Package checkpoint/ngfw Release Notes

Package checkpoint/ngfw Release Notes Version 1.2.0
  • Bumps the minimum LogScale version to 1.142 to support assertions in yaml files.

  • Adds support for JSON format.

  • Fixes an issue where the timestamp wasn't working if it was +2:00.

  • Adds a couple of feidls, for example: host.ip, observer.egress.interface.name, observer.ingress.interface.name, destination.user.name and more.

  • Builds out the event.category and event.type fields.

Package checkpoint/ngfw Release Notes Version 1.1.0
  • Adds more options for Action and Rule Action mappings

  • Adds default category and type as network/info to ensure all events are parsed to CPS standard

Package checkpoint/ngfw Release Notes Version 1.0.0
  • Adds new event.module and Cps.version fields

  • Removes the Product , related.user, related.hash and related.ip fields

  • Sets following tags: Cps.version, Vendor, ecs.version, event.dataset, event.kind, event.module, event.outcome, observer.type