Package cloudflare/zerotrust Release Notes

Package cloudflare/zerotrust Release Notes Version 1.5.0
  • Enhanced bulk log processing with improved batched event handling

  • Added SHA256 hash generation for batched events to track event relationships

  • Improved JSON parsing structure for better event separation

  • Updated parser version to 2.4.0

Package cloudflare/zerotrust Release Notes Version 1.4.0
  • Added severity mapping based on risk score

  • Added event.kind = alert for zone-scoped-http-requests when severity is present

  • Added event.action mapping from Vendor.SecurityAction

  • Added array deduplication for event.category[] and event.type[]

  • Updated email field normalization to convert all email addresses to lowercase

  • Enhanced DNS event action mapping to use coalesce function for better field resolution

  • Updated parser version to 2.3.0 and CPS version to 1.1.0

Package cloudflare/zerotrust Release Notes Version 1.3.0
  • Enhanced JSON parsing with excludeEmpty and handleNull options

  • Updated event type categorization for email security logs

  • Added new test cases for improved coverage

  • Updated parser version to 2.2.0

Package cloudflare/zerotrust Release Notes Version 1.2.3
  • Fixed handling of PROXY_CONN_REFUSED connection close reason

  • Improved bulk log processing by removing trailing newline characters

  • Updated parser version to 2.1.3

Package cloudflare/zerotrust Release Notes Version 1.2.2
  • Fixed email attachment parsing by properly dropping temporary arrays

  • Updated ECS version to 8.17.0

  • Updated parser version to 2.1.2

Package cloudflare/zerotrust Release Notes Version 1.2.1
  • Fixed email attachment parsing by properly dropping temporary arrays

  • Updated ECS version to 8.17.0

  • Updated parser version to 2.1.1

Package cloudflare/zerotrust Release Notes Version 1.2.0
  • Improved JSON parsing with support for message prefix removal

  • Enhanced event categorization with proper event.category and event.type arrays

  • Added comprehensive email attachment parsing for Area1 security logs

  • Improved HTTP response status code handling for better event outcome determination

  • Added support for bulk log processing with improved detection logic

Package cloudflare/zerotrust Release Notes Version 1.1.1
  • Improves the case statement to only look for fields that are not possibly null

  • Reassigns as.number to client.as.number and interface.id to observer.egress.interface.id to comply with ECS standards

Package cloudflare/zerotrust Release Notes Version 1.1.0
  • Improves the field extraction and performance.

  • Bumps the minimum LogScale version to 1.142 to support parser assertions in yaml files.

  • Adds support of Network Analytics, Magic IDS and Zone-scoped HTTP Requests logs.

  • Adds event.reason , message , interface.name , email.from.address , email.sender.address , email.to.address , file.name , file.size , file.sizefile.size , device.id fields and more.

  • Renames the parser to cloudflare-one .

Package cloudflare/zerotrust Release Notes Version 1.0.0
  • Adds new event.module and Cps.version fields

  • Removes the Product , related.user and related.ip fields

  • Sets following tags: Cps.version , Vendor , ecs.version , event.dataset , event.kind , event.module , event.outcome , observer.type