Package aws/vpcflow Release Notes

Package aws/vpcflow Release Notes Version 1.2.1
  • Updated field mapping to use direct assignment instead of rename function

  • Updated ECS version to 8.17.0

  • Updated parser version to 1.2.1

  • Updated parser to use array:append for array declaration

Package aws/vpcflow Release Notes Version 1.2.0
  • Removes header before parsing in certain cases.

  • Reworks logic to drop events when the only data included is the header.

Package aws/vpcflow Release Notes Version 1.1.0
  • Sets new field cloud.account .

  • Bumps the minimum LogScale version to 1.142 to support assertions in yaml files.

  • Renames the parser to aws-vpcflow .

    ###1.0.0

  • Normalizes data to CrowdStrike Parsing Standard (CPS) schema.

  • Sets following tags: Cps.version , Vendor , ecs.version , event.dataset , event.kind , event.module , event.outcome , observer.type

  • Improves the field extraction.

  • Removes old queries and dashboards from the package. To keep those, stay on the old version of the package.

  • Bumps minimum LogScale version to 1.120 to support AWS S3 ingest feed.