July 14th, 2026 - Content Release
Important Notice
To better represent and improve reliability of third-party security alerts passed through to Sumo Logic Cloud SIEM, we are introducing six new detection rules. These new rules represent new, more granular categories, enabling easier tuning and improved context from the underlying alerts over the existing Normalized Security Signal passthrough rule (MATCH-S00402). Since this is a significant change and custom content such as tuning expressions and custom insights dependent on the existing passthrough rule will need to be migrated, we will be phasing the migration of vendor/product log mappings which contribute records to the passthroughs over the course of July and August.
Target Dates:
-
July 30 — Runtime and Identity sources
- Runtime (MATCH-S01159): Falco, Sysdig Secure, Twistlock (Prisma Cloud Compute), Aqua Security
- Identity (MATCH-S01161): Azure AD Identity Protection, Microsoft ATA, Microsoft Graph Identity API, MCAS/Defender for Cloud Apps, Google Workspace Alert Center, Slack Enterprise, Okta, DocuSign Monitor, Exabeam, Salesforce, Box, CrowdStrike Identity Protection
-
August 13 — Network and Data Protection sources
- Network (MATCH-S01162): Kemp LoadMaster WAF, Palo Alto Firewall, FortiGate, FireEye NX/CMS, Vectra AI, Claroty xDome, Darktrace, AlphaSOC, CrowdStrike FDR, Bitdefender, Trend Micro
- Data Protection (MATCH-S01163): Egnyte DLP, Varonis, Netskope, Akamai CPC, Noname API Security, Check Point Avanan, Proofpoint TRAP, Mimecast, Thinkst Canary, Contrast ADR, Qualys, IBM Guardium, Office 365 DLP, CrowdStrike DataProtection, Fortinet, Google Workspace
-
August 27 — Cloud and Endpoint sources
- Cloud (MATCH-S01160): AWS GuardDuty, AWS Security Hub, Google Cloud SCC, GCP IDS, Orca Security, Wiz, Palo Alto Prisma Cloud, Azure
- Endpoint (MATCH-S01158): CrowdStrike Falcon, SentinelOne, Carbon Black, Cylance, Cisco AMP, Cybereason, Endgame, Jamf Protect, Malwarebytes, McAfee, Palo Alto Cortex XDR, Sophos, Tanium, Trend Micro, Windows Defender, FireEye HX, Azure Defender for Endpoint, Google Workspace, Bitdefender
- This content release includes:
- Six new Normalized Detection rules that provide unified pass-through coverage across security domains — cloud, endpoint, identity, network, runtime, and data protection. These will eventually replace the existing Normalized Security Signal passthrough rule (MATCH-S00402).
- New AWS GuardDuty AttackSequence log mapper to surface multi-stage attack sequence findings
- Updated Palo Alto Threat and Traffic log mappers removing inappropriately normalized Palo Alto specific flag fields
- Updated Office 365 parsing to better extract nested fields and combine separated key-value pairs that represent a single pair.
- Updated Microsoft Teams external and guest access detection rules to reflect updated Office 365 parsing
- Updated Okta MFA mapping to remove incorrect classification of logon for events only representing a portion of the logon process.
- Added alternate value for device_hostname to WatchGuard Fireware mapper
- Changes are enumerated below
Rules
- [New] MATCH-S01158 Normalized Endpoint Detection
- [New] MATCH-S01159 Normalized Runtime Detection
- [New] MATCH-S01160 Normalized Cloud Detection
- [New] MATCH-S01161 Normalized Identity Detection
- [New] MATCH-S01162 Normalized Network Detection
- [New] MATCH-S01163 Normalized Data Protection Detection
- [Updated] MATCH-S00888 Microsoft Teams External Access Enabled
- [Updated] MATCH-S00889 Microsoft Teams Guest Access Enabled
Log Mappers
- [New] AWSGuardDuty - AttackSequence
- [Updated] Okta Authentication - auth_via_mfa
- [Updated] Palo Alto Threat DLP non File - Custom Parser
- [Updated] Palo Alto Threat Data - Custom Parser
- [Updated] Palo Alto Threat File - Custom Parser
- [Updated] Palo Alto Threat Flood - Custom Parser
- [Updated] Palo Alto Threat Packet - Custom Parser
- [Updated] Palo Alto Threat Scan - Custom Parser
- [Updated] Palo Alto Threat Spyware - Custom Parser
- [Updated] Palo Alto Threat URL Filtering - Custom Parser
- [Updated] Palo Alto Threat Virus - Custom Parser
- [Updated] Palo Alto Threat Vulnerability - Custom Parser
- [Updated] Palo Alto Threat Wildfire - Custom Parser
- [Updated] Palo Alto Threat Wildfire Virus - Custom Parser
- [Updated] Palo Alto Traffic - Custom Parser
- [Updated] Watchguard Fireware - Firewall
Parsers
- [Updated] /Parsers/System/Microsoft/Office 365
Schema
- [Updated] threat_ruleType
- endpoint
- runtime
- cloud
- identity
- network
- data_protection