Maintained with ☕️ by
IcePanel logo

The following supported default parsers have changed. Each is listed by product name and log_type value, if applicable

Share

Services

## Change The following supported default parsers have changed. Each is listed by product name and `log_type` value, if applicable. * Abnormal Security (`ABNORMAL_SECURITY`) * Akamai DNS (`AKAMAI_DNS`) * Akamai WAF (`AKAMAI_WAF`) * Apigee (`GCP_APIGEE_X`) * Array Networks SSL VPN (`ARRAYNETWORKS_VPN`) * AWS CloudFront (`AWS_CLOUDFRONT`) * AWS Cloudtrail (`AWS_CLOUDTRAIL`) * Azure AD (`AZURE_AD`) * Azure AD Directory Audit (`AZURE_AD_AUDIT`) * Azure AD Sign-In (`AZURE_AD_SIGNIN`) * Barracuda Email (`BARRACUDA_EMAIL`) * Barracuda Firewall (`BARRACUDA_FIREWALL`) * Blue Coat Proxy (`BLUECOAT_WEBPROXY`) * BMC AMI Defender (`BMC_AMI_DEFENDER`) * Carbon Black (`CB_EDR`) * Check Point (`CHECKPOINT_FIREWALL`) * Check Point Sandblast (`CHECKPOINT_EDR`) * Checkpoint Audit (`CHECKPOINT_AUDIT`) * Cisco AMP (`CISCO_AMP`) * Cisco EStreamer (`CISCO_ESTREAMER`) * Cisco FireSIGHT Management Center (`CISCO_FIRESIGHT`) * Cisco ISE (`CISCO_ISE`) * Cisco Router (`CISCO_ROUTER`) * Cisco Switch (`CISCO_SWITCH`) * Cisco Umbrella DNS (`UMBRELLA_DNS`) * Cisco VPN (`CISCO_VPN`) * Cisco WLC/WCS (`CISCO_WIRELESS`) * Citrix Netscaler (`CITRIX_NETSCALER`) * Cloud Audit Logs (`N/A`) * Cloud SQL (`GCP_CLOUDSQL`) * Cloud Storage Context (`N/A`) * Cohesity (`COHESITY`) * CrowdStrike Falcon (`CS_EDR`) * CyberArk Privileged Access Manager (PAM) (`CYBERARK_PAM`) * ESET AV (`ESET_AV`) * F5 ASM (`F5_ASM`) * F5 BIGIP LTM (`F5_BIGIP_LTM`) * F5 VPN (`F5_VPN`) * Forcepoint DLP (`FORCEPOINT_DLP`) * FortiGate (`FORTINET_FIREWALL`) * GMAIL Logs (`GMAIL_LOGS`) * HID DigitalPersona (`HID_DIGITALPERSONA`) * Honeyd (`HONEYD`) * HP Aruba (ClearPass) (`CLEARPASS`) * IBM AS/400 (`IBM_AS400`) * IBM DS8000 Storage (`IBM_DS8000`) * IBM Security Verify (`IBM_SECURITY_VERIFY`) * Infoblox (`INFOBLOX`) * Island Browser logs (`ISLAND_BROWSER`) * JAMF CMDB (`JAMF`) * JumpCloud Directory Insights (`JUMPCLOUD_DIRECTORY_INSIGHTS`) * Juniper Mist (`JUNIPER_MIST`) * Kubernetes Node (`KUBERNETES_NODE`) * Linux Auditing System (AuditD) (`AUDITD`) * ManageEngine ADAudit Plus (`ADAUDIT_PLUS`) * Microsoft AD FS (`ADFS`) * Microsoft Azure Activity (`AZURE_ACTIVITY`) * Microsoft Azure Resource (`AZURE_RESOURCE_LOGS`) * Microsoft CyberX (`CYBERX`) * Microsoft Defender for Endpoint (`MICROSOFT_DEFENDER_ENDPOINT`) * Microsoft Graph Activity Logs (`MICROSOFT_GRAPH_ACTIVITY_LOGS`) * Microsoft Graph API Alerts (`MICROSOFT_GRAPH_ALERT`) * Microsoft SQL Server (`MICROSOFT_SQL`) * Mikrotik Router (`MIKROTIK_ROUTER`) * NetDocuments Solutions (`NETDOCUMENTS`) * Netwrix (`NETWRIX`) * Office 365 (`OFFICE_365`) * Office 365 Message Trace (`OFFICE_365_MESSAGETRACE`) * Okta (`OKTA`) * OneLogin (`ONELOGIN_SSO`) * Opengear Remote Management (`OPENGEAR`) * Palo Alto Networks Firewall (`PAN_FIREWALL`) * pfSense (`PFSENSE`) * PostFix Mail (`POSTFIX_MAIL`) * Proofpoint Sendmail Sentrion (`PROOFPOINT_SENDMAIL_SENTRION`) * Proofpoint Tap Alerts (`PROOFPOINT_MAIL`) * Pulse Secure (`PULSE_SECURE_VPN`) * Qumulo FS (`QUMULO_FS`) * Rapid7 (`RAPID7_NEXPOSE`) * Rapid7 Insight (`RAPID7_INSIGHT`) * Rubrik Polaris (`RUBRIK_POLARIS`) * SailPoint IAM (`SAILPOINT_IAM`) * SAP SuccessFactors (`SAP_SUCCESSFACTORS`) * Semperis DSP (`SEMPERIS_DSP`) * Sentinelone Alerts (`SENTINELONE_ALERT`) * SentinelOne EDR (`SENTINEL_EDR`) * Signal Sciences WAF (`SIGNAL_SCIENCES_WAF`) * Snare System Diagnostic Logs (`SNARE_SOLUTIONS`) * SonicWall (`SONIC_FIREWALL`) * Sophos Central (`SOPHOS_CENTRAL`) * Sophos UTM (`SOPHOS_UTM`) * Spur data feeds (`SPUR_FEEDS`) * Suricata EVE (`SURICATA_EVE`) * Symantec DLP (`SYMANTEC_DLP`) * Symantec Endpoint Protection (`SEP`) * Symantec VIP Authentication Hub (`SYMANTEC_VIP_AUTHHUB`) * Tanium Audit (`TANIUM_AUDIT`) * Thinkst Canary (`THINKST_CANARY`) * Trend Micro Vision One (`TRENDMICRO_VISION_ONE`) * Twingate (`TWINGATE`) * Unix system (`NIX_SYSTEM`) * Vectra Detect (`VECTRA_DETECT`) * Veeam (`VEEAM`) * Verba Recording System (`VERBA_REC`) * VeridiumID by Veridium (`VERIDIUM_ID`) * VMware ESXi (`VMWARE_ESX`) * Windows Defender ATP (`WINDOWS_DEFENDER_ATP`) * Windows DNS (`WINDOWS_DNS`) * Windows Event (`WINEVTLOG`) * Windows Event (XML) (`WINEVTLOG_XML`) * Winscp (`WINSCP`) * WordPress (`WORDPRESS_CMS`) * Workspace Activities (`WORKSPACE_ACTIVITY`) * Zeek TSV (`BRO_TSV`) * Zix Email Encryption (`ZIX_EMAIL_ENCRYPTION`) * Zscaler (`ZSCALER_WEBPROXY`) * ZScaler DNS (`ZSCALER_DNS`) * Zscaler Private Access (`ZSCALER_ZPA`) The following log types, without a default parser, were added. Each is listed by product name and `log_type` value, if applicable. * Akamai Log Delivery Service (`AKAMAI_LDS`) * AudioCodes Voice DNA (`AUDIOCODES`) * Amazon API Gateway (`AWS_API_GATEWAY`) * Axway (`AXWAY`) * Biztalk (`BIZTALK`) * Check Point FDE (`CHECKPOINT_FDE`) * Cimcor | File Integrity Monitoring (`CIMCOR`) * CS Alerts (`CS_ALERTS`) * Custom CSV Log (`CUSTOM_CSV_LOG`) * Cyral (`CYRAL`) * Druva (`DRUVA`) * Entrust DataControl Audit (`ENTR_DATACTRL_AUDIT`) * Ergon Informatik Airlock IAM (`ERGON_INFORMATIK_AIRLOCK_IAM`) * Eset Protect Platform (`ESET_PROTECT_PLATFORM`) * Exim Internet Mailer (`EXIM_INTERNET_MAILER`) * FM Systems Workplace Management (`FM_SYSTEMS`) * GluWare Network Automation (`GLUWARE_NETWORK_AUTOMATION`) * Guidewire Billing Center (`GUIDEWIRE_BILLING_CENTER`) * Guidewire Claim Center (`GUIDEWIRE_CLAIM_CENTER`) * Guidewire Policy Center (`GUIDEWIRE_POLICY_CENTER`) * HAVI Connect (`HAVI_CONNECT`) * IBM OpenPages (`IBM_OPENPAGES`) * Ingrian Networks DataSecure Appliance (`INGRIAN_NETWORKS_DATASECURE_APPLIANCE`) * iSecurity | Security Services and Remediation (`ISECURITY`) * iTop (`ITOP`) * Microsoft Defender for Office 365 (`MICROSOFT_DEFENDER_MAIL`) * Microsoft Graph Risky Users (`MICROSOFT_GRAPH_RISKY_USERS`) * NetApp BlueXP (`NETAPP_BLUEXP`) * Netgate Firewall (`NETGATE_FIREWALL`) * 1KOSMOS | Identity and Authentication (`ONEKOSMOS`) * Palo Alto Global Protect SVC (`PAN_GPSVC`) * Palo Alto SSLVPN Access (`PAN_SSLVPN_ACCESS`) * Palo Alto Telemetry (`PAN_TELEMETRY`) * Proofpoint Endpoint Data Loss Prevention (`PROOFPOINT_ENDPOINT_DLP`) * SAP ERP (`SAP_ERP`) * Ubika WAAP (`UBIKA_WAAP`) * Webroot Endpoint Protection (`WEBROOT`) * Wolters Kluwer Teammate (`WOLTERS_KLUWER_TEAMMATE`) * Xirrus Wireless Controller (`XIRRUS`) For a list of supported log types and details about default parser changes, see [Supported log types and default parsers](https://cloud.google.com/chronicle/docs/ingestion/parser-list/supported-default-parsers).