Google SecOps has updated the list of supported default parsers
Share
Services
## Change
Change
Google SecOps has updated the list of supported default parsers. Parsers are updated gradually, so it might take one to four days before you see the changes reflected in your region.
The following supported default parsers have been updated. Each parser is listed by product name and `log_type` value, where applicable. This list includes both released default parsers and pending parser updates.
* 1Password Audit Events (`ONEPASSWORD_AUDIT_EVENTS`)
* AIX system (`AIX_SYSTEM`)
* Apache (`APACHE`)
* Aruba EdgeConnect SD-WAN (`ARUBA_EDGECONNECT_SDWAN`)
* Avaya Aura Experience Portal (`AVAYA_AURA`)
* AWS CloudFront (`AWS_CLOUDFRONT`)
* AWS Cloudtrail (`AWS_CLOUDTRAIL`)
* AWS GuardDuty (`GUARDDUTY`)
* AWS Security Hub (`AWS_SECURITY_HUB`)
* Azure AD (`AZURE_AD`)
* Azure AD Organizational Context (`AZURE_AD_CONTEXT`)
* Azure AD Sign-In (`AZURE_AD_SIGNIN`)
* Azure SQL (`AZURE_SQL`)
* Azure Storage Audit (`AZURE_STORAGE_AUDIT`)
* Barracuda WAF (`BARRACUDA_WAF`)
* Blue Coat Proxy (`BLUECOAT_WEBPROXY`)
* Chrome Management (`CHROME_MANAGEMENT`)
* Cisco ACS (`CISCO_ACS`)
* Cisco ISE (`CISCO_ISE`)
* Cisco Secure Access (`CISCO_SECURE_ACCESS`)
* Cisco Secure Workload (`CISCO_SECURE_WORKLOAD`)
* Cisco Switch (`CISCO_SWITCH`)
* Cisco Umbrella Audit (`CISCO_UMBRELLA_AUDIT`)
* Citrix Netscaler (`CITRIX_NETSCALER`)
* Claroty Xdome (`CLAROTY_XDOME`)
* Claude Compliance Logs (`CLAUDE_COMPLIANCE_LOGS`)
* Cloudflare (`CLOUDFLARE`)
* Cloudflare Warp (`CLOUDFLARE_WARP`)
* Corelight (`CORELIGHT`)
* CrowdStrike Alerts API (`CS_ALERTS`)
* CrowdStrike Falcon (`CS_EDR`)
* CyberArk (`CYBERARK`)
* CyberArk Privileged Access Manager (PAM) (`CYBERARK_PAM`)
* Duo Administrator Logs (`DUO_ADMIN`)
* EfficientIP DDI (`EFFICIENTIP_DDI`)
* Elastic Audit Beats (`ELASTIC_AUDITBEAT`)
* Elastic Windows Event Log Beats (`ELASTIC_WINLOGBEAT`)
* F5 ASM (`F5_ASM`)
* Forcepoint Proxy (`FORCEPOINT_WEBPROXY`)
* FortiGate (`FORTINET_FIREWALL`)
* GitHub (`GITHUB`)
* Google Cloud Asset Inventory (`GCP_CLOUD_ASSET_INVENTORY`)
* Google Cloud Audit (`GCP_CLOUDAUDIT`)
* Google Compute Context (`GCP_COMPUTE_CONTEXT`)
* Google Threat Intelligence IOC (`GTI_IOC`)
* GTB Technologies DLP (`GTB_DLP`)
* HP Aruba (ClearPass) (`CLEARPASS`)
* IBM Websphere Application Server (`IBM_WEBSPHERE_APP_SERVER`)
* IBM z/OS (`IBM_ZOS`)
* Imperva (`IMPERVA_WAF`)
* Imperva CEF (`IMPERVA_CEF`)
* Imperva DRA (`IMPERVA_DRA`)
* Imperva SecureSphere Management (`IMPERVA_SECURESPHERE`)
* Island Browser logs (`ISLAND_BROWSER`)
* Juniper (`JUNIPER_FIREWALL`)
* Juniper Mist (`JUNIPER_MIST`)
* Kubernetes Node (`KUBERNETES_NODE`)
* LastPass Password Management (`LASTPASS`)
* Linux Auditing System (AuditD) (`AUDITD`)
* Microsoft Azure Activity (`AZURE_ACTIVITY`)
* Microsoft Defender for Office 365 (`MICROSOFT_DEFENDER_MAIL`)
* Microsoft IIS (`IIS`)
* Mobileiron (`MOBILEIRON`)
* Mongo Database (`MONGO_DB`)
* MySQL (`MYSQL`)
* Netapp Storagegrid (`NETAPP_STORAGEGRID`)
* Netskope V2 (`NETSKOPE_ALERT_V2`)
* Netskope Web Proxy (`NETSKOPE_WEBPROXY`)
* NGFW Enterprise (`GCP_NGFW_ENTERPRISE`)
* Office 365 (`OFFICE_365`)
* Office 365 Message Trace (`OFFICE_365_MESSAGETRACE`)
* Okta Scaleft (`OKTA_SCALEFT`)
* Oracle (`ORACLE_DB`)
* Oracle Cloud Infrastructure Audit Logs (`OCI_AUDIT`)
* Orca Cloud Security Platform (`ORCA`)
* Proofpoint On Demand (`PROOFPOINT_ON_DEMAND`)
* Radware Web Application Firewall (`RADWARE_FIREWALL`)
* Red Hat Directory Server LDAP (`REDHAT_DIRECTORY_SERVER`)
* Red Hat OpenShift (`REDHAT_OPENSHIFT`)
* Salesforce (`SALESFORCE`)
* Sangfor Next Generation Firewall (`SANGFOR_NGAF`)
* Security Command Center Error (`GCP_SECURITYCENTER_ERROR`)
* Security Command Center Misconfiguration (`GCP_SECURITYCENTER_MISCONFIGURATION`)
* Security Command Center Observation (`GCP_SECURITYCENTER_OBSERVATION`)
* Security Command Center Posture Violation (`GCP_SECURITYCENTER_POSTURE_VIOLATION`)
* Security Command Center Threat (`GCP_SECURITYCENTER_THREAT`)
* Security Command Center Toxic Combination (`GCP_SECURITYCENTER_TOXIC_COMBINATION`)
* Security Command Center Unspecified (`GCP_SECURITYCENTER_UNSPECIFIED`)
* Security Command Center Vulnerability (`GCP_SECURITYCENTER_VULNERABILITY`)
* SentinelOne Singularity Cloud Funnel (`SENTINELONE_CF`)
* ServiceNow Security (`SERVICENOW_SECURITY`)
* Sourcefire (`SOURCEFIRE_IDS`)
* Suricata EVE (`SURICATA_EVE`)
* Symantec Endpoint Protection (`SEP`)
* Sysdig (`SYSDIG`)
* Trend Micro Deep Security (`TRENDMICRO_DEEP_SECURITY`)
* Trend Micro Vision One Observerd Attack Techniques (`TRENDMICRO_VISION_ONE_OBSERVERD_ATTACK_TECHNIQUES`)
* Ubiquiti UniFi Switch (`UBIQUITI_SWITCH`)
* Unix system (`NIX_SYSTEM`)
* Upwind (`UPWIND`)
* VMware ESXi (`VMWARE_ESX`)
* VMWare VSphere (`VMWARE_VSPHERE`)
* Windows DNS (`WINDOWS_DNS`)
* Windows Event (`WINEVTLOG`)
* Wiz.io (`WIZ_IO`)
* Workday User Activity (`WORKDAY_USER_ACTIVITY`)
* Workspace Activities (`WORKSPACE_ACTIVITY`)
* Zscaler (`ZSCALER_WEBPROXY`)
* Zscaler CASB (`ZSCALER_CASB`)
* Zscaler DLP (`ZSCALER_DLP`)
* Zscaler Private Access (`ZSCALER_ZPA`)
The following log types were added without a default parser. Each parser is listed by product name and `log_type` value, where applicable.
* Azure Software Vulnerabilities (`AZURE_SOFTWARE_VULNERABILITIES`)
* Caller Verify (`CALLER_VERIFY`)
* CertSecure Log (`CERTSECURE_LOG`)
* Cisco MultiCloud Defense Firewall (`CISCO_MULTICLOUD_DEFENSE_FIREWALL`)
* Cursor (`CURSOR`)
* Cyfirma (`CYFIRMA_DECYFIR_LOG`)
* Databahn (`DATABAHN`)
* Flare Darkweb Alerts (`FLARE_DARKWEB_ALERTS`)
* Fortinet FortiAppSec Cloud (`FORTINET_FORTIAPPSEC`)
* Hikvision Network Video Recorders (`HIKVISION_NVR`)
* IBM B2B Integrator (`IBM_B2B_INTEGRATOR`)
* IBM InfoSphere Virtual Data Pipeline (`IBM_VDP`)
* Imperva Account TakeOver (`IMPERVA_ATO`)
* Imperva Client Side Protection (`IMPERVA_CSP`)
* Imperva DNS (`IMPERVA_DNS`)
* Imperva Network Security (`IMPERVA_NETWORK_SECURITY`)
* Microsoft Defender XDR (`MICROSOFT_DEFENDER_XDR`)
* Nakivo Backup and Recovery (`NAKIVO_BACKUP`)
* Netcraft Takedown (`NETCRAFT_TAKEDOWN`)
* Next Level Performance Amplify (`NXL_AMPLIFY`)
* Siemens Desigo (`SIEMENS_DESIGO`)
What else is happening at Google Cloud Platform?
Read update
Services
Share
Read update
Services
Share
Read update
Services
Share
New SAP certification for operating system: RHEL 10.0 for SAP
about 2 hours ago
Services
Share
Read update
Services
Share