapped File size (bytes) to target.file.size.
2022-09-21 Enhancement - Migrated custom parsers to default parser.
2022-08-12 Enhancement - Modified grok pattern to parse the logs.
Handled the dropped logs and mapped them to valid event_types.
- Dropped logs had following logType, which are now handled:
REP, SubmissionsMan, SYLINK, IPS, SONAR, SEC, CVE, LiveUpdate Manager; Messages related to definition updates,
Antivirus detection submission.
- New conditions msg1 containing Create Process|GUP|RebootManager|Smc|WSS|Network Intrusion|Mitigation System are handled.
- event_description containing client-server activity logs|Got a valid certificate.|Replication .*from remote site|The database|received the client log successfully.
- Added new code block to handle the logType REP,SONAR,CVE,GUP,Smc,WSS made them parse.
- Changed event type from GENERIC_EVENT to STATUS_UPDATE, USER_UNCATEGORIZED, NETWORK_CONNECTION, STATUS_UNCATEGORIZED wherever possible.
- Mapped eventDescription to metadata.description.
- Mapped hostName to principal.hostname.
- Mapped machineDomainName to principal.administrative_domain.
- Mapped domainName to target.administrative_domain.
- Mapped serverName to intermediary.hostname.
- Mapped userName to principal.user.userid.
- Mapped siteName to read_only_udm.additional.fields.
2022-07-26 for the logs that has messageTmp as Site mapped the following fields:
- Mapped eventDescription to metadata.description.
- Mapped hostName to target.hostname.
- Mapped machineDomainName to target.administrative_domain.
- Mapped domainName to principal.administrative_domain.
- Mapped serverName to principal.hostname.
- Mapped userName to principal.user.userid.
- Mapped siteName to read_only_udm.additional.fields.
2022-05-11 Parsed Event Timestamp log entries with the format yyyy-MM-dd HH:mm:ss.