September 17th, 2026 - Content Release
- This content release includes:
- New Google Cloud Platform Vertex AI support with a parser and log mapper, providing visibility into who is calling Vertex AI APIs, which resources they access, and from where
- New PingOne support with a parser and log mapper covering identity and administrative audit events
- AWS GuardDuty findings delivered through Security Hub are now parsed when wrapped in EventBridge events, and GuardDuty finding types are recognized with either
/or-delimiters, so Tor activity, SSH brute force, reconnaissance, and unauthorized access findings normalize correctly - Expanded Cisco Meraki cloud-to-cloud coverage with parsing for WPA and network events, along with hostname, source MAC address, and source IP mappings for those events
- Fixed Okta user attribution for OAuth token grants from public client applications, so these events are attributed to the person rather than the application client ID
- Additional changes are enumerated below
Log Mappers
- [New] Google Cloud Platform Vertex AI
- [New] PingOne - Audit Event
- [Updated] AWSGuardDuty - Audit Events
- [Updated] AWSGuardDuty - Reconnaissance and malicious activity detection
- [Updated] AWSGuardDuty - Tor Client and Relay
- [Updated] AWSGuardDuty - UnauthorizedAccess_EC2_TorIPCaller
- [Updated] Cisco Meraki Traffic Events
- Added destination hostname (
dstDevice_hostname) mapping
- Added destination hostname (
- [Updated] Cisco Meraki WPA - Custom Parser
- Added alternate source keys so source MAC address (
srcDevice_mac), source IP (srcDevice_ip), and device hostname (device_hostname) populate for cloud-to-cloud collected events
- Added alternate source keys so source MAC address (
- [Updated] UnauthorizedAccess_EC2_SSHBruteForce
Parsers
- [New] /Parsers/System/Google/Google Cloud Platform Vertex AI
- [New] /Parsers/System/PingIdentity/PingOne
- [Updated] /Parsers/System/AWS/AWS Security Hub
- [Updated] /Parsers/System/Cisco/Cisco Meraki C2C
- [Updated] /Parsers/System/Okta/Okta