Maintained with ☕️ by
IcePanel logo

Override the default time zone for forwarder logs Google SecOps now lets you override the default time zone for your logs when creating or configuring a forwarder

Share

Services

## Change **Override the default time zone for forwarder logs** Google SecOps now lets you override the default time zone for your logs when creating or configuring a forwarder. To know more, see [Add collector information](https://cloud.google.com/chronicle/docs/install/forwarder-management-configurations#add-collectors). ## Announcement **Improvements to Okta parser and Symantec Endpoint Protection parser** These changes are currently in Preview. The Okta parser and the Symantec Endpoint Protection parser are now more efficient, and have increased log-field coverage and more-accurate log-field mappings. The changes include new UDM fields and changes to field mappings. For relevant details on the Okta parser, see [UDM mapping table](https://cloud.google.com/chronicle/docs/ingestion/default-parsers/okta#udm%5Fmapping%5Ftable) and [UDM mapping delta reference](https://cloud.google.com/chronicle/docs/ingestion/default-parsers/okta#udm%5Fmapping%5Fdelta%5Freference). For relevant details on the Symantec Endpoint Protection parser, see [Collect Symantec Endpoint Protection logs](https://cloud.google.com/chronicle/docs/ingestion/default-parsers/symantec-endpoint-protection#udm%5Fmapping%5Ftable) and [UDM mapping delta reference](https://cloud.google.com/chronicle/docs/ingestion/default-parsers/symantec-endpoint-protection#udm-mapping-delta). We advise you to opt-in and get these new versions. ## Announcement **Removed CBN alerts functionality from all prebuilt parsers** As part of deprecating the Configuration Based Normalization (CBN) alerts functionality, all [prebuilt parsers](https://cloud.google.com/chronicle/docs/event-processing/manage-parser-updates#types%5Fof%5Fparsers) that included the CBN alerts functionality were updated, and the functionality was removed. **Note:** For information about how you can migrate CBN alerts to YARA-L detection alerts, see [Migrate CBN alerts to YARA-L detection rule alerts](https://cloud.google.com/chronicle/docs/detection/migrate-cbn-alerts)