diff --git a/Packs/BarracudaEmailProtection/ParsingRules/BarracudaEmailProtection/BarracudaEmailProtectionParsingRules/BarracudaEmailProtectionParsingRules.xif b/Packs/BarracudaEmailProtection/ParsingRules/BarracudaEmailProtection/BarracudaEmailProtectionParsingRules/BarracudaEmailProtectionParsingRules.xif index 87ac9742b14f..6368fbc8aa99 100644 --- a/Packs/BarracudaEmailProtection/ParsingRules/BarracudaEmailProtection/BarracudaEmailProtectionParsingRules/BarracudaEmailProtectionParsingRules.xif +++ b/Packs/BarracudaEmailProtection/ParsingRules/BarracudaEmailProtection/BarracudaEmailProtectionParsingRules/BarracudaEmailProtectionParsingRules.xif @@ -1,7 +1,9 @@ [INGEST:vendor = barracuda, product = email_protection, target_dataset = barracuda_email_protection_raw, no_hit = keep] alter - tmp_payload = arrayindex(regextract(_raw_log, "\[\d\]: (\{.*?$)"), 0) | -alter + tmp_payload = arrayindex(regextract(_raw_log, "\[\d\]: (\{.*?$)"), 0) +| alter + tmp_get_timestamp = json_extract_scalar(tmp_payload, "$.timestamp") +| alter // 2020-11-29T19:49:46+0000 - _time = to_timestamp(parse_epoch("%Y-%m-%dT%H:%M:%S%z", json_extract_scalar(tmp_payload, "$.timestamp")) , "SECONDS") | -fields -tmp_payload; + _time = parse_timestamp("%Y-%m-%dT%H:%M:%S%z", tmp_get_timestamp) +| fields -tmp_payload, tmp_get_timestamp; diff --git a/Packs/BarracudaEmailProtection/ReleaseNotes/1_0_1.md b/Packs/BarracudaEmailProtection/ReleaseNotes/1_0_1.md new file mode 100644 index 000000000000..bbc2b5cf60de --- /dev/null +++ b/Packs/BarracudaEmailProtection/ReleaseNotes/1_0_1.md @@ -0,0 +1,6 @@ + +#### Parsing Rules + +##### Barracuda Email Protection Parsing Rule + +- Updated the Parsing Rule logic. diff --git a/Packs/BarracudaEmailProtection/pack_metadata.json b/Packs/BarracudaEmailProtection/pack_metadata.json index 93493a816386..96709575635d 100644 --- a/Packs/BarracudaEmailProtection/pack_metadata.json +++ b/Packs/BarracudaEmailProtection/pack_metadata.json @@ -2,7 +2,7 @@ "name": "Barracuda Email Protection", "description": "Email protection from Barracuda", "support": "xsoar", - "currentVersion": "1.0.0", + "currentVersion": "1.0.1", "author": "Cortex XSOAR", "url": "https://www.paloaltonetworks.com/cortex", "email": "",