Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update to duo parsing rule #23199

Merged
merged 13 commits into from
Dec 29, 2022
18 changes: 12 additions & 6 deletions Packs/DuoAdminApi/ParsingRules/DuoParsingRules/DuoParsingRules.xif
Original file line number Diff line number Diff line change
@@ -1,6 +1,12 @@
[INGEST:vendor="duo", product="duo", target_dataset="duo_duo_raw", no_hit=drop]
alter tmp_time_part = to_string(TIMESTAMP),
tmp_mili_part = arraystring(regextract(ISOTIMESTAMP, "\:\d{2}\.(\d{3})"), "")
| alter tmp_con_time = to_integer(concat(tmp_time_part, tmp_mili_part))
| alter _time = to_timestamp(tmp_con_time, "millis")
| fields -tmp_time_part, tmp_mili_part, tmp_con_time;
[INGEST:vendor="duo", product="duo", target_dataset="duo_duo_raw", no_hit=keep]
alter
tmp_time_part = to_string(coalesce(timestamp, TIMESTAMP)),
tmp_mili_part = arraystring(regextract(to_string(coalesce(isotimestamp, ISOTIMESTAMP)), "\:\d{2}\.(\d{3})"), "")
| alter
tmp_con_time = concat(tmp_time_part, tmp_mili_part)
| alter
tmp_num = len(tmp_con_time),
tmp_prepare = to_integer(tmp_con_time)
|alter
_time = if(tmp_num > 10, to_timestamp(tmp_prepare , "millis"), to_timestamp(tmp_prepare , "seconds"))
| fields -tmp_time_part, tmp_mili_part, tmp_con_time, tmp_num, tmp_prepare;
4 changes: 4 additions & 0 deletions Packs/DuoAdminApi/ReleaseNotes/3_1_8.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,4 @@

#### Parsing Rules
##### Duo Parsing Rule
- Fixed an issue with Parsing Rule.
2 changes: 1 addition & 1 deletion Packs/DuoAdminApi/pack_metadata.json
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@
"name": "DUO Admin",
"description": "DUO for admins.\nMust have access to the admin api in order to use this",
"support": "xsoar",
"currentVersion": "3.1.7",
"currentVersion": "3.1.8",
"author": "Cortex XSOAR",
"url": "https://www.paloaltonetworks.com/cortex",
"email": "",
Expand Down