Google SecOps has updated the list of supported default parsers
Share
Services
## Change
Change
Google SecOps has updated the list of [supported default parsers](https://cloud.google.com/chronicle/docs/ingestion/parser-list/supported-default-parsers). Parsers are updated gradually, so it might take one to four days before you see the changes reflected in your region.
The following supported default parsers have been updated. Each parser is listed by product name and `log_type` value, where applicable. This list includes both released default parsers and pending parser updates.
* AIX system (`AIX_SYSTEM`)
* Amazon API Gateway (`AWS_API_GATEWAY`)
* Apache (`APACHE`)
* Appian Cloud (`APPIAN_CLOUD`)
* Aruba Switch (`ARUBA_SWITCH`)
* Atlassian Bitbucket (`ATLASSIAN_BITBUCKET`)
* Avaya Aura Experience Portal (`AVAYA_AURA`)
* AWS CloudWatch (`AWS_CLOUDWATCH`)
* AWS GuardDuty (`GUARDDUTY`)
* AWS Network Firewall (`AWS_NETWORK_FIREWALL`)
* AWS RDS (`AWS_RDS`)
* AWS Security Hub (`AWS_SECURITY_HUB`)
* AWS VPC Flow (`AWS_VPC_FLOW`)
* AWS VPC Flow (CSV) (`AWS_VPC_FLOW_CSV`)
* AWS WAF (`AWS_WAF`)
* Azure AD (`AZURE_AD`)
* Barracuda WAF (`BARRACUDA_WAF`)
* Blue Coat Proxy (`BLUECOAT_WEBPROXY`)
* Cato Networks (`CATO_NETWORKS`)
* Check Point Harmony (`CHECKPOINT_HARMONY`)
* Chrome Management (`CHROME_MANAGEMENT`)
* CircleCI (`CIRCLECI`)
* Cisco ACS (`CISCO_ACS`)
* Cisco ASA (`CISCO_ASA_FIREWALL`)
* Cisco Email Security (`CISCO_EMAIL_SECURITY`)
* Cisco Firepower NGFW (`CISCO_FIREPOWER_FIREWALL`)
* Cisco IronPort (`CISCO_IRONPORT`)
* Cisco ISE (`CISCO_ISE`)
* Cisco Meraki (`CISCO_MERAKI`)
* Cisco Router (`CISCO_ROUTER`)
* Cisco Secure Access (`CISCO_SECURE_ACCESS`)
* Cisco Switch (`CISCO_SWITCH`)
* Cisco Umbrella Audit (`CISCO_UMBRELLA_AUDIT`)
* Cisco Umbrella Cloud Firewall (`UMBRELLA_FIREWALL`)
* Cisco Umbrella Web Proxy (`UMBRELLA_WEBPROXY`)
* Cisco vManage SD-WAN (`CISCO_SDWAN`)
* Cisco WLC/WCS (`CISCO_WIRELESS`)
* Citrix Netscaler (`CITRIX_NETSCALER`)
* Claroty Xdome (`CLAROTY_XDOME`)
* Cloudflare (`CLOUDFLARE`)
* Corelight (`CORELIGHT`)
* CrowdStrike Alerts API (`CS_ALERTS`)
* CrowdStrike Falcon (`CS_EDR`)
* CyberArk PTA Privileged Threat Analytics (`CYBERARK_PTA`)
* Cynet 360 AutoXDR (`CYNET_360_AUTOXDR`)
* Dell Switch (`DELL_SWITCH`)
* Elastic Windows Event Log Beats (`ELASTIC_WINLOGBEAT`)
* F5 ASM (`F5_ASM`)
* F5 BIGIP LTM (`F5_BIGIP_LTM`)
* FireEye ETP (`FIREEYE_ETP`)
* FireEye NX (`FIREEYE_NX`)
* Forcepoint Proxy (`FORCEPOINT_WEBPROXY`)
* FortiGate (`FORTINET_FIREWALL`)
* FortiMail Email Security (`FORTINET_FORTIMAIL`)
* Fortinet FortiAnalyzer (`FORTINET_FORTIANALYZER`)
* Fortinet Web Application Firewall (`FORTINET_FORTIWEB`)
* GitHub (`GITHUB`)
* Google Cloud Audit (`GCP_CLOUDAUDIT`)
* Google Cloud DNS (`GCP_DNS`)
* HAProxy (`HAPROXY`)
* IBM Tape Storages (`IBM_LTO`)
* Imperva CEF (`IMPERVA_CEF`)
* Imperva SecureSphere Management (`IMPERVA_SECURESPHERE`)
* Infoblox DNS (`INFOBLOX_DNS`)
* Island Browser logs (`ISLAND_BROWSER`)
* JumpCloud Directory Insights (`JUMPCLOUD_DIRECTORY_INSIGHTS`)
* Kemp Load Balancer (`KEMP_LOADBALANCER`)
* Kubernetes Node (`KUBERNETES_NODE`)
* ManageEngine ADAudit Plus (`ADAUDIT_PLUS`)
* Microsoft Defender for Endpoint (`MICROSOFT_DEFENDER_ENDPOINT`)
* Microsoft Defender for Office 365 (`MICROSOFT_DEFENDER_MAIL`)
* Microsoft Graph API Alerts (`MICROSOFT_GRAPH_ALERT`)
* Microsoft IIS (`IIS`)
* Microsoft SQL Server (`MICROSOFT_SQL`)
* MISP Threat Intelligence (`MISP_IOC`)
* NetApp ONTAP (`NETAPP_ONTAP`)
* NetIQ eDirectory (`NETIQ_EDIRECTORY`)
* Netskope V2 (`NETSKOPE_ALERT_V2`)
* Netskope Web Proxy (`NETSKOPE_WEBPROXY`)
* NGINX (`NGINX`)
* Noname API Security (`NONAME_API_SECURITY`)
* Office 365 (`OFFICE_365`)
* Okta (`OKTA`)
* Oracle (`ORACLE_DB`)
* Oracle Cloud Infrastructure VCN Flow Logs (`OCI_FLOW`)
* Oracle NetSuite (`ORACLE_NETSUITE`)
* Palo Alto Networks Firewall (`PAN_FIREWALL`)
* Palo Alto Panorama (`PAN_PANORAMA`)
* Palo Alto Prisma Access (`PAN_CASB`)
* Palo Alto Prisma Cloud Alert payload (`PAN_PRISMA_CA`)
* Ping Identity (`PING`)
* Proofpoint On Demand (`PROOFPOINT_ON_DEMAND`)
* RSA (`RSA_AUTH_MANAGER`)
* Salesforce (`SALESFORCE`)
* Security Command Center Error (`GCP_SECURITYCENTER_ERROR`)
* Security Command Center Misconfiguration (`GCP_SECURITYCENTER_MISCONFIGURATION`)
* Security Command Center Observation (`GCP_SECURITYCENTER_OBSERVATION`)
* Security Command Center Posture Violation (`GCP_SECURITYCENTER_POSTURE_VIOLATION`)
* Security Command Center Threat (`GCP_SECURITYCENTER_THREAT`)
* Security Command Center Toxic Combination (`GCP_SECURITYCENTER_TOXIC_COMBINATION`)
* Security Command Center Unspecified (`GCP_SECURITYCENTER_UNSPECIFIED`)
* Security Command Center Vulnerability (`GCP_SECURITYCENTER_VULNERABILITY`)
* Sendmail (`SENDMAIL`)
* Sentinelone Activity (`SENTINELONE_ACTIVITY`)
* ServiceNow CMDB (`SERVICENOW_CMDB`)
* Sophos Firewall (Next Gen) (`SOPHOS_FIREWALL`)
* Squid Web Proxy (`SQUID_WEBPROXY`)
* Symantec EDR (`SYMANTEC_EDR`)
* Symantec Endpoint Protection (`SEP`)
* Sysdig (`SYSDIG`)
* Thinkst Canary (`THINKST_CANARY`)
* Trellix EDRF Trace Data and Telemetry (`TRELLIX_EDRF`)
* Trend Micro Vision One Detections (`TRENDMICRO_VISION_ONE_DETECTIONS`)
* Trend Micro Vision One Workbench (`TRENDMICRO_VISION_ONE_WORKBENCH`)
* Unix system (`NIX_SYSTEM`)
* Varonis (`VARONIS`)
* Veeam (`VEEAM`)
* VMware vCenter (`VMWARE_VCENTER`)
* VMWare VSphere (`VMWARE_VSPHERE`)
* Windows DNS (`WINDOWS_DNS`)
* Windows Event (`WINEVTLOG`)
* Windows Event (XML) (`WINEVTLOG_XML`)
* Windows Sysmon (`WINDOWS_SYSMON`)
* wiz.io (`WIZ_IO`)
* Workday User Activity (`WORKDAY_USER_ACTIVITY`)
* Zeek JSON (`BRO_JSON`)
* Zscaler (`ZSCALER_WEBPROXY`)
* ZScaler NGFW (`ZSCALER_FIREWALL`)
The following log types were added without a default parser. Each parser is listed by product name and `log_type` value, where applicable.
* Cisco Secure Access Enrollment (`CISCO_SECURE_ACCESS_ENROLLMENT`)
* Cisco Secure Access Network (`CISCO_SECURE_ACCESS_NETWORK`)
* CyberArk Certificate Manager SaaS (`CYBERARK_CERTIFICATE_MANAGER_SAAS`)
* Gemini Enterprise Agent Platform (`GEMINI_ENTERPRISE_AGENT_PLATFORM`)
* Schneider Electric GeoScada OT (`GEOSCADA_OT`)
* Model Context Protocol Dev (`MCPDEV`)
* Model Context Protocol Modify (`MCPMODIFY`)
* Model Context Protocol View (`MCPVIEW`)
* NetApp Ransomware Resilience (`NETAPP_RANSOMWARE_RESILIENCE`)
* Netskope Log Streaming (`NETSKOPE_LOG_STREAMING`)
* Pylon Audit Logs (`PYLON_LOGS`)
* Reco AI CSPM (`RECO_CSPM`)
* Salt Security API Protection Platform (`SALT_SECURITY`)
* SentinelOne Application (`SENTINELONE_APPLICATION`)
* Wiz Vulnerabilities (`WIZ_VULNERABILITIES`)