October 2nd, 2026 - Content Release
This content release includes:
- New Check Point Audit support with a parser and log mapper covering administrator activity on Check Point management, including which objects were changed, the operation performed, the administrator, source IP, and session.
- Fixed CrowdStrike Falcon Data Protection detections so severity and normalized severity now populate, including for Informational-level detections.
- Jamf Protect Gatekeeper and threat match execution events are now handled by the Jamf Protect Analytics mapper instead of falling through to a generic mapping, so they normalize with the correct fields.
- Updated how Palo Alto Networks firewall actions map to the
successfield across the traffic and threat custom parser log mappers.
Changes are enumerated below.
Log Mappers
- [New] Check Point Audit
- [Updated] CrowdStrike Falcon - Catch DataProtectionDetectionSummaryEvent
- [Updated] Jamf Protect Analytics - Events
- [Updated] Palo Alto Threat DLP non File - Custom Parser
- [Updated] Palo Alto Threat Data - Custom Parser
- [Updated] Palo Alto Threat File - Custom Parser
- [Updated] Palo Alto Threat Flood - Custom Parser
- [Updated] Palo Alto Threat Packet - Custom Parser
- [Updated] Palo Alto Threat Scan - Custom Parser
- [Updated] Palo Alto Threat Spyware - Custom Parser
- [Updated] Palo Alto Threat URL Filtering - Custom Parser
- [Updated] Palo Alto Threat Virus - Custom Parser
- [Updated] Palo Alto Threat Vulnerability - Custom Parser
- [Updated] Palo Alto Threat Wildfire - Custom Parser
- [Updated] Palo Alto Threat Wildfire Virus - Custom Parser
- [Updated] Palo Alto Traffic - Custom Parser
Parsers
- [New] /Parsers/System/Check Point/Check Point Audit JSON