Unix
StandardUnix allows you to monitor and identify threats in your organization using Unix data. Logpoint aggregates and normalizes the Unix logs so you can analyze the information through dashboards and security reports. Unix dashboards and reports provide visualization of event details for authentication requests, privilege escalation and user account management of the Unix environment detected in your network.
Key Information
Activate the label packages to apply specific labels and group similar logs together. To learn more, go to Activating Labels Packages.
Enhancement
Minor bug fixes and enhancements.
Bug Fixes
KB-1943871705
Some Systemd logs were not normalized by LP_Unix Systemd.
KB-17545
The file field was incorrectly mapped as target_file for the EventData_TargetFilename file in UnixSysmonCompiledNormalizer.
KB-1740567530
The host field was not properly parsed by UnixAuditLogNormalizer. It took two different hostnames as a field value.
Past Releases
Unix v5.4.0 ▾
Enhancement
KB-22616
Added Syslog Collector based Linux log source template, simplifying the log source configuration process. To learn more, go to Creating Log Source via a Template .
Unix v5.3.0 ▾
Enhancements
KB-1652065243
Added a new LP_Dell Data Domain normalization package to normalize the Dell Data Domain logs.
Added a new signature in LP_Kernel to normalize Unix Kernel's new log format.
KB-19146, KB-16688, KB-1833470988, 65994, 68980
Added new signatures in LP_Unix Crond, LP_Unix Rsyslogd and LP_Unix SU to normalize Crond, Rsyslogd and Switch User (SU) log's new format .
Updated the version of UnixSysmonCompiledNormalizer , UnixCompiledNormalizer and UnixAuditLogNormalizer compatible to the latest Unix version .
KB-1973871731
Updated the user field in the Unix CompiledNormalizer to accept only a username as a value. In addition, to assign a domain name use the new field domain . Previously, user accepted both a username and domain name as its value.
KB-1809768372
Added Authentication label for UnixCompiledNormalizer.
Replaced the status=Accepted field with status=Successful in the UnixCompiledNormalizer to maintain consistency.
KB-12244, KB-17227, KB-1742952334, 67195
Updated LP_Unix Syslog NG and LP_Unix Inetd to normalize the Syslog NG and SSHD Log format correctly.
The following fields are updated and mapped to Logpoint taxonomy to maintain consistency:
-
rhosttoremote_host -
rusertoremote_user
KB-1887868790
Updated signatures in LP_Unix Ipmserver, LP_Unix Systemd, LP_Unix Named and LP_Unix Syslogd to normalize Unix Ipmserver's new log format.
KB-1902770682
Updated Unix CompiledNormalizer to normalize the Snort Log format correctly.
KB-17987
All the argument fields are combined in a single key for the Unix Audit logs with the EXECVE event.
KB-1750167571, 68665
Added new signatures and labels in LP_Unix Generic to normalize the Debian Package Manager ( DPKG) logs correctly.
KB-16688, KB-1714365994, 67153
Added new signatures in LP_Unix Crond and LP_Unix Systemd to normalize C rond and Systemd logs.
Bug Fixes
KB-1943871705
Some Systemd logs were not normalized by LP_Unix Systemd.
KB-17545
The file field was incorrectly mapped as target_file for the EventData_TargetFilename file in UnixSysmonCompiledNormalizer.
KB-1740567530
The host field was not properly parsed by UnixAuditLogNormalizer. It took two different hostnames as a field value.
Unix v5.2.1 ▾
Enhancements
KB-16135
Updated the proctitle field in the UnixAuditLogNormalizer to capture the value in the ASCII format. Previously, proctitle captured the value only in hex format.
KB-16136
Updated UnixAuditLogNormalizer to normalize the Enriched Auditd Log format correctly.
KB-1625264580
Added new signatures in LP_Unix Systemd to normalize Unix Systemd's new log format.
Updated signatures in LP_Unix Dockerd to normalize Unix Dockerd's new log format.
KB-16664
Added the LP_Unix Possible DNS Server Modified alert.
Modified the query of the following Unix alerts: LP_Unix Group Deleted LP_Unix User Session Alert LP_Unix User Removed from Privileged Group
Removed the following Unix alerts: LP_Unix Privilege Escalation Failed LP_Unix Security Violation
Bug Fixes
KB-1613563617
Some sshd and system logs were not normalized by LP_Unix SSHD and LP_Unix Systemd.
KB-16396
Some Unix logs with the User Add/Delete to Group event were not properly normalized.
Unix v5.2.0 ▾
Enhancements
New normalization packages are added: LP_Unix Dovecot LP_Unix Scponly LP_Unix Nullmailer LP_Unix Iptables
KB-1545961052
A new compiled normalizer UnixSysmonCompiledNormalizer is added to normalize the Sysmon logs.
KB-15573, KB-15662, KB-15651, KB-1416761917, 62324, 62215, 59794
New signatures are added in the following normalization packages: LP_Unix Sudo, LP_Unix Crond, and LP_Unix Systemd to normalize the Unix logs. LP_Solaris OS to normalize the Solaris OS logs. LP_Unix Xrdp to normalize the Xrdp logs. LP_Common Unix System to normalize the MISP, snapd, and tracker-store logs . UnixCompiledNormalizer to normalize the sshd, systemd, and dbus-daemon log s.
KB-1416759794
New signatures are added in the UnixCompiledNormalizer to normalize the sshd, systemd, and dbus-daemon log s.
KB-1565462215
Session and Start labels are added for the session logs in the LP_Unix Systemd .
The Unix alerts are enhanced. To learn more, go to the Appendix section in the Unix v5.2.0 guide.
Unix v3.4.0 ▾
Support
If you have any questions or require assistance, create a support ticket.
Comments
Article is closed for comments.
Hi, is there any alert packages for unix? Thanks.