Change log for THREATX_WAF
| Date | Changes |
|---|---|
| 2025-01-28 |
- Mapped dst_domain to target.hostname and target.assest.hostname.- Defined version, severity, and priority fields in statedata.- Mapped rule.id, rule.description, rule.classification, rule.state, rule.contrib_score, rule.beta, and rule.blocking to security_result.detection_fields.- Mapped action, tenant_name, random_id, cookie, js_fingerprint, content_type, postblock_event, ssl, content_length, count, upstream_response_time, upstream_response_time, and response_length to additional.fields.- Mapped risk to security_result.risk_score.- Mapped rule.description to metadata.description.- Added a new Grok pattern to map msg1 to principal.url.- Mapped username to target.hostname and target.assest.hostname.- Mapped old_value and new_value to additional.fields.
|
| 2024-10-14 | Newly created parser. |