Skip to main content

October 2nd, 2026 - Content Release

This content release includes:

  • New Check Point Audit support with a parser and log mapper covering administrator activity on Check Point management, including which objects were changed, the operation performed, the administrator, source IP, and session.
  • Fixed CrowdStrike Falcon Data Protection detections so severity and normalized severity now populate, including for Informational-level detections.
  • Jamf Protect Gatekeeper and threat match execution events are now handled by the Jamf Protect Analytics mapper instead of falling through to a generic mapping, so they normalize with the correct fields.
  • Updated how Palo Alto Networks firewall actions map to the success field across the traffic and threat custom parser log mappers.

Changes are enumerated below.

Log Mappers​

  • [New] Check Point Audit
  • [Updated] CrowdStrike Falcon - Catch DataProtectionDetectionSummaryEvent
  • [Updated] Jamf Protect Analytics - Events
  • [Updated] Palo Alto Threat DLP non File - Custom Parser
  • [Updated] Palo Alto Threat Data - Custom Parser
  • [Updated] Palo Alto Threat File - Custom Parser
  • [Updated] Palo Alto Threat Flood - Custom Parser
  • [Updated] Palo Alto Threat Packet - Custom Parser
  • [Updated] Palo Alto Threat Scan - Custom Parser
  • [Updated] Palo Alto Threat Spyware - Custom Parser
  • [Updated] Palo Alto Threat URL Filtering - Custom Parser
  • [Updated] Palo Alto Threat Virus - Custom Parser
  • [Updated] Palo Alto Threat Vulnerability - Custom Parser
  • [Updated] Palo Alto Threat Wildfire - Custom Parser
  • [Updated] Palo Alto Threat Wildfire Virus - Custom Parser
  • [Updated] Palo Alto Traffic - Custom Parser

Parsers​

  • [New] /Parsers/System/Check Point/Check Point Audit JSON
Status
Legal
Privacy Statement
Terms of Use
CA Privacy Notice

Copyright © 2026 by Sumo Logic, Inc.